Github actions
Skill ahtishamshahzad/agent_dev_flow/.ai/skills/devops/github-actions
Use to implement the designed CI/CD pipeline as GitHub Actions workflows — jobs/matrices, dependency + build caching, pinned action versions, least-privilege GITHUB_TOKEN, secrets from the store, environment protection rules for approval-gated deploys. Implements the ci-cd design; adds no jobs for nonexistent apps.From its SKILL.md
npx -y skills add ahtishamshahzad/agent_dev_flow --skill github-actionsAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
5.1 KB, ~1.1k tokens by cl100k_base, as published. Nobody here has run it
GitHub Actions
Purpose
Turn the ci-cd pipeline design into secure, efficient GitHub Actions workflows — correct triggers, caching, pinned actions, least-privilege permissions, and environment protection for gated deploys — without introducing jobs the design didn't call for.
When to Use
- When the CI platform is GitHub and the
ci-cddesign is ready to implement. - Not for designing the pipeline (
ci-cd) or on non-GitHub platforms.
Inputs
- The
ci-cdjob design (app-derived jobs + gates). - Secret store + environments (
secrets-management,environment-management), repo/monorepo shape.
Discovery Questions
- What triggers each workflow (PR, push to main, tag, manual dispatch)?
- Which jobs need which secrets, and from where (repo/environment secrets)?
- Which deploys need environment protection rules (required reviewers) for approval gating?
Responsibilities
- Implement the designed jobs as workflows/jobs with correct
needsordering and matrices where useful (Node versions, packages); implement exactly the app-derived set fromci-cd— no invented jobs for absent apps. - Cache dependencies and build outputs (setup-action caches, Turborepo remote cache if configured —
turborepo-foundation); frozen installs (npm ci/pnpm --frozen-lockfile). - Pin action versions (by major tag at least, commit SHA for third-party actions) — floating
@mainis a supply-chain risk (../../security/dependency-security). - Apply least-privilege
GITHUB_TOKEN: default read-onlypermissions, grantingwritescopes only per job that needs them. - Source secrets from GitHub secrets / environment secrets (
secrets-management) — never inline; never echo into logs; be mindful of untrustedpull_request_targetand fork PRs (don't expose secrets to fork code). - Gate deploys with GitHub Environments + required reviewers so production deploy jobs pause for approval (
ci-cd,../../release-planning); run post-deploy smoke (../../testing/smoke-testing). - Keep workflows DRY (reusable/composite workflows) where the repo has several apps.
Required Workflow
- Map the
ci-cdjobs to workflows + triggers. - Implement jobs with
needsordering + matrices; frozen installs + caching. - Pin all actions; set least-privilege
permissions. - Wire secrets from the store; guard fork/PR secret exposure.
- Add environment protection rules for gated deploys + post-deploy smoke.
Decision Rules
- Implement only the designed, app-derived jobs — the platform layer doesn't invent scope.
- Default
permissions: read-all; escalate per job, never globally to write. - Pin third-party actions to a SHA; a hijacked floating tag runs arbitrary code with your token/secrets.
- Never expose secrets to untrusted fork PR code (
pull_request_targetcare). - Production deploys pass through an Environment with required reviewers.
Rules
- Actions pinned;
GITHUB_TOKENleast-privilege. - Secrets from the store, never logged or inlined.
- Deploy jobs approval-gated via Environments.
Anti-Patterns
- Adding workflow jobs for apps the project doesn't have.
uses: some/action@main(unpinned third-party).- Global
permissions: write-all. - Secrets echoed in logs or exposed to fork PRs.
- Auto-deploy to production with no environment approval.
Validation Checklist
- Designed jobs implemented (no extras for absent apps).
-
needsordering + matrices; frozen installs + caching. - Actions pinned; least-privilege
GITHUB_TOKEN. - Secrets from store; fork/PR exposure guarded.
- Environment protection for gated deploys + post-deploy smoke.
Definition of Done
The ci-cd design implemented as GitHub Actions workflows — correctly ordered cached jobs, pinned actions, least-privilege token, store-sourced secrets, and environment-protected approval-gated deploys — matching the app-derived job set exactly.
Related Skills
ci-cd, secrets-management, environment-management, turborepo-foundation, deployment-selection, ../../testing/smoke-testing, ../../security/dependency-security, ../../release-planning, ../../github-repository.
Related Knowledge
../../../knowledge/ (triggers, environments, reviewers).
Related References
../../../references/devops/ (workflow patterns, when populated).
Context Loading Guidance
- Requires: the
ci-cdjob design, secret store + environments, repo shape. - Does not require: re-deciding the pipeline scope, app feature code.
- May load:
secrets-management,deployment-selection. - Stop when: workflows implement the design with security + gates in place.
Token Efficiency Guidance
Work from the ci-cd job matrix; the workflow is its implementation. Keep YAML discussion to triggers, permissions, and gates.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.