Dependency & Supply Chain Security Gate
by stojke72
Audit supplied dependency manifests, lockfiles, SBOMs, registry settings, CI build inputs, and provenance evidence. Reconcile exact component identities, trace privileged execution paths, identify integrity and resolution gaps, and return an evidence-bound PASS, REVIEW, or BLOCK release decision—without installing packages or requiring network access.