cicd-golden-pipeline

Automate a compliant GitHub Actions CI/CD pipeline with SSDF checks, SBOM generation, and OSCAL artifacts.

Updated Mar 29, 2026
One-click install
npx skills add https://github.com/doolin/dave-skills --skill cicd-golden-pipeline
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cicd-golden-pipeline
Source: https://github.com/doolin/dave-skills/tree/main/skills/cicd-golden-pipeline
Command: npx skills add https://github.com/doolin/dave-skills --skill cicd-golden-pipeline

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automates a compliant CI/CD pipeline for GitHub Actions orchestrating federated checks.

Core Features & Use Cases

  • Reusable workflow_call that enforces SSDF-aligned checks, SBOM generation, OSCAL artifact generation, evidence verification, and per-repo deploy/attest steps.
  • Centralized, policy-driven pipeline design that can be copied into multiple repos to ensure consistent security and provenance across pushes and PRs.
  • Machine-readable evidence and OSCAL outputs to support modern risk management and compliance reviews.

Quick Start

Copy the cicd-golden-pipeline skill into your repo and reference the reusable workflow in your GitHub Actions configuration to start enforcing a compliant pipeline.

Frequently Asked Questions about cicd-golden-pipeline

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate OSCAL artifacts and SBOMs in a GitHub Actions CI/CD pipeline?

To generate OSCAL artifacts and SBOMs in a GitHub Actions CI/CD pipeline, use a reusable workflow_call that enforces SSDF-aligned checks and orchestrates federated evidence verification across pushes and PRs, producing machine-readable outputs.

What is the best way to align GitHub Actions workflows with SSDF and EO 14028 compliance requirements?

Aligning GitHub Actions workflows with SSDF and EO 14028 compliance requirements involves implementing a centralized, policy-driven pipeline design that enforces structured audit events and reproducible evidence bundles for modern risk management.

Can I enforce per-repo IAM roles and evidence verification across multiple GitHub Actions repositories?

Yes, you can enforce per-repo IAM roles and evidence verification across multiple GitHub Actions repositories by copying a centralized, policy-driven pipeline into each repo to ensure consistent security and provenance.

Does this compliant pipeline approach support machine-readable outputs for risk management reviews?

Yes, this compliant pipeline approach supports risk management reviews by generating machine-readable evidence and OSCAL outputs that satisfy structured audit event requirements and functional compliance checks.

How do I set up a reusable GitHub Actions workflow for federated compliance checks?

To set up a reusable GitHub Actions workflow for federated compliance checks, copy the skill into your repository and reference the reusable workflow in your GitHub Actions configuration to start enforcing a compliant pipeline.

Why do I need reproducible evidence bundles and structured audit events in CI/CD?

Reproducible evidence bundles and structured audit events in CI/CD are needed to satisfy functional compliance requirements, supporting modern risk management reviews with machine-readable OSCAL outputs and provenance verification.