github-actions-pipeline-hardened

Installation
SKILL.md

GitHub Actions Pipeline (Hardened)

When to use

Invoke when authoring CI/CD for a new service or when an existing pipeline lacks supply-chain controls (unpinned actions, long-lived cloud secrets, wide-open permissions). Use after the Dockerfile and tests exist.

Inputs

  • Project type: Maven/Gradle.
  • Target container registry (e.g., GHCR, ECR, GAR).
  • Target cloud account and the OIDC trust relationship name.

Output contract

Generated workflows MUST conform to:

  • deployment-standards — required CI gates: lint, unit, integration (Testcontainers), build artifact, SCA, container scan, SAST, OpenAPI lint (when relevant), migration plan review. CI does not push to environments; CD is a separate pipeline.
  • security-standards — actions pinned by SHA, OIDC for cloud auth (no long-lived keys), signed artifacts (cosign/Sigstore), secret scanning in pre-commit + CI.
  • naming-conventions — workflow filenames kebab-case, env vars SCREAMING_SNAKE_CASE.
Installs
3
GitHub Stars
12
First Seen
Jun 10, 2026
github-actions-pipeline-hardened — amritmalla/claude-full-stack-2.0