ci-pipeline-synthesizer — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ci-pipeline-synthesizer (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Generate production-ready GitHub Actions workflow files for library and package projects with automated build and test stages, dependency caching, and multi-version testing matrices.
Determine the package ecosystem by examining project files:
package.json presentsetup.py, pyproject.toml, or requirements.txt presentgo.mod presentCargo.toml presentUse the appropriate template from assets/ based on project type:
github-actions-nodejs.yml - Node.js/npm packagesgithub-actions-python.yml - Python packagesgithub-actions-go.yml - Go modulesgithub-actions-rust.yml - Rust cratesAdapt the template to project-specific needs:
Test commands: Update test scripts to match project conventions
npm test, npm run test:coveragepytest, python -m unittestgo test ./...cargo testBuild commands: Adjust build steps if needed
npm run build (if build step exists)python -m buildgo buildcargo build --releaseVersion matrix: Modify tested versions based on support policy
Trigger conditions: Adjust when pipeline runs
Create the workflow file at .github/workflows/ci.yml in the project root. If .github/workflows/ doesn't exist, create the directory structure first.
Check that the generated workflow:
actions/checkout@v4, actions/setup-node@v4)All templates include:
Add code coverage reporting:
- name: Upload coverage to Codecov
uses: codecov/codecov-action@v3
with:
file: ./coverage.xmlAdd linting step:
- name: Run linter
run: npm run lint # or: pylint, golangci-lint, cargo clippyRestrict to specific branches:
on:
push:
branches: [main, develop]
pull_request:
branches: [main]Add scheduled runs:
on:
schedule:
- cron: '0 0 * * 0' # Weekly on Sundayactions/cache for dependencies to reduce build times~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.