Skip to content

nisavid/artifact-customs

v1.0.0MIT

Clear, adopt, maintain, replace, and retire exact third-party software components under explicit policy.

assessing-third-party-components

Use for a standalone ungoverned read-only clearance of an exact third-party software component or immutable artifact, including provenance, license, dependencies, and conformance checks before adoption or maintenance. Includes packages, vendored artifacts, Actions, images, toolchains, CLIs, and agent plugins; a governed advisory enters maintenance first, and mutation and generic vendor, release, deployment, Git, PR, or review work are excluded.

Read SKILL.md at the source

Pinned to revision 4a40c0d3cfa8, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.