con un clic
ci-workflows
ci-workflows contiene 22 skills recopiladas de NDDev-it-com, con cobertura ocupacional por repositorio y páginas de detalle dentro del sitio.
Skills en este repositorio
The complete golden-path checklist for any change to the ci-workflows repository — editing a workflow, catalog entry, action pin, doc, or skill — so you touch every layer the catalog-driven pipeline expects and leave the validation gate green. Invoke before you edit.
The end-to-end release procedure for ci-workflows — version prep, the signed SemVer tag, the immutable-release verification checklist, and the post-release runtime-coverage re-promotion. Invoke when cutting or verifying a release. Requires an authorized maintainer.
Orient an agent on the ci-workflows repository in a single read — its catalog-as-source-of-truth architecture, the non-negotiable contracts, the validation gate, and which skill or file to reach for each task. Invoke first when you start work in this repository.
The complete golden-path checklist for any change to the ci-workflows repository — editing a workflow, catalog entry, action pin, doc, or skill — so you touch every layer the catalog-driven pipeline expects and leave the validation gate green. Invoke before you edit.
The end-to-end release procedure for ci-workflows — version prep, the signed SemVer tag, the immutable-release verification checklist, and the post-release runtime-coverage re-promotion. Invoke when cutting or verifying a release. Requires an authorized maintainer.
Orient an agent on the ci-workflows repository in a single read — its catalog-as-source-of-truth architecture, the non-negotiable contracts, the validation gate, and which skill or file to reach for each task. Invoke first when you start work in this repository.
Select and continuously verify zero-cost or bounded-cost CI for public and private repositories using a freshness-enforced fact ledger, normalized resource units, plan gates, and no-surprise-spend controls. Use for CI provider/tier architecture and budgeting.
Select and continuously verify zero-cost or bounded-cost CI for public and private repositories using a freshness-enforced fact ledger, normalized resource units, plan gates, and no-surprise-spend controls. Use for CI provider/tier architecture and budgeting.
Optimize CI latency, throughput, cache behavior, matrices, artifacts, runner capacity, and spend without weakening correctness or trust boundaries. Use for slow, queued, expensive, or quota-constrained pipelines.
Diagnose CI failures and flakes from exact run evidence, separate baseline/environment/regression causes, reproduce minimally, and produce a bounded fix without suppressing signals. Use when a check is red, intermittent, skipped, or unexpectedly green.
Audit a repository’s CI/CD topology, required checks, reusable workflow interfaces, event and tier coverage, runtime evidence, and enforcement gaps. Use for repository onboarding, CI completeness reviews, migration planning, or before changing workflows.
Design and verify deterministic release pipelines with source closure, SBOM, checksums, provenance/attestation plan gates, immutable publication, least privilege, and rollback-safe evidence. Use for releases, packages, containers, or supply-chain audits.
Create executable consumer fixtures for reusable workflows, GitHub event payloads, plan/visibility gates, runners, and destructive release/deploy paths. Use when static CI validators do not prove real caller behavior.
Design or modify secure, deterministic GitHub Actions and reusable workflow_call APIs with least privilege, pinned dependencies, correct event semantics, bounded resources, and testable contracts. Use when implementing or reviewing workflow YAML.
Threat-model and harden GitHub Actions across fork PRs, privileged events, tokens, OIDC, caches, artifacts, actions, runners, environments, and release pipelines. Use for security review, incident prevention, or workflow privilege changes.
Optimize CI latency, throughput, cache behavior, matrices, artifacts, runner capacity, and spend without weakening correctness or trust boundaries. Use for slow, queued, expensive, or quota-constrained pipelines.
Diagnose CI failures and flakes from exact run evidence, separate baseline/environment/regression causes, reproduce minimally, and produce a bounded fix without suppressing signals. Use when a check is red, intermittent, skipped, or unexpectedly green.
Audit a repository’s CI/CD topology, required checks, reusable workflow interfaces, event and tier coverage, runtime evidence, and enforcement gaps. Use for repository onboarding, CI completeness reviews, migration planning, or before changing workflows.
Design and verify deterministic release pipelines with source closure, SBOM, checksums, provenance/attestation plan gates, immutable publication, least privilege, and rollback-safe evidence. Use for releases, packages, containers, or supply-chain audits.
Create executable consumer fixtures for reusable workflows, GitHub event payloads, plan/visibility gates, runners, and destructive release/deploy paths. Use when static CI validators do not prove real caller behavior.
Design or modify secure, deterministic GitHub Actions and reusable workflow_call APIs with least privilege, pinned dependencies, correct event semantics, bounded resources, and testable contracts. Use when implementing or reviewing workflow YAML.
Threat-model and harden GitHub Actions across fork PRs, privileged events, tokens, OIDC, caches, artifacts, actions, runners, environments, and release pipelines. Use for security review, incident prevention, or workflow privilege changes.