← ClaudeAtlas

github-actions-pipelinelisted

Design, write, or fix GitHub Actions workflows for a project: a CI pipeline with the right triggers, concurrency, caching, matrix, and least-privilege permissions; pinned actions; reusable workflows and composite actions; deploy workflows with environments and OIDC instead of long-lived secrets; and the debugging moves for slow, flaky, or failing runs. Use when adding CI to a repository, when a pipeline is slow or flaky, when a workflow needs deploy or release steps, or when a security review flags workflow permissions.
KhaledSaeed18/dotclaude · ★ 5 · Code & Development · score 80
Install: claude install-skill KhaledSaeed18/dotclaude
A pipeline is trusted when it is fast enough to run on every push, deterministic enough that a red is a real failure, and locked down enough that a compromised dependency cannot use it. Design for those three before adding steps. ## A CI workflow skeleton ```yaml name: ci on: pull_request: push: branches: [main] permissions: contents: read # top-level default; widen per job only concurrency: group: ci-${{ github.workflow }}-${{ github.ref }} cancel-in-progress: ${{ github.event_name == 'pull_request' }} jobs: test: runs-on: ubuntu-latest timeout-minutes: 15 strategy: fail-fast: false matrix: node: [20, 22] steps: - uses: actions/checkout@v4 # pin to a SHA in security-sensitive repos - uses: pnpm/action-setup@v4 - uses: actions/setup-node@v4 with: node-version: ${{ matrix.node }} cache: pnpm - run: pnpm install --frozen-lockfile - run: pnpm lint - run: pnpm typecheck - run: pnpm test -- --reporter=junit --outputFile=junit.xml - uses: actions/upload-artifact@v4 if: always() with: { name: test-results-${{ matrix.node }}, path: junit.xml } ``` ## Rules **Triggers** - `pull_request` for validation, `push` to the default branch for post-merge and deploy, `workflow_dispatch` for manual runs, `schedule` for nightly or dependency checks. Path filters (`paths:`) to skip irrelevant runs, remembering that a required check t