agentsclimarketplace

Cicd pipeline

Skill valdomirosouza/agent-skills/skills/cicd-pipeline

Expert AI Agent Skills for SDD, SRE, DevSecOps and Enterprise Engineering

Install
npx -y skills add valdomirosouza/agent-skills --skill cicd-pipeline

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Defines and validates CI/CD pipeline standards — stage sequencing, quality gates, branch strategy, deployment strategies (canary, blue-green), and artifact signing. Use when designing or reviewing a CI/CD pipeline, configuring quality gates, defining branch protection rules, setting up canary deployments, implementing SBOM generation, or ensuring a pipeline meets enterprise security and reliability standards.

SKILL.md

5.2 KB, as published. Nobody here has run it

CI/CD Pipeline

Contents

  • Mandatory pipeline stages (in order)
  • Quality gates — all blocking
  • Branch strategy
  • Deployment strategies
  • Artifact integrity (signing + SBOM)

Mandatory Pipeline Stages

stages:
  - name: validate
    steps:
      - lint                      # Language-specific
      - type-check
      - dependency-audit          # Known vulnerability scan
      - secret-detection          # gitleaks / truffleHog
      - spec-compliance-check     # Validates AI traceability header

  - name: test
    steps:
      - unit-tests                # Coverage ≥ 80%
      - integration-tests
      - contract-tests            # Pact / OpenAPI
      - observability-validation  # Log schema, metric labels, trace propagation

  - name: security
    steps:
      - SAST                      # Semgrep / SonarQube / Checkmarx
      - SCA                       # OWASP Dependency Check / Snyk
      - container-scan            # Trivy / Grype
      - IaC-scan                  # Checkov / tfsec
      - license-check             # FOSSA / license-checker

  - name: build
    steps:
      - build-artifact
      - sign-artifact             # Cosign / Sigstore (SLSA)
      - generate-SBOM             # Syft / CycloneDX
      - push-to-registry

  - name: staging-deploy
    environment: staging
    steps:
      - deploy
      - smoke-tests
      - DAST                      # OWASP ZAP full scan
      - performance-baseline

  - name: production-deploy
    environment: production
    requires: [manual-approval, RFC-approved]
    strategy: canary              # 5% → 25% → 100%
    steps:
      - deploy
      - golden-signal-monitoring  # 15 min observation window
      - auto-rollback-if-slo-breach

Quality Gates — All Blocking

GateCriterionBlocks
LintZero critical rule warningsYes
TestsCoverage ≥ 80%, zero failuresYes
SASTZero CRITICAL/HIGH findingsYes
SecretsZero secrets detectedYes
ContainerZero critical CVEs in base imageYes
SBOMGenerated and signedYes
Human reviewMinimum 1 reviewerYes
DASTZero OWASP Top 10 critical findingsYes (staging)
Error budgetBudget > 10%Yes (production)
RFCRFC approved for Normal/Emergency changesYes (production)

Branch Strategy

main ──────────────────────────────────────── (production — full protection)
  └── release/YYYY-MM-DD ─────────────────── (staging)
        └── feature/SPEC-NNN-description ─── (development)
        └── fix/SPEC-NNN-description ──────── (bugfix)
        └── hotfix/SPEC-NNN-description ───── (hotfix — direct merge to main)

Branch protection rules (main):

  • Require PR — no direct push
  • Minimum 1 approved review
  • All status checks passing
  • No force-push
  • Require linear history

Deployment Strategies

Canary (default for production):

Step 1: 5% of traffic → new version
  └── Monitor Golden Signals for 15 min
Step 2: 25% → if SLO maintained
  └── Monitor for 15 min
Step 3: 100% → if SLO maintained
Auto-rollback: if error rate > SLO threshold at any step

Blue-Green (for stateful services or DB migrations):

1. Deploy new version (green) alongside current (blue)
2. Run smoke tests on green
3. Switch load balancer to green
4. Keep blue running for 30 min (fast rollback)
5. Decommission blue

Feature flags (for all new features):

  • Deploy to 100% of instances with flag OFF
  • Enable progressively per user segment / % of traffic
  • Flag owner and expiry date required

Artifact Integrity

# Generate SBOM
syft . -o cyclonedx-json > sbom.json

# Sign artifact with Cosign (SLSA provenance)
cosign sign --key cosign.key registry.example.com/service:sha256-...

# Verify on deploy
cosign verify --key cosign.pub registry.example.com/service:sha256-...

SLSA target: Level 3 (hermetic builds, signed provenance, auditable build process)


Change Type Integration

# Pipeline behavior per change type
standard_change:
  label: "standard-change"
  approval: Automatic if pipeline green and spec referenced
  restriction: Deploy only in defined windows (Mon-Thu, 10:00-17:00)

normal_change:
  label: "normal-change"
  approval: RFC approved by CAB required before merge
  block: Pipeline rejects deploy without RFC_ID in commit message

emergency_change:
  label: "emergency-change"
  approval: TL + SecOps async approval in #cab-emergency
  audit: Emergency RFC generated retroactively within 24h
  postmortem: Mandatory even if change successful

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.