CI Hardener
Optimize and harden Continuous Integration (CI) workflows.
Workflow
Audit Current Workflows
List all workflows in .github/workflows/. Identify:
- Triggers: Are they correct (push, pull_request)?
- Jobs: Are they parallelized?
- Steps: Are they caching dependencies?
Apply Hardening Patterns
- Caching: Use
actions/setup-node with cache: 'pnpm' and pnpm/action-setup.
- Timeouts: Set
timeout-minutes on every job to prevent hangs.
- Concurrency: Use
concurrency groups to cancel outdated runs on PRs.
- Permissions: Use least-privilege
permissions blocks.
Optimize Speed
- Run independent jobs (
lint, Test) in parallel.
- Make
Build depend on Test and Lint.
- Use
pnpm install --frozen-lockfile for deterministic installs.
Verify
Ensure the changes are valid YAML and follow GitHub Actions syntax.
Checklist
Example
Input: "The build takes too long because it installs dependencies in every job."
Action:
Update .github/workflows/main.yml:
jobs:
install:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v2
- uses: actions/setup-node@v6
with:
node-version: '20'
cache: 'pnpm'
- run: pnpm install --frozen-lockfile
# Cache node_modules for other jobs if needed, or rely on setup-node cache
Output:
"Added pnpm/action-setup with caching to the install step. This will speed up subsequent runs by reusing the pnpm cache."
Skill sync: compatible with React 19.2.8 / Vite 8.2.2 / Tailwind 4.3.3 baseline as of 2026-05-20.