agentsclimarketplace

Infra ci cd

Skill barcelosvinicius/basic-engineering/plugins/be/skills/infra-ci-cd

Claude Code plugin + npm base for AI-assisted engineering: 25 skills, 12 agents, slash commands, session-continuity hook. Also works with Copilot, Cursor, and others.

Install
npx -y skills add barcelosvinicius/basic-engineering --skill infra-ci-cd

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Use when configuring or evolving a project's CI/CD pipeline — stage ordering, dependency audit (SCA), static analysis (SAST), automated dependency updates, commit message validation, and merge gates. Stack-agnostic principles with GitHub Actions / Maven / npm examples available as on-demand resources.

SKILL.md

4.6 KB, as published. Nobody here has run it

Skill: CI/CD Pipeline and Dependency Audit

Defines the structure of the continuous integration and delivery pipeline, with special focus on automatic security auditing. Use when configuring or evolving the project's workflows.

Reference: engineering-principles.md §2.8 (Supply Chain).

Minimum pipeline structure

lint → build → test-unit → test-integration → security-scan → build-image → deploy

Each stage runs only if the previous one passes. A broken build blocks everything.

Dependency audit (SCA)

Every pipeline must scan third-party dependencies for known CVEs and fail the build above an agreed severity threshold:

  • JVM/Maven: OWASP Dependency Check (failBuildOnCVSS).
  • Node: npm audit --audit-level=high (use npm ci, never npm install, in CI).
  • Python: pip-audit; Go: govulncheck; Rust: cargo audit.

Keep a documented suppression file for confirmed false positives — never silence findings ad hoc.

Gradual adoption strategy (avoid blocking the team on day one):

PhaseThresholdGoal
Week 1Critical onlyVisibility, no blocking
Week 2–4High + CriticalBlock only severe issues
StableModerate and upRecommended standard

Supply-chain integrity (beyond CVEs)

SCA finds known-vulnerable versions; it misses known-malicious ones (compromised releases, typosquats, install-script exfiltration). Add:

  • Advisory / IOC scan: check installed versions against malicious-package feeds — OSV-Scanner, Socket, or the OpenSSF malicious-packages / GitHub Advisory data — and fail on a match. Re-run on every lockfile change.
  • Provenance & signatures: prefer packages with build provenance and verify it in CI (npm audit signatures, sigstore/cosign).
  • Neutralize install scripts: install with scripts disabled where feasible (npm ci --ignore-scripts) so a malicious postinstall cannot run in CI.
  • Pin + review new deps before adding (proc-dependency-management); pin transitive versions via the lockfile.

Static application security testing (SAST)

SCA checks dependencies; SAST checks the code you wrote. Use both:

  • Semgrep OSS (recommended default): no build step, works in private repos without paid add-ons, community rulesets (p/owasp-top-ten, p/secrets, per-language packs) plus custom YAML rules in .semgrep/rules/<language>/.
  • Language-native linters with security plugins where they add value (e.g., SpotBugs + find-sec-bugs for Java).

Typical custom rules every project should have: hardcoded secrets, sensitive data logging, weak hashing, non-cryptographic PRNG, SQL string concatenation, eval/dynamic code, auth tokens in localStorage, innerHTML XSS.

Automated dependency updates

Enable a bot (Dependabot, Renovate) with a weekly schedule and a PR limit (e.g., 5 open PRs max) so updates arrive continuously instead of as a yearly big-bang upgrade. Label the PRs for triage. See also the proc-dependency-management skill.

Mandatory gates before merge

  • Required status checks: every CI job green.
  • At least 1 approving review; stale reviews dismissed on new commits.
  • Branch up to date with the target before merge.
  • Force push to the default branch: never.

Commit and quality conventions in CI

  • Validate Conventional Commits automatically (commitlint or equivalent).
  • Enforce coverage thresholds where the team has agreed on them.
  • Frontend projects: run accessibility checks (e.g., Lighthouse CI with categories:accessibility minScore 0.9) — see fe-accessibility-patterns.

Common mistakes

MistakeSolution
Slow pipeline (> 10 min)Configure dependency caches per ecosystem
False positives blocking adoptionStart at critical-only threshold, tighten gradually
Non-deterministic installs in CIUse lockfile-strict installs (npm ci, --frozen-lockfile)
Update bot floods the repoCap open PRs, schedule weekly

Resources

  • examples-github-actions.md — copy-paste GitHub Actions pipelines: Maven OWASP Dependency Check, SpotBugs + find-sec-bugs, Semgrep workflow and custom rule template, Dependabot config, full backend+frontend pipeline, commitlint, Lighthouse CI.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.