github-actions-ci
Installation
SKILL.md
Instructions
When to Use
- Use for PR CI: lint, typecheck, test, build, cache.
- Prefer
secure-dependenciesfor audit/frozen lockfile policy. - Prefer
monorepo-toolingfor turbo task graphs first.
Add or improve GitHub Actions for a Next.js + pnpm repo.
- Workflow permissions: default
contents: readat workflow or job level; elevateid-tokenorpackagesonly where OIDC/npm publish needs it - least privilege. - Concurrency:
group: ${{ github.workflow }}-${{ github.ref }}+cancel-in-progress: trueon PR workflows to save minutes and avoid stale deploys. - Triggers:
pull_request+pushtomain; optionalworkflow_dispatch. - pnpm:
pnpm/action-setup+ cache viapnpm store pathor built-in cache; alwayspnpm install --frozen-lockfilein CI. - Jobs:
lint→typecheck→test→buildwithneedswhere parallel is impossible; optional parallelauditjob (pnpm audit --audit-level=highor org policy) - seesecure-dependencies. - Next build: set
NODE_OPTIONSonly if required; artifactnext buildtrace for failures optional. - Fork PRs:
pull_request_targetavoided unless user understands risk; defaultpull_request. - Node version: pin
22or20LTS withactions/setup-nodeand matchenginesinpackage.json.