← Files Cloudflare SecurityARCHIVED FILE
skills/deployment-supply-chain/SKILL.md
1.04 KB · Oct 3, 2026 · 06:37 UTC
--- name: deployment-supply-chain description: Review Cloudflare CI/CD, Git integrations, build credentials, environment separation, dependencies, and release controls. --- # Deployment and Supply-Chain Security Review source control and CI identity/permissions, branch and environment protections, deploy hooks, build logs/artifacts, dependency lifecycle, lockfiles, secret injection, production-vs-preview configuration, Wrangler deploy targets, approval gates, provenance where available, and rollback/version history. Seek narrow, purpose-specific deploy tokens; prevent untrusted pull-request code from accessing production secrets; isolate preview data and credentials; pin dependencies where the project’s ecosystem supports it and update with tests. Treat a green build or successful deployment as operational evidence only, not proof of secure code. Identify checks not run and supply-chain visibility gaps. Do not trigger deployments, dependency upgrades, key rotation, or CI permission changes unless the user specifically authorizes that action.
SHA-256: 4c75ea950062e993b44c5f13873684e3995c1c010cdf77d6a3df8b4419754eba