action-remediate

작성자: bitwarden

Remediate GitHub Actions action findings identified by the action-audit skill. Applies the appropriate fix per action type — `@main` ref for internal…

npx skills add https://github.com/bitwarden/ai-plugins --skill action-remediate

Rules

  • No mutating API calls without confirmation. gh api GET requests are allowed freely. Any call using -X POST, -X PUT, -X PATCH, or -X DELETE must be shown to the user and approved before execution.
  • Never force-push, delete branches, or delete repositories.
  • Only modify files under .github/. Do not touch application code, scripts, or configuration outside of workflow files.
  • Show a diff and get confirmation before handing off for commit.
  • All PRs must be created as drafts.
  • Flag uncertainty. If a finding is ambiguous or a fix could break a workflow, stop and ask rather than guessing.

Step 1: Confirm Audit Findings

Before proceeding, verify that the user has audit findings to act on. These should come from a prior run of the action-audit skill. Confirm:

  • Which repos to remediate (all, a subset, or specific ones)
  • The remediation approach:
    • pin to main — for internal bitwarden/ actions: change the ref to @main
    • pin update — for external actions: update to a verified 40-character SHA with an inline version comment
    • replace — swap to a different action entirely
  • The target SHA, replacement action, or confirmation that @main is the fix

If any of this is unclear, ask the user before continuing.

Step 2: Apply Fixes Per Repo

For each selected repo:

  1. Ask the user for the base directory where their repos are cloned (if not already known). Check if a local clone exists at <base-dir>/<repo>. If not, inform the user and skip that repo.

  2. Create a fix branch:

    git checkout -b fix/action-remediation-<action-name-slug>
    
  3. Apply the fix to each affected file based on the remediation approach:

    • Pin to main (internal bitwarden/ actions): Replace the ref with @main — e.g., uses: bitwarden/gh-actions/action@v1uses: bitwarden/gh-actions/action@main. No SHA resolution needed.
    • Pin update (external actions): Replace the uses: line with uses: <action>@<sha> # <original-ref>
    • Replace: Before applying, verify the replacement action is on Bitwarden's approved actions list in bitwarden/workflow-linter. Then swap uses: <old-action>@<ref> with uses: <new-action>@<sha> # <tag>
  4. Show a git diff of changes in this repo and get confirmation before proceeding.

Step 3: Commit, Push, and Create PRs

Do not run the staging, commit, or push commands yourself. For each repo, present the block below for the user to run manually as a suggestion:

git add .github/
git commit -m "Remediate <action-name> action usage"
git push -u origin fix/action-remediation-<action-name-slug>

Once the user confirms the push, create the draft PR:

gh pr create \
  --title "Remediate <action-name> action usage" \
  --body "$(cat <<'EOF'
## Summary

Remediates usage of `<action-name>` across this repository.

**Action taken:** <pin updated to `<sha>` / replaced with `<new-action>`>

**Reason:** <compromised action / deprecated action / unpinned reference>
EOF
)" \
  --draft

Step 4: Final Summary

Output a summary of all actions taken:

RepoFiles ChangedPR CreatedNotes
............

Remind the user that code search results may have a lag and to verify no repos were missed by checking manually if this is a security incident.

bitwarden의 다른 스킬

analyzing-git-sessions
bitwarden
특정 기간이나 커밋 범위 내의 Git 커밋과 변경 사항을 분석하여 코드 리뷰, 회고, 작업 로그 또는 세션을 위한 구조화된 요약을 제공합니다.
official
figma-to-angular
bitwarden
이 스킬은 Figma 디자인 스펙을 Bitwarden Clients 모노레포 내에서 Storybook 스토리와 함께 완전히 구현된 Angular 컴포넌트로 변환합니다. 출력물은 모든 코드베이스 규칙을 따르면서 시각적으로 디자인과 일치해야 합니다.
official
agent-access
bitwarden
Retrieve login credentials, API keys, and secrets (username, password, TOTP) from the user's Bitwarden vault via aac. Use when you need credentials to sign…
official
action-audit
bitwarden
Audit GitHub Actions action usage across an org. Searches for a specific action (incident mode) or sweeps all workflow files for non-compliant action…
official
analyzing-code-security
bitwarden
이 스킬은 사용자가 "코드의 보안 문제를 분석"하거나, "OWASP 취약점을 확인"하거나, "CWE Top 25에 대해 코드를 검토"하도록 요청할 때 사용해야 합니다. "찾…
official
applying-bitwarden-branding
bitwarden
Apply Bitwarden brand standards — logo usage, color palette, typography, iconography, and capitalization rules — grounded in bitwarden.com/brand and the…
official
architecting-solutions
bitwarden
Architecting solutions at the team level while staying coherent with Bitwarden's holistic architecture. Covers security mindset, architectural judgment,…
official
assessing-jira-issue-relevance
bitwarden
Use when the user provides a single Jira issue key and asks whether it is still relevant, still applicable, still pending, still a bug, has been fixed, or can…
official