cicd-golden-pipeline

Automate a compliant GitHub Actions CI/CD pipeline with SSDF checks, SBOM generation, and OSCAL artifacts.

Updated Mar 29, 2026
One-click install
npx skills add https://github.com/doolin/dave-skills --skill cicd-golden-pipeline
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: cicd-golden-pipeline
Source: https://github.com/doolin/dave-skills/tree/main/skills/cicd-golden-pipeline
Command: npx skills add https://github.com/doolin/dave-skills --skill cicd-golden-pipeline

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automates a compliant CI/CD pipeline for GitHub Actions orchestrating federated checks.

Core Features & Use Cases

  • Reusable workflow_call that enforces SSDF-aligned checks, SBOM generation, OSCAL artifact generation, evidence verification, and per-repo deploy/attest steps.
  • Centralized, policy-driven pipeline design that can be copied into multiple repos to ensure consistent security and provenance across pushes and PRs.
  • Machine-readable evidence and OSCAL outputs to support modern risk management and compliance reviews.

Quick Start

Copy the cicd-golden-pipeline skill into your repo and reference the reusable workflow in your GitHub Actions configuration to start enforcing a compliant pipeline.

Frequently Asked Questions about cicd-golden-pipeline

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate OSCAL artifacts and SBOMs in a GitHub Actions CI/CD pipeline?▼

To generate OSCAL artifacts and SBOMs in a GitHub Actions CI/CD pipeline, use a reusable workflow_call that enforces SSDF-aligned checks and orchestrates federated evidence verification across pushes and PRs, producing machine-readable outputs.

What is the best way to align GitHub Actions workflows with SSDF and EO 14028 compliance requirements?▼

Aligning GitHub Actions workflows with SSDF and EO 14028 compliance requirements involves implementing a centralized, policy-driven pipeline design that enforces structured audit events and reproducible evidence bundles for modern risk management.

Can I enforce per-repo IAM roles and evidence verification across multiple GitHub Actions repositories?▼

Yes, you can enforce per-repo IAM roles and evidence verification across multiple GitHub Actions repositories by copying a centralized, policy-driven pipeline into each repo to ensure consistent security and provenance.

Does this compliant pipeline approach support machine-readable outputs for risk management reviews?▼

Yes, this compliant pipeline approach supports risk management reviews by generating machine-readable evidence and OSCAL outputs that satisfy structured audit event requirements and functional compliance checks.

How do I set up a reusable GitHub Actions workflow for federated compliance checks?▼

To set up a reusable GitHub Actions workflow for federated compliance checks, copy the skill into your repository and reference the reusable workflow in your GitHub Actions configuration to start enforcing a compliant pipeline.

Why do I need reproducible evidence bundles and structured audit events in CI/CD?▼

Reproducible evidence bundles and structured audit events in CI/CD are needed to satisfy functional compliance requirements, supporting modern risk management reviews with machine-readable OSCAL outputs and provenance verification.