github-actions-pipelinelisted
Install: claude install-skill KhaledSaeed18/dotclaude
A pipeline is trusted when it is fast enough to run on every push, deterministic enough that a red is a real failure, and locked down enough that a compromised dependency cannot use it. Design for those three before adding steps.
## A CI workflow skeleton
```yaml
name: ci
on:
pull_request:
push:
branches: [main]
permissions:
contents: read # top-level default; widen per job only
concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
test:
runs-on: ubuntu-latest
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
node: [20, 22]
steps:
- uses: actions/checkout@v4 # pin to a SHA in security-sensitive repos
- uses: pnpm/action-setup@v4
- uses: actions/setup-node@v4
with:
node-version: ${{ matrix.node }}
cache: pnpm
- run: pnpm install --frozen-lockfile
- run: pnpm lint
- run: pnpm typecheck
- run: pnpm test -- --reporter=junit --outputFile=junit.xml
- uses: actions/upload-artifact@v4
if: always()
with: { name: test-results-${{ matrix.node }}, path: junit.xml }
```
## Rules
**Triggers**
- `pull_request` for validation, `push` to the default branch for post-merge and deploy, `workflow_dispatch` for manual runs, `schedule` for nightly or dependency checks. Path filters (`paths:`) to skip irrelevant runs, remembering that a required check t