ci-pipeline-and-gates
Installation
SKILL.md
CI Pipeline & Gates
A CI gate is not a decorative green check — it converts one release-blocking contract into a check a build either passes or fails, without trusting a human. Keep the pipeline lean: one workflow file for most single-package apps, every job pinned, every gate traceable to a named contract, and an honest note wherever CI cannot prove the thing that actually matters.
Read the reference for the task at hand:
references/workflow-skeleton.md— the copy-paste single-fileci.yml: pinned runner + toolchain, freshness gates, format/analyze, randomized tests, host-sqlite, coverage-strip, and the release-build job.references/policy-grep-gate.md— the grep-based invariant gate: the three-criteria bar, strip-comments-first, anchor-to-structure, accumulate-and-fail-once, write-the-reason-for-a-stranger.
Run scripts/ci-gates.sh and scripts/banned-strings.sh before a PR to reproduce the static gates locally.