adopting-third-party-components
Use when explicitly authorized to add an exact third-party software component or materially revise its trust policy, including a first package, vendored artifact, Action, image, toolchain, CLI, or agent-plugin pin. Establishes the durable policy and first admitted identity; do not use for read-only comparison, ordinary updates under an existing policy, or generic Git/PR work.
Pinned to revision 4a40c0d3cfa8, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/adopting-third-party-components/SKILL.md
- skills/adopting-third-party-components/agents/openai.yaml
- skills/adopting-third-party-components/references/component-clearance-contract.md
- skills/adopting-third-party-components/references/component-policy-contract.md
Every link opens the file at its source, pinned to the revision this page describes.