git:20260718.bab1220 to git:20260726.40e457e

3 added, 0 removed. Audit A to A.

---
name: github-actions
description: Use when adding CI/CD, creating workflows, auditing GitHub Actions, or fixing action pinning. Creates and audits workflows for SHA pinning and permissions.
+ license: MIT
allowed-tools: Read Glob Grep Edit Write Bash(gh:*)
model: sonnet
effort: high
context: fork
agent: general-purpose
compatibility: Targets GitHub Actions (GitHub-native); uses gh for SHA lookups; auto-detects project language (Node/JS-TS, Go, Python, Rust, Ruby)
+ metadata:
+ short-description: Create and audit CI workflows.
---
## Mode Detection
Classify the request before acting, and default to read-only when intent is ambiguous or diagnostic:
- **Create mode**: The user explicitly asks to create, add, generate, scaffold, or set up a workflow, CI, or a CI/CD pipeline (e.g. "set up CI") — regardless of whether a `.github/workflows/` directory already exists. Generates workflows and pins every action to a full commit SHA per `rules/action-pinning.md`.
- **Audit (read-only, default)**: The user asks to audit/review/check/diagnose existing workflows, or the request is ambiguous. Produce an evidence-backed report and make NO file edits — this holds even when no `.github/workflows/` directory exists (report that none were found rather than generating one).
- **Fix**: The user explicitly asks to fix, pin, apply, or says "audit and fix". Only then apply the scoped edits in Audit Mode's Auto-Fix step.
When intent is ambiguous, stay in Audit mode and end the report by offering to apply the fixes.
---
## Create Mode
### 1. Detect Project Type
Scan for project indicators:
- `package.json` → Node.js/JS/TS
- `go.mod` → Go
- `requirements.txt` / `pyproject.toml` / `setup.py` → Python
- `Cargo.toml` → Rust
- `Gemfile` → Ruby
### 2. Detect Package Manager (JS/TS projects)
- `pnpm-lock.yaml` → pnpm
- `bun.lock` / `bun.lockb` → bun
- `yarn.lock` → yarn
- `package-lock.json` → npm
### 3. Generate Workflow
Apply all rules from the `rules/` directory when generating workflows. Read each rule file for detailed requirements and examples.
Pin every action per `rules/action-pinning.md` before writing the workflow, including GitHub-owned `actions/*`. Resolve the intended release or source ref to a full commit SHA with `gh api repos/{owner}/{repo}/commits/{ref} --jq '.sha'`, then retain the release or source ref in a comment.
### 4. Workflow Template
Route by the language detected in Step 1. The template below is the **JS/TS default**; for any other detected language, load `references/<lang>.md` and use its template instead:
| Language | Template |
|----------|----------|
| **JS/TS** (Node) | the template below |
| **Go** | `references/go.md` |
| **Python** | `references/python.md` |
| **Rust** | `references/rust.md` |
| **Ruby** | `references/ruby.md` |
Every template applies the same `rules/` (action pinning, `permissions`, concurrency). Adapt the JS/TS template to the detected package manager (replace `<pm>` with the detected package manager):
```yaml
name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
ci:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 'lts/*'
cache: '<pm>'
- run: <pm> install --frozen-lockfile
- run: <pm> check
- run: <pm> test
- run: <pm> build
```
---
## Audit Mode
### 1. Scan Workflows
Read all `.yml` and `.yaml` files in `.github/workflows/` and audit against every rule in the `rules/` directory.
### 2. Report Format
```
## GitHub Actions Audit Results
### HIGH Severity
- `.github/workflows/ci.yml:15` - `codecov/codecov-action@v4` → pin to commit SHA
### MEDIUM Severity
- `.github/workflows/ci.yml` - Missing concurrency group → add concurrency block
### Summary
- High: X
- Medium: Y
- Low: Z
- Files scanned: N
```
### 3. Auto-Fix (fix mode only)
Skip this step entirely in Audit mode — report **all** rule violations found in the audit (pinning, permissions, concurrency, node version, caching, triggers, and matrix), not just pinning and permissions. Only apply fixes when the request is in Fix mode (see Mode Detection). When fixing, look up commit SHAs for pinning using `gh api`.
---
## Rules
Read individual rule files for detailed checks and examples:
| Rule | Impact | File |
|------|--------|------|
| Action pinning | HIGH | `rules/action-pinning.md` |
| Permissions | HIGH | `rules/permissions.md` |
| Concurrency | MEDIUM | `rules/concurrency.md` |
| Node version | MEDIUM | `rules/node-version.md` |
| Caching | MEDIUM | `rules/caching.md` |
| Triggers | LOW | `rules/triggers.md` |
| Matrix strategy | LOW | `rules/matrix.md` |
---
## Compatibility
GitHub Actions is a GitHub-native CI system — this skill targets it specifically, and `gh` is used to look up action commit SHAs. Project **language** is auto-detected (Node/JS-TS, Go, Python, Rust, Ruby), so the generated workflow adapts across ecosystems — the JS/TS template is inline in Create Mode and per-language templates live in `references/<lang>.md`. GitLab CI and other CI systems are separate and out of scope here.