/supply-chain
Claude
supply-chain
Secure the software supply chain from source to running container. Covers Cosign keyless image signing (Sigstore/Rekor), SBOM generation and attestation (Syft), vulnerability scanning with severity gates (Trivy/Grype), SLSA Level 2 provenance, and Kyverno/OPA admission enforcement. All open-source, no license cost. Use when asked to "sign my image", "generate an SBOM", "scan for CVEs", "attest build provenance", "enforce image signatures in Kubernetes", or "implement SLSA".
More Claude commands
/effort
Set effort
Set the model effort/reasoning level.
/agents
Manage subagents
Create or manage subagents, or edit the agents directory directly.
/team-onboarding
Team onboarding
Generate a team onboarding guide from your usage history.
/deep-research
Deep research
Fan out web searches, cross-check sources, and synthesize a cited report.