cicd-pipelines — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cicd-pipelines (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A unified skill for CI/CD pipeline design, DevOps automation, infrastructure as code, GitOps deployment automation, security scanning, and enterprise pipeline readiness across major platforms.
Use this skill when:
For Dockerfile design, Docker Compose, local container environments, or container runtime architecture, switch to docker-containerization.
Decision tree:
What are you building?
+-- Node.js/Frontend --> templates/github-actions/node-ci.yml | templates/gitlab-ci/node-ci.yml
+-- Python --> templates/github-actions/python-ci.yml | templates/gitlab-ci/python-ci.yml
+-- Go --> templates/github-actions/go-ci.yml | templates/gitlab-ci/go-ci.yml
+-- Container image pipeline --> templates/github-actions/docker-build.yml | templates/gitlab-ci/docker-build.yml
+-- Security Scanning --> templates/github-actions/security-scan.yml | templates/gitlab-ci/security-scan.ymlBasic pipeline structure:
# 1. Fast feedback (lint, format) - <1 min
# 2. Unit tests - 1-5 min
# 3. Integration tests - 5-15 min
# 4. Build artifacts
# 5. E2E tests (optional, main branch only) - 15-30 min
# 6. Deploy (with approval gates)Quick wins checklist:
needs dependenciesnpm ci instead of npm installAnalyze existing pipeline:
# Use the pipeline analyzer script
python3 scripts/pipeline_analyzer.py --platform github --workflow .github/workflows/ci.ymlEssential security checklist:
OIDC Authentication (GitHub Actions to AWS):
permissions:
id-token: write
contents: read
steps:
- uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: arn:aws:iam::123456789:role/GitHubActionsRole
aws-region: us-east-1| Domain | Tools & Technologies |
|---|---|
| CI/CD Platforms | GitHub Actions, GitLab CI, Jenkins |
| Infrastructure as Code | Terraform, AWS CDK, CloudFormation, Pulumi |
| Container Pipeline Integration | Image build/publish steps, Trivy/Snyk scanning, Cosign signing, Kubernetes/Helm deploy jobs |
| GitOps | ArgoCD, Flux |
| Security Scanning | CodeQL, Semgrep, Trivy, Snyk, TruffleHog |
| Cloud Platforms | AWS, Azure, GCP, Cloudflare |
| Release Artifacts & Provenance | Cosign, SLSA, signed tags, reproducible build checks |
Code Commit --> Build --> Test --> Security Scan --> Package
|
Monitor <-- Release Staging <-- Smoke Tests <-- Deploy Dev
|
Manual Approval
|
Deploy ProductionApp Repo --CI--> Config Repo --ArgoCD--> K8s Cluster
^ |
+----Continuous Sync-----+references/best_practices.md - Pipeline design patterns, testing strategies, deployment workflowsreferences/optimization.md - Caching strategies, parallelization, build performancereferences/troubleshooting.md - Common issues, debugging, platform-specific problemsreferences/cicd-github-actions.md - GitHub Actions workflows, runners, secretsreferences/security.md - Secrets management, OIDC, supply chain securityreferences/devsecops.md - SAST, DAST, SCA, container scanning guidereferences/devsecops-basics.md - Security best practices, shift-left securityreferences/security-hardening.md - TLS enforcement, input validation, headersreferences/terraform-eks-module.tf - Production EKS cluster Terraformreferences/kubernetes-deployment.yaml - Example manifest deployed by pipelinesreferences/kubernetes-basics.md - Kubernetes concepts needed to understand deployment jobsreferences/docker-basics.md - Pipeline-adjacent container concepts; use docker-containerization for Dockerfile designreferences/docker-compose.md - Pipeline-adjacent compose references; use docker-containerization for local container environmentsreferences/aws-overview.md - AWS fundamentals, IAM, servicesreferences/gcloud-platform.md - GCP overview, gcloud CLIreferences/cloudflare-workers-basics.md - Edge computing, Workersreferences/general.md - Universal enterprise readiness checksreferences/github.md - GitHub-specific enterprise requirementsreferences/openssf-badge-silver.md - Silver badge criteriareferences/openssf-badge-gold.md - Gold badge criteriareferences/signed-releases.md - Artifact and tag signingreferences/reproducible-builds.md - Deterministic build patternsreferences/signed-releases.md - Artifact and tag signingreferences/reproducible-builds.md - Deterministic build patterns| Template | Description |
|---|---|
templates/github-actions/node-ci.yml | Complete Node.js CI/CD with security scanning |
templates/github-actions/python-ci.yml | Python pipeline with pytest, coverage, PyPI |
templates/github-actions/go-ci.yml | Go pipeline with multi-platform builds |
templates/github-actions/docker-build.yml | Docker build with multi-platform, signing |
templates/github-actions/security-scan.yml | Comprehensive DevSecOps pipeline |
templates/github-actions/dco-check.yml | DCO sign-off enforcement |
| Template | Description |
|---|---|
templates/gitlab-ci/node-ci.yml | GitLab CI Node.js pipeline |
templates/gitlab-ci/python-ci.yml | Python pipeline with parallel testing |
templates/gitlab-ci/go-ci.yml | Go pipeline with Kubernetes deployment |
templates/gitlab-ci/docker-build.yml | Docker build with DinD, multi-arch |
templates/gitlab-ci/security-scan.yml | DevSecOps with GitLab security templates |
| Template | Description |
|---|---|
templates/GOVERNANCE.md | Project governance documentation |
templates/ARCHITECTURE.md | Technical architecture template |
templates/CODE_OF_CONDUCT.md | Contributor Covenant v2.1 |
templates/SECURITY_AUDIT.md | Security self-audit template |
| Script | Description |
|---|---|
scripts/pipeline_analyzer.py | Analyze workflows for optimization opportunities |
scripts/ci_health.py | Check pipeline status and identify issues |
scripts/validate-devops-skill.sh | Validate DevOps configurations |
| Script | Description |
|---|---|
scripts/verify-badge-criteria.sh | OpenSSF Badge verification |
scripts/check-coverage-threshold.sh | Statement coverage validation |
scripts/check-branch-coverage.sh | Branch coverage analysis |
scripts/verify-signed-tags.sh | Git tag signature verification |
scripts/verify-review-requirements.sh | PR review requirements check |
scripts/check-tls-minimum.sh | TLS 1.2+ enforcement check |
scripts/verify-spdx-headers.sh | SPDX license header verification |
scripts/add-spdx-headers.sh | Add SPDX headers to files |
| Script | Description |
|---|---|
scripts/cloudflare_deploy.py | Cloudflare Worker deployments |
scripts/docker_optimize.py | Dockerfile analysis and optimization |
| Anti-Pattern | Symptom | Fix |
|---|---|---|
| YAML copy-paste proliferation | Identical workflows duplicated across repos | Reusable workflows, Helm charts, Kustomize bases, Terraform modules |
| Hardcoded secrets in code | API keys/passwords committed to git | Secret managers (Vault, AWS SM), sealed secrets, env vars from secure sources |
| No rollback strategy | No plan for deployment failure | Blue/green, canary with automated rollback, ArgoCD auto-revert |
| Monolithic CI pipeline | Single 45-minute pipeline on every commit | Parallel jobs, caching, incremental builds, path-based triggers |
| Running as root in containers | No USER instruction, privileged pods | Add USER instruction, set securityContext.runAsNonRoot: true |
| Using :latest tags | FROM node:latest in production | Pin specific versions, use immutable tags with SHA digests |
| Script injection vulnerability | ${{ github.event.* }} directly in run: blocks | Use environment variables instead (see below) |
| Missing resource limits | Pods consume unbounded resources | Set requests and limits for CPU/memory in all deployments |
| Unpinned GitHub Actions | uses: actions/checkout@v4 without SHA | Pin to commit SHA: uses: actions/checkout@b4ffde6 |
Script injection fix:
# DANGEROUS
- run: echo "Title: ${{ github.event.issue.title }}"
# SAFE
- name: Process issue
env:
TITLE: ${{ github.event.issue.title }}
run: echo "Title: $TITLE"gh workflow list # List workflows
gh run list --limit 20 # View recent runs
gh run view <run-id> # View specific run
gh run rerun <run-id> --failed # Re-run failed jobs
gh run view <run-id> --log > logs.txt # Download logs
gh workflow run ci.yml # Trigger workflow manuallygl project-pipelines list # View pipelines
gl project-pipeline get <id> # Pipeline status
gl project-pipeline retry <id> # Retry failed jobs
gl project-pipeline cancel <id> # Cancel pipelinedocker build -t myapp . # Build image
docker run -p 3000:3000 myapp # Run container
docker compose up -d # Start multi-container app
docker scout cves myapp # Scan for vulnerabilitieskubectl apply -f deployment.yaml # Apply manifest
kubectl get pods,services # Check status
kubectl logs -f <pod> # Stream logs
kubectl rollout status deployment/app # Check rolloutterraform init # Initialize
terraform plan # Preview changes
terraform apply # Apply changes
terraform state list # List resources[ ] All secrets in secret management (not in code)
[ ] Resource limits defined for all containers
[ ] Health checks configured (liveness, readiness)
[ ] Horizontal pod autoscaling enabled
[ ] Security contexts set (non-root, read-only)
[ ] Monitoring and alerting configured
[ ] Rollback strategy documented
[ ] Multi-environment support (dev, staging, prod)
[ ] Concurrency controls in CI pipelines
[ ] Remote state backend for Terraform
[ ] Vulnerability scanning in pipeline
[ ] Version pinning for all dependencies
[ ] Branch protection enabled
[ ] Code review required before merge| Need | Choose |
|---|---|
| Sub-50ms latency globally | Cloudflare Workers |
| Serverless functions (AWS) | AWS Lambda |
| Containerized workloads | AWS ECS/Fargate, GKE, AKS |
| Kubernetes at scale | AWS EKS, Azure AKS, GCP GKE |
| Object storage (zero egress) | Cloudflare R2 |
| Managed SQL | AWS RDS, Azure SQL, Cloud SQL |
| GitHub-integrated CI/CD | GitHub Actions |
| Self-hosted CI/CD | GitLab CI, Jenkins |
| Kubernetes GitOps | ArgoCD, Flux |
| Predictable workloads | Reserved Instances, Savings Plans |
| Fault-tolerant workloads | Spot Instances, Preemptible VMs |
templates/scripts/pipeline_analyzer.pyreferences/troubleshooting.mdreferences/security.md and references/devsecops.mdreferences/general.md checklistgit-workflow for changelog, semantic version, and commit convention workflowsThis curated skill combines content from the following legacy skills (now part of cicd-pipelines):
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.