github-actions
Installation
SKILL.md
GitHub Actions CI/CD
A workflow is config that runs on an event. Before you write a single step, decide three things: which events fire the workflow, what permissions the token needs, and where credentials come from. Get those wrong and you have a fast pipeline that leaks secrets or a secure one nobody can trigger. Everything after that — checkout, install, test, build — is just steps.
This skill owns the workflow layer — the .github/workflows/*.yml files, their triggers, jobs, matrix, caching, secret/OIDC handling, environments and deploy gates. Route the rest out:
| Not this skill | Goes to | Because |
|---|---|---|
The Dockerfile, image build strategy |
../docker/SKILL.md |
The workflow may call docker build; designing the image is not this skill. |
| Branching model, PR hygiene, merge vs rebase, commit conventions | ../git-workflow/SKILL.md |
That is the source-control model, not the CI config layer. |
| Release readiness checklist, changelog, the shipping decision | ../ship/SKILL.md |
Whether to release is a decision; this skill only automates the mechanics. |
| Blue/green, canary, rollback theory | ../deployment/SKILL.md |
Actions triggers the deploy; the strategy is deployment's. |
| Choosing the host and its deploy primitives | ../vercel/SKILL.md, ../aws-essentials/SKILL.md |
Actions triggers the deploy; the host owns the target. |
| Triaging SAST/CVE findings, threat modeling | ../secure-coding/SKILL.md |
This skill runs a scanner as a job; it does not interpret the report. |
Decide the trigger first
Pick the event(s) for each job class before writing YAML — the trigger decides what context and secrets the run gets.