Supply Chain Trust Assessment¶
Source: hooks/ways/softwaredev/code/supplychain/supplychain.md
Frontmatter
| Field | Value |
|---|---|
description |
supply chain security, repository trust assessment, evaluating code from untrusted sources |
vocabulary |
supply chain trust assessment forked repo untrusted repo audit repo hygiene dependency scan vulnerability malicious backdoor provenance clone fork grab use try found shared unfamiliar external third party |
commands |
git\ clone |
refire |
0.2 |
scope |
agent, subagent |
Scan before you run. Don't install dependencies or execute code from an unfamiliar source until you've looked at it.
Assessment Tiers¶
Work from fast and cheap to slow and thorough. Most repos only need the first two.
| Tier | What | Time | When |
|---|---|---|---|
| 0. Maturity | Is the package what it presents itself as? | a minute | Before adopting anything found via search |
| 1. Repo audit | Git history, size, leaked secrets | seconds | Any unfamiliar repo |
| 2. Source audit | Dangerous code patterns | minutes | Before running anything |
| 3. Dep scan | Known vulnerabilities in dependencies | minutes | Before installing |
| 4. Automation | CI/Makefile scanning integration | varies | Established projects |
| 5. History sever | Flatten or delete tainted history | minutes | When history is the threat |
Principles¶
- Scan before you run.
pip installandnpm installexecute arbitrary code. Scan first. - Check what a package is before checking whether it is safe. A thin wrapper around a mature library is usually the wrong adoption even when it is perfectly safe.
- Containers aren't a security boundary. A malicious setup.py in Docker still has network access.
- Match the tool to the project. Manual
osv-scannerfor a hobby project. GitHub Actions for a team repo. Don't skip levels, don't overbuild. - Responsible disclosure over silence. If you find leaked secrets in someone else's repo, report it — masked values, remediation hints, not a public callout.
See Also¶
- code/security(softwaredev) — supply chain is a security concern
- code/supplychain/maturity(softwaredev) — adoption versus presentation, before the safety tiers
- code/supplychain/depscan(softwaredev) — scanning dependencies
- code/supplychain/sourceaudit(softwaredev) — auditing source before execution
- environment/deps(softwaredev) — dependency management workflow