github-actions-pipeline-hardened
Installation
SKILL.md
GitHub Actions Pipeline (Hardened)
When to use
Invoke when authoring CI/CD for a new service or when an existing pipeline lacks supply-chain controls (unpinned actions, long-lived cloud secrets, wide-open permissions). Use after the Dockerfile and tests exist.
Inputs
- Project type: Maven/Gradle.
- Target container registry (e.g., GHCR, ECR, GAR).
- Target cloud account and the OIDC trust relationship name.
Output contract
Generated workflows MUST conform to:
- deployment-standards — required CI gates: lint, unit, integration (Testcontainers), build artifact, SCA, container scan, SAST, OpenAPI lint (when relevant), migration plan review. CI does not push to environments; CD is a separate pipeline.
- security-standards — actions pinned by SHA, OIDC for cloud auth (no long-lived keys), signed artifacts (cosign/Sigstore), secret scanning in pre-commit + CI.
- naming-conventions — workflow filenames
kebab-case, env varsSCREAMING_SNAKE_CASE.