SKILL.md
CI Hardener
Optimize and harden Continuous Integration (CI) workflows.
Workflow
- Audit Current Workflows
List all workflows in .github/workflows/. Identify: - Triggers: Are they correct (push, pull_request)? - Jobs: Are they parallelized? - Steps: Are they caching dependencies?
- Apply Hardening Patterns
- Caching: Use actions/setup-node with cache: 'pnpm' and pnpm/action-setup. - Timeouts: Set timeout-minutes on every job to prevent hangs. - Concurrency: Use concurrency groups to cancel outdated runs on PRs. - Permissions: Use least-privilege permissions blocks.
- Optimize Speed
- Run independent jobs (lint, Test) in parallel. - Make Build depend on Test and Lint. - Use pnpm install --frozen-lockfile for deterministic installs.
- Verify
Ensure the changes are valid YAML and follow GitHub Actions syntax.
Checklist
-
timeout-minutesis set. -
concurrencyis set for PRs. -
actions/checkoutusesfetch-depth: 0if needed (otherwise default is 1). -
pnpm install --frozen-lockfileis used. - Node version is pinned (e.g.,
node-version: 20).
Example
Input: "The build takes too long because it installs dependencies in every job."
Action: Update .github/workflows/main.yml:
jobs:
install:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v2
- uses: actions/setup-node@v6
with:
node-version: '20'
cache: 'pnpm'
- run: pnpm install --frozen-lockfile
# Cache node_modules for other jobs if needed, or rely on setup-node cache
Output: "Added pnpm/action-setup with caching to the install step. This will speed up subsequent runs by reusing the pnpm cache."
Skill sync: compatible with React 19.2.8 / Vite 8.2.2 / Tailwind 4.3.3 baseline as of 2026-05-20.