depot-github-actions
Installation
SKILL.md
Depot GitHub Actions
Use this skill when reviewing or changing GitHub Actions workflows for Depot runners, accelerated file caching, or container builds. Treat a migration as a behavior-preserving repository change, not a label substitution.
Operating sequence
- Inventory the complete workflow graph: both workflow extensions, triggers, permissions, environments, matrices, reusable callers and callees, expressions, cache steps, builds, publications, outputs, and downstream consumers.
- Resolve every affected edge. If an expression or unavailable reusable workflow makes topology dynamic, name the file and job and block affected edits.
- Collect applicable evidence. Runner work needs verified Depot App installation, repository access, runner group, documented runner label, and repository pin policy. Require project, OIDC, registry, and publication evidence only where the affected seam uses it; record irrelevant evidence as
N/A. - Classify the seam using runners, cache, container builds, and security and validation.
- For implementation, capture hashes of every target, re-read immediately before mutation, and stop on concurrent drift. Apply a transactional, minimal patch only after all evidence and equivalence gates pass.
- Inspect the diff and run repository-native validation. Report commands and observed results truthfully. A blocked path remains byte-identical.