Github Actions

Write, review, and harden GitHub Actions workflows against supply-chain attacks, and bump a whole fleet of repos' action pins to the latest versions. Use when writing or editing a workflow YAML (.github/workflows/*.yml, ci.yml), when asked to review a CI workflow or audit GitHub Actions security, when the ci-action-ref-reminder hook fires, or when the user wants to "bump my actions", "update the fleet", "pin actions to SHAs", run zizmor, or close supply-chain / pull_request_target / script-injection / GITHUB_TOKEN-permissions gaps. Pairs with references/security-checklist.md (the full checklist) and dev-env-setup's CI templates.

mickzijdel 0770441 2 files · 16.6 KB Updated

File contents

mickzijdel/dev-hooks/tree/main/plugins/dev-hooks/skills/github-actions commit 07704418b5

Frequently asked questions

npx skillmds@latest add mickzijdel/github-actions