Skip to content
Back to skills

Github Actions

ASecurity

Covers GitHub Actions: workflow YAML, runners, marketplace actions, reusable workflows, composite actions, OIDC authentication, matrix builds, caching, secrets, and environments. WHEN: \"GitHub Actions\", \"workflow\", \".github/workflows\", \"actions/checkout\", \"GitHub runner\", \"reusable workflow\", \"composite action\", \"GitHub OIDC\", \"GitHub secrets\", \"GitHub environments\". Do NOT use for branch strategy, PR review process, or release/tagging policy — use the `github` skill.

  • 4 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 24, 2026
devopsshellbashnodeexpressawstestingdebugginggitapici/cd

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 6 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill github-actions --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Github Actions?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Github Actions
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-github-actions/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-github-actions)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: github-actions
description: "Covers GitHub Actions: workflow YAML, runners, marketplace actions, reusable workflows, composite actions, OIDC authentication, matrix builds, caching, secrets, and environments. WHEN: \"GitHub Actions\", \"workflow\", \".github/workflows\", \"actions/checkout\", \"GitHub runner\", \"reusable workflow\", \"composite action\", \"GitHub OIDC\", \"GitHub secrets\", \"GitHub environments\". Do NOT use for branch strategy, PR review process, or release/tagging policy — use the `github` skill."
license: MIT
---

# GitHub Actions Expert

This skill covers GitHub Actions. GitHub Actions is a managed CI/CD platform integrated into GitHub. It uses YAML workflow files stored in `.github/workflows/`. There is no traditional versioning — GitHub continuously ships updates.

## How to Approach Tasks

1. **Classify** the request:
   - **Troubleshooting** -- Load `references/diagnostics.md` for workflow failures, runner issues, and debugging techniques
   - **Architecture** -- Load `references/architecture.md` for runner internals, event system, expression language, and reusable workflow patterns
   - **Best practices** -- Load `references/best-practices.md` for workflow design, security hardening, performance, and cost optimization

2. **Load context** -- Read the relevant reference file.

3. **Analyze** -- Apply GitHub Actions-specific reasoning. Consider event triggers, runner context, permissions, expression syntax.

4. **Recommend** -- Provide YAML workflow examples with explanations.

5. **Verify** -- Suggest validation steps (act for local testing, workflow dispatch for manual triggers, run logs).

## Core Concepts

### Workflow Structure

```yaml
name: github-actions

on:
  push:
    branches: [main]
  pull_request:
    branches: [main]

permissions:
  contents: read
  packages: write

env:
  NODE_VERSION: '26'

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v6
      - uses: actions/setup-node@v6
        with:
          node-version: ${{ env.NODE_VERSION }}
          cache: 'npm'
      - run: npm ci
      - run: npm test
      - run: npm run build
```

### Event Triggers

| Event | When | Key Options |
|---|---|---|
| `push` | Code pushed | `branches`, `tags`, `paths`, `paths-ignore` |
| `pull_request` | PR opened/updated | `branches`, `types` (opened, synchronize, closed) |
| `workflow_dispatch` | Manual trigger | `inputs` (parameters) |
| `schedule` | Cron | `cron` expression (UTC) |
| `release` | GitHub release created | `types` (published, created) |
| `workflow_call` | Called by another workflow | `inputs`, `outputs`, `secrets` |
| `repository_dispatch` | API webhook | `types` (custom event types) |

### Runner Types

| Runner | OS | Use Case |
|---|---|---|
| `ubuntu-latest` | Ubuntu 24.04 | Default for most workloads |
| `ubuntu-22.04` | Ubuntu 22.04 | Specific OS version |
| `windows-latest` | Windows Server 2022 | .NET, PowerShell |
| `macos-latest` | macOS (Sequoia) | iOS, macOS builds |
| `self-hosted` | Any | Private network, GPU, custom tools |

### Permissions (GITHUB_TOKEN)

Always use least-privilege permissions:

```yaml
permissions:
  contents: read        # Read repo content
  packages: write       # Push container images
  id-token: write       # OIDC for cloud auth
  pull-requests: write  # Comment on PRs
  issues: read          # Read issues
  actions: read         # Read workflow runs
```

**Default**: `contents: read` for PRs from forks, `contents: write` for pushes to the repo.

## Key Patterns

### Matrix Builds

```yaml
jobs:
  test:
    strategy:
      fail-fast: false
      matrix:
        os: [ubuntu-latest, windows-latest]
        node: [24, 26]
        exclude:
          - os: windows-latest
            node: 24
        include:
          - os: ubuntu-latest
            node: 26
            coverage: true
    runs-on: ${{ matrix.os }}
    steps:
      - uses: actions/checkout@v6
      - uses: actions/setup-node@v6
        with:
          node-version: ${{ matrix.node }}
      - run: npm ci && npm test
      - if: ${{ matrix.coverage }}
        run: npm run coverage
```

### Caching

```yaml
- uses: actions/cache@v4
  with:
    path: ~/.npm
    key: npm-${{ runner.os }}-${{ hashFiles('**/package-lock.json') }}
    restore-keys: |
      npm-${{ runner.os }}-
```

### OIDC Authentication (Keyless Cloud Access)

```yaml
permissions:
  id-token: write
  contents: read

steps:
  - uses: aws-actions/configure-aws-credentials@v4
    with:
      role-to-assume: arn:aws:iam::123456789012:role/GitHubActionsRole
      aws-region: us-east-1
      # No static credentials — uses OIDC federation
```

### Reusable Workflows

```yaml
# .github/workflows/reusable-deploy.yml
on:
  workflow_call:
    inputs:
      environment:
        required: true
        type: string
    secrets:
      deploy_key:
        required: true

jobs:
  deploy:
    runs-on: ubuntu-latest
    environment: ${{ inputs.environment }}
    steps:
      - run: echo "Deploying to ${{ inputs.environment }}"

# Caller workflow
jobs:
  deploy-staging:
    uses: ./.github/workflows/reusable-deploy.yml
    with:
      environment: staging
    secrets:
      deploy_key: ${{ secrets.DEPLOY_KEY }}
```

### Composite Actions

```yaml
# .github/actions/setup-project/action.yml
name: github-actions
description: Install dependencies and build
inputs:
  node-version:
    default: '26'
runs:
  using: composite
  steps:
    - uses: actions/setup-node@v6
      with:
        node-version: ${{ inputs.node-version }}
        cache: 'npm'
    - run: npm ci
      shell: bash
    - run: npm run build
      shell: bash
```

### Environments with Approvals

```yaml
jobs:
  deploy-prod:
    runs-on: ubuntu-latest
    environment:
      name: production
      url: https://myapp.example.com
    steps:
      - run: echo "Deploying to production"
```

Configure protection rules in GitHub Settings > Environments:
- Required reviewers
- Wait timer
- Branch restrictions
- Deployment branch policies

### Concurrency Control

```yaml
concurrency:
  group: ${{ github.workflow }}-${{ github.ref }}
  cancel-in-progress: true    # Cancel previous runs on same branch
```

## Expression Language

```yaml
# Context variables
${{ github.sha }}                    # Commit SHA
${{ github.ref_name }}               # Branch or tag name
${{ github.actor }}                  # User who triggered
${{ github.event.pull_request.number }}  # PR number
${{ runner.os }}                     # Runner OS

# Functions
${{ contains(github.event.head_commit.message, '[skip ci]') }}
${{ startsWith(github.ref, 'refs/tags/v') }}
${{ hashFiles('**/package-lock.json') }}
${{ toJSON(matrix) }}
${{ format('Hello {0}', github.actor) }}

# Status check functions (in if:)
if: ${{ success() }}
if: ${{ failure() }}
if: ${{ always() }}
if: ${{ cancelled() }}
```

## Reference Files

- `references/architecture.md` — Event system, runner lifecycle, expression engine, action types, workflow dispatch, webhook payloads
- `references/best-practices.md` — Workflow organization, security hardening (pin actions to SHA), cost optimization, monorepo patterns, reuse strategies
- `references/diagnostics.md` — Workflow debugging, runner connectivity, permission errors, cache misses, action version conflicts

## Diagnostic Scripts

Ready-made gh CLI audits (read-only) in `scripts/`.

- `scripts/01-failed-runs-audit.sh` -- Failed runs and per-workflow failure rates (deterministic vs flaky)
- `scripts/02-workflow-duration-trend.sh` -- Duration stats per workflow (the runner-minutes levers)

Files in this skill

  • SKILL.md7.4 KB
  • references/architecture.md7.3 KB
  • references/best-practices.md5.4 KB
  • references/diagnostics.md5 KB
  • scripts/01-failed-runs-audit.sh1.4 KB
  • scripts/02-workflow-duration-trend.sh1.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…