Skip to content
Back to skills

Ci Setup

ASecurity

Add a CI workflow that builds, lints, and tests the project on every push and PR

  • 3 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 3, 2026
ai-agentspythongonodegit

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill ci-setup --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ci Setup?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ci Setup
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-ci-setup/badge)](https://www.skillsdirectory.com/skills/black141312-ci-setup)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ci-setup
description: Add a CI workflow that builds, lints, and tests the project on every push and PR
category: ci-cd
---

# CI Setup

Reach for this when a repo has no continuous integration and you want every push/PR to build, lint, and test automatically.

1. Detect the stack and its scripts: read the manifest (`package.json`, `pyproject.toml`, `go.mod`, `Cargo.toml`, `Makefile`) to find the real build/lint/test commands.
2. Pick the CI provider already implied by the host (GitHub -> Actions in `.github/workflows/`, GitLab -> `.gitlab-ci.yml`) rather than introducing a new one.
3. Write one workflow triggered on `push` to the default branch and on `pull_request`, running on the matching runner image.
4. Order jobs/steps as checkout -> setup runtime (pinned version) -> restore dependency cache -> install -> lint -> build -> test.
5. Run lint/build/test as the SAME commands a developer runs locally, so green CI means a green local checkout.
6. Commit, push a branch, open a PR, and confirm the workflow actually ran and passed before declaring done.

## Rules
- Pin runtime versions (Node 20, Python 3.12) — never rely on the runner default drifting.
- Reuse existing npm/make scripts; do not hardcode a parallel command that can silently diverge.
- Make the job fail loudly: no `|| true`, no `continue-on-error` on the steps that gate quality.
- Enable dependency caching keyed on the lockfile hash to keep runs fast.
- Keep secrets out of the YAML; reference provider secret stores, never inline tokens.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…