agentsclimarketplace

Ci cd

Skill mikulgohil/claude-skills/skills/devex/ci-cd

My curated collection of Claude Code Agent Skills — 21 skills across frontend, Sitecore, AI/agents, devex fundamentals, and personal workflows.

Install
npx -y skills add mikulgohil/claude-skills --skill ci-cd

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

CI/CD pipeline patterns with GitHub Actions — build/test/deploy workflows, caching, matrix builds, release automation, and testing strategies. Use when writing or improving a pipeline.

The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

10.1 KB, as published. Nobody here has run it

CI/CD Operations

Comprehensive patterns for continuous integration, delivery, and deployment using GitHub Actions, release automation tools, and testing pipelines.

GitHub Actions Quick Reference

Workflow File Anatomy

name: CI                          # Display name in Actions tab
on:                               # Trigger events
  push:
    branches: [main]
  pull_request:
    branches: [main]

permissions:                      # GITHUB_TOKEN scope (least privilege)
  contents: read
  pull-requests: write

concurrency:                      # Prevent duplicate runs
  group: ${{ github.workflow }}-${{ github.ref }}
  cancel-in-progress: true

env:                              # Workflow-level environment variables
  NODE_VERSION: "20"

jobs:
  test:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with:
          node-version: ${{ env.NODE_VERSION }}
          cache: npm
      - run: npm ci
      - run: npm test

Core Syntax Elements

ElementPurposeExample
onEvent triggerspush, pull_request, schedule
jobs.<id>.runs-onRunner selectionubuntu-latest, self-hosted
jobs.<id>.needsJob dependenciesneeds: [build, lint]
jobs.<id>.ifConditional executionif: github.event_name == 'push'
jobs.<id>.strategy.matrixParallel variantsnode-version: [18, 20, 22]
jobs.<id>.environmentDeployment targetenvironment: production
jobs.<id>.permissionsToken scopecontents: write
steps[*].usesUse an actionuses: actions/checkout@v4
steps[*].runRun a commandrun: npm test
steps[*].envStep environmentenv: { CI: true }

Trigger Decision Tree

ScenarioTriggerConfig
Run tests on every PRpull_requestbranches: [main]
Deploy on merge to mainpushbranches: [main]
Release on version tagpushtags: ['v*']
Nightly buildsschedulecron: '0 2 * * *'
Manual deploymentworkflow_dispatchinputs: { environment: ... }
Called by another workflowworkflow_callinputs:, secrets:
On PR label changepull_requesttypes: [labeled]
On issue commentissue_commenttypes: [created]
On release publishedreleasetypes: [published]
On package pushregistry_packagetypes: [published]

Trigger Filter Patterns

on:
  push:
    branches: [main, 'release/**']      # Branch patterns
    paths: ['src/**', '!src/**/*.test.*'] # Path filters (ignore tests)
    tags: ['v*']                          # Tag patterns
  pull_request:
    types: [opened, synchronize, reopened] # Default types
    paths-ignore: ['docs/**', '*.md']     # Ignore docs-only changes

Caching Strategies

EcosystemAction / KeyPathRestore Key
Node (npm)actions/setup-node with cache: npmAutoAuto
Node (pnpm)actions/setup-node with cache: pnpmAutoAuto
Go modulesactions/setup-go with cache: trueAutoAuto
Cargoactions/cache@v4~/.cargo/registry, targetcargo-${{ runner.os }}-${{ hashFiles('Cargo.lock') }}
pip / uvactions/setup-python with cache: pipAutoAuto
Docker layersdocker/build-push-actionUses buildx cachetype=gha or type=registry
Gradleactions/setup-java with cache: gradleAutoAuto
Composeractions/cache@v4vendorcomposer-${{ hashFiles('composer.lock') }}

Manual Cache Example

- uses: actions/cache@v4
  with:
    path: |
      ~/.cargo/bin
      ~/.cargo/registry
      ~/.cargo/git
      target
    key: cargo-${{ runner.os }}-${{ hashFiles('**/Cargo.lock') }}
    restore-keys: |
      cargo-${{ runner.os }}-

Matrix Strategy

strategy:
  fail-fast: false                    # Don't cancel siblings on failure
  max-parallel: 4                     # Limit concurrent jobs
  matrix:
    os: [ubuntu-latest, windows-latest, macos-latest]
    node-version: [18, 20, 22]
    include:                          # Add specific combos
      - os: ubuntu-latest
        node-version: 22
        coverage: true
    exclude:                          # Remove specific combos
      - os: windows-latest
        node-version: 18

Dynamic Matrix

prepare:
  runs-on: ubuntu-latest
  outputs:
    matrix: ${{ steps.set.outputs.matrix }}
  steps:
    - id: set
      run: echo "matrix=$(jq -c . matrix.json)" >> "$GITHUB_OUTPUT"

test:
  needs: prepare
  strategy:
    matrix: ${{ fromJson(needs.prepare.outputs.matrix) }}

Secrets Management

ScopeAccessUse Case
Repository secretsAll workflows in repoAPI keys, tokens
Environment secretsJobs targeting that environmentProduction credentials
Organization secretsSelected repos in orgShared service accounts
OIDC tokensFederated identityCloud deployment (no stored secrets)

Secrets Best Practices

# Reference secrets - NEVER echo or log them
- run: deploy --token ${{ secrets.DEPLOY_TOKEN }}

# Mask custom values
- run: echo "::add-mask::$CUSTOM_SECRET"

# Use environments for deployment secrets
jobs:
  deploy:
    environment: production           # Requires approval + has secrets
    steps:
      - run: deploy --key ${{ secrets.PROD_API_KEY }}

OIDC for Cloud (No Stored Secrets)

permissions:
  id-token: write
  contents: read

steps:
  - uses: aws-actions/configure-aws-credentials@v4
    with:
      role-to-assume: arn:aws:iam::123456789:role/github-actions
      aws-region: us-east-1

Common Workflow Patterns

Test on Pull Request

name: Test
on:
  pull_request:
    branches: [main]
concurrency:
  group: test-${{ github.head_ref }}
  cancel-in-progress: true
jobs:
  test:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with: { node-version: 20, cache: npm }
      - run: npm ci
      - run: npm run lint
      - run: npm test -- --coverage

Deploy on Merge to Main

name: Deploy
on:
  push:
    branches: [main]
jobs:
  deploy:
    runs-on: ubuntu-latest
    environment: production
    steps:
      - uses: actions/checkout@v4
      - run: npm ci && npm run build
      - run: npx wrangler deploy
        env:
          CLOUDFLARE_API_TOKEN: ${{ secrets.CF_API_TOKEN }}

Release on Tag

name: Release
on:
  push:
    tags: ['v*']
permissions:
  contents: write
jobs:
  release:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with: { fetch-depth: 0 }
      - run: |
          gh release create ${{ github.ref_name }} \
            --generate-notes \
            --title "${{ github.ref_name }}"
        env:
          GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}

Gotchas Table

GotchaProblemFix
Shallow clonegit describe fails, history missingactions/checkout@v4 with fetch-depth: 0
Default permissionsGITHUB_TOKEN is read-only by defaultSet permissions: explicitly
Action pinning@main can break without warningPin to SHA: @abc123 or @v4
Fork PR secretsSecrets unavailable on fork PRsUse pull_request_target carefully
Concurrent deploysRace condition on productionUse concurrency: groups
Stale cachesCache grows unboundedInclude lockfile hash in key
Node.js versionsetup-node defaults varyAlways specify node-version
Docker layer cacheRebuilds everything without cacheUse cache-from: type=gha
Matrix + environmentEach matrix job needs approvalUse a single deploy job after matrix
Path filters + required checksSkipped jobs block mergeUse paths-filter action or make checks non-required
GITHUB_TOKEN in PRsCannot trigger other workflowsUse a PAT or GitHub App token
Windows line endingsScripts fail with \r\nUse .gitattributes or core.autocrlf

Expression Syntax Quick Reference

ExpressionResult
${{ github.event_name }}push, pull_request, etc.
${{ github.ref_name }}Branch or tag name
${{ github.sha }}Full commit SHA
${{ github.actor }}User who triggered
${{ runner.os }}Linux, Windows, macOS
${{ contains(github.event.head_commit.message, '[skip ci]') }}Check commit message
${{ needs.build.outputs.version }}Output from prior job
${{ fromJson(steps.meta.outputs.json) }}Parse JSON output
${{ hashFiles('**/package-lock.json') }}Hash for cache keys
${{ format('refs/heads/{0}', matrix.branch) }}String formatting
${{ toJson(matrix) }}Debug: print matrix config

Step Outputs

steps:
  - id: version
    run: echo "value=$(cat VERSION)" >> "$GITHUB_OUTPUT"

  - run: echo "Version is ${{ steps.version.outputs.value }}"

Job Outputs (for Cross-Job Communication)

jobs:
  build:
    runs-on: ubuntu-latest
    outputs:
      artifact-id: ${{ steps.upload.outputs.artifact-id }}
    steps:
      - id: upload
        run: echo "artifact-id=abc123" >> "$GITHUB_OUTPUT"

  deploy:
    needs: build
    runs-on: ubuntu-latest
    steps:
      - run: echo "Deploying ${{ needs.build.outputs.artifact-id }}"

Reference Files

FileContents
references/github-actions.mdComplete workflow syntax, reusable workflows, composite actions, OIDC, runners, debugging
references/release-automation.mdSemantic versioning, semantic-release, changesets, goreleaser, changelog, publishing
references/testing-pipelines.mdTest stages, parallelism, coverage, service containers, e2e in CI, deployment pipelines

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.