Nipmod

skill

strict-ci-policy

Apply a strict agent-package policy for production repositories that require verified supply chains.

Readme

What this package gives an agent

Apply a strict agent-package policy for production repositories that require verified supply chains.

The signed bundle is stored on Gitlawb, pinned by digest and checked against transparency evidence before install. Use the evidence page for the exact source, release and witness proof for this package version.

Install

Choose the safest command for the job

Install

nipmod install pkg:did:key:z6MkhmdBsWDz4gejutZzV3bHZUYXaf2UigNT7QN8MSotbHHN/strict-ci-policy@0.1.0

Inspect first

nipmod inspect pkg:did:key:z6MkhmdBsWDz4gejutZzV3bHZUYXaf2UigNT7QN8MSotbHHN/strict-ci-policy@0.1.0

Plan only

nipmod install --plan pkg:did:key:z6MkhmdBsWDz4gejutZzV3bHZUYXaf2UigNT7QN8MSotbHHN/strict-ci-policy@0.1.0

Versions

Published versions

0.1.0
2073b8316b6af86f1ffb6d83c6c83d51dc2d598e7a8b01f12cd145f88a85dd27

Dependencies

Capability graph

No dependency metadata is published for this package version.

Trust

Verification status

Level
verified
Score
100
Artifact digest
verified
Bundle signature
verified
Source provenance
verified
Transparency
verified
Quality
100/100 Excellent

Audit

Install decision

Ready
Trust
verified/100
Quality
100/100
Permissions
quiet
Advisory
clear
nipmod inspect pkg:did:key:z6MkhmdBsWDz4gejutZzV3bHZUYXaf2UigNT7QN8MSotbHHN/strict-ci-policy@0.1.0 --json
nipmod install --plan pkg:did:key:z6MkhmdBsWDz4gejutZzV3bHZUYXaf2UigNT7QN8MSotbHHN/strict-ci-policy@0.1.0 --json

Advisories

Install risk

No active high or critical quarantine blocks this package version.

nipmod install strict-ci-policy

Provenance

Gitlawb source and proof

Canonical
pkg:did:key:z6MkhmdBsWDz4gejutZzV3bHZUYXaf2UigNT7QN8MSotbHHN/strict-ci-policy@0.1.0
Digest
2073b8316b6af86f1ffb6d83c6c83d51dc2d598e7a8b01f12cd145f88a85dd27
Source tag
v0.1.0
Source commit
63477a439e561eba8035858ef9bee338b4528721
Root
3cc66da3292900a4ac482b2c301db5c6e0a00c2461847a29fec5275da7f631cf

Agent use

Permissions and host fit

No manifest permissions

Agents should inspect first, then install only when trust score, permissions, advisories and local policy match the workspace.