{"id":23875,"plugin_id":"plugins_6ab3634387ec81919729f26fb2a8e67b","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:17:49.001Z","digest":"5be6e0f5526c0e547ae13f5b30c935dc6b1a5e38669cfe8278bcd617c59b9084","against":null,"payload":{"name":"deployment-supply-chain","description":"Review Cloudflare CI/CD, Git integrations, build credentials, environment separation, dependencies, and release controls.","included_files":[],"skill_md_contents":"---\nname: deployment-supply-chain\ndescription: Review Cloudflare CI/CD, Git integrations, build credentials, environment separation, dependencies, and release controls.\n---\n\n# Deployment and Supply-Chain Security\n\nReview source control and CI identity/permissions, branch and environment protections, deploy hooks, build logs/artifacts, dependency lifecycle, lockfiles, secret injection, production-vs-preview configuration, Wrangler deploy targets, approval gates, provenance where available, and rollback/version history. Seek narrow, purpose-specific deploy tokens; prevent untrusted pull-request code from accessing production secrets; isolate preview data and credentials; pin dependencies where the project’s ecosystem supports it and update with tests.\n\nTreat a green build or successful deployment as operational evidence only, not proof of secure code. Identify checks not run and supply-chain visibility gaps. Do not trigger deployments, dependency upgrades, key rotation, or CI permission changes unless the user specifically authorizes that action.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}