agentsclimarketplace

Infra ci cd

Skill barcelosvinicius/basic-engineering/plugins/be/skills/infra-ci-cd

Use when configuring or evolving a project's CI/CD pipeline — stage ordering, dependency audit (SCA), static analysis (SAST), automated dependency updates, commit message validation, and merge gates. Stack-agnostic principles with GitHub Actions / Maven / npm examples available as on-demand resources.From its SKILL.md

Install
npx -y skills add barcelosvinicius/basic-engineering --skill infra-ci-cd

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

4.6 KB, ~1.0k tokens by cl100k_base, as published. Nobody here has run it

Skill: CI/CD Pipeline and Dependency Audit

Defines the structure of the continuous integration and delivery pipeline, with special focus on automatic security auditing. Use when configuring or evolving the project's workflows.

Reference: engineering-principles.md §2.8 (Supply Chain).

Minimum pipeline structure

lint → build → test-unit → test-integration → security-scan → build-image → deploy

Each stage runs only if the previous one passes. A broken build blocks everything.

Dependency audit (SCA)

Every pipeline must scan third-party dependencies for known CVEs and fail the build above an agreed severity threshold:

  • JVM/Maven: OWASP Dependency Check (failBuildOnCVSS).
  • Node: npm audit --audit-level=high (use npm ci, never npm install, in CI).
  • Python: pip-audit; Go: govulncheck; Rust: cargo audit.

Keep a documented suppression file for confirmed false positives — never silence findings ad hoc.

Gradual adoption strategy (avoid blocking the team on day one):

PhaseThresholdGoal
Week 1Critical onlyVisibility, no blocking
Week 2–4High + CriticalBlock only severe issues
StableModerate and upRecommended standard

Supply-chain integrity (beyond CVEs)

SCA finds known-vulnerable versions; it misses known-malicious ones (compromised releases, typosquats, install-script exfiltration). Add:

  • Advisory / IOC scan: check installed versions against malicious-package feeds — OSV-Scanner, Socket, or the OpenSSF malicious-packages / GitHub Advisory data — and fail on a match. Re-run on every lockfile change.
  • Provenance & signatures: prefer packages with build provenance and verify it in CI (npm audit signatures, sigstore/cosign).
  • Neutralize install scripts: install with scripts disabled where feasible (npm ci --ignore-scripts) so a malicious postinstall cannot run in CI.
  • Pin + review new deps before adding (proc-dependency-management); pin transitive versions via the lockfile.

Static application security testing (SAST)

SCA checks dependencies; SAST checks the code you wrote. Use both:

  • Semgrep OSS (recommended default): no build step, works in private repos without paid add-ons, community rulesets (p/owasp-top-ten, p/secrets, per-language packs) plus custom YAML rules in .semgrep/rules/<language>/.
  • Language-native linters with security plugins where they add value (e.g., SpotBugs + find-sec-bugs for Java).

Typical custom rules every project should have: hardcoded secrets, sensitive data logging, weak hashing, non-cryptographic PRNG, SQL string concatenation, eval/dynamic code, auth tokens in localStorage, innerHTML XSS.

Automated dependency updates

Enable a bot (Dependabot, Renovate) with a weekly schedule and a PR limit (e.g., 5 open PRs max) so updates arrive continuously instead of as a yearly big-bang upgrade. Label the PRs for triage. See also the proc-dependency-management skill.

Mandatory gates before merge

  • Required status checks: every CI job green.
  • At least 1 approving review; stale reviews dismissed on new commits.
  • Branch up to date with the target before merge.
  • Force push to the default branch: never.

Commit and quality conventions in CI

  • Validate Conventional Commits automatically (commitlint or equivalent).
  • Enforce coverage thresholds where the team has agreed on them.
  • Frontend projects: run accessibility checks (e.g., Lighthouse CI with categories:accessibility minScore 0.9) — see fe-accessibility-patterns.

Common mistakes

MistakeSolution
Slow pipeline (> 10 min)Configure dependency caches per ecosystem
False positives blocking adoptionStart at critical-only threshold, tighten gradually
Non-deterministic installs in CIUse lockfile-strict installs (npm ci, --frozen-lockfile)
Update bot floods the repoCap open PRs, schedule weekly

Resources

  • examples-github-actions.md — copy-paste GitHub Actions pipelines: Maven OWASP Dependency Check, SpotBugs + find-sec-bugs, Semgrep workflow and custom rule template, Dependabot config, full backend+frontend pipeline, commitlint, Lighthouse CI.

What ships with it: 1 file

9.1 KB alongside SKILL.md

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.