action-remediate

โดย bitwarden

ก่อนดำเนินการ ให้ตรวจสอบว่าผู้ใช้มีผลการตรวจสอบที่ต้องดำเนินการ ซึ่งควรมาจากการทำงานก่อนหน้าของสกิล action-audit ยืนยัน:

npx skills add https://github.com/bitwarden/ai-plugins --skill action-remediate

Rules

  • No mutating API calls without confirmation. gh api GET requests are allowed freely. Any call using -X POST, -X PUT, -X PATCH, or -X DELETE must be shown to the user and approved before execution.
  • Never force-push, delete branches, or delete repositories.
  • Only modify files under .github/. Do not touch application code, scripts, or configuration outside of workflow files.
  • Show a diff and get confirmation before handing off for commit.
  • All PRs must be created as drafts.
  • Flag uncertainty. If a finding is ambiguous or a fix could break a workflow, stop and ask rather than guessing.

Step 1: Confirm Audit Findings

Before proceeding, verify that the user has audit findings to act on. These should come from a prior run of the action-audit skill. Confirm:

  • Which repos to remediate (all, a subset, or specific ones)
  • The remediation approach:
    • pin to main — for internal bitwarden/ actions: change the ref to @main
    • pin update — for external actions: update to a verified 40-character SHA with an inline version comment
    • replace — swap to a different action entirely
  • The target SHA, replacement action, or confirmation that @main is the fix

If any of this is unclear, ask the user before continuing.

Step 2: Apply Fixes Per Repo

For each selected repo:

  1. Ask the user for the base directory where their repos are cloned (if not already known). Check if a local clone exists at <base-dir>/<repo>. If not, inform the user and skip that repo.

  2. Create a fix branch:

    git checkout -b fix/action-remediation-<action-name-slug>
    
  3. Apply the fix to each affected file based on the remediation approach:

    • Pin to main (internal bitwarden/ actions): Replace the ref with @main — e.g., uses: bitwarden/gh-actions/action@v1 → uses: bitwarden/gh-actions/action@main. No SHA resolution needed.
    • Pin update (external actions): Replace the uses: line with uses: <action>@<sha> # <original-ref>
    • Replace: Before applying, verify the replacement action is on Bitwarden's approved actions list in bitwarden/workflow-linter. Then swap uses: <old-action>@<ref> with uses: <new-action>@<sha> # <tag>
  4. Show a git diff of changes in this repo and get confirmation before proceeding.

Step 3: Commit, Push, and Create PRs

Do not run the staging, commit, or push commands yourself. For each repo, present the block below for the user to run manually as a suggestion:

git add .github/
git commit -m "Remediate <action-name> action usage"
git push -u origin fix/action-remediation-<action-name-slug>

Once the user confirms the push, create the draft PR:

gh pr create \
  --title "Remediate <action-name> action usage" \
  --body "$(cat <<'EOF'
## Summary

Remediates usage of `<action-name>` across this repository.

**Action taken:** <pin updated to `<sha>` / replaced with `<new-action>`>

**Reason:** <compromised action / deprecated action / unpinned reference>
EOF
)" \
  --draft

Step 4: Final Summary

Output a summary of all actions taken:

RepoFiles ChangedPR CreatedNotes
............

Remind the user that code search results may have a lag and to verify no repos were missed by checking manually if this is a security incident.

Skills เพิ่มเติมจาก bitwarden

figma-to-angular
bitwarden
ทักษะนี้จะเปลี่ยนสเปกการออกแบบจาก Figma ให้เป็นคอมโพเนนต์ Angular ที่สมบูรณ์พร้อมกับสตอรีบุ๊กสตอรีใน Bitwarden Clients monorepo ผลลัพธ์ควรตรงกับการออกแบบทางสายตาในขณะที่ปฏิบัติตามข้อกำหนดของโค้ดเบสทั้งหมด
force-multiplier
bitwarden
ใช้เจตนาหนึ่งกับหลายเป้าหมายพร้อมกัน — กลุ่ม repositories ในระบบนิเวศ Bitwarden หรือหลาย projects ภายใน monorepo — เป็น N ที่สอดคล้องกัน,…
analyzing-git-sessions
bitwarden
วิเคราะห์ git commits และการเปลี่ยนแปลงภายในกรอบเวลาหรือช่วงของ commits โดยให้สรุปที่มีโครงสร้างสำหรับการตรวจสอบโค้ด การย้อนหลัง บันทึกการทำงาน หรือเซสชัน…
coordinating-cross-team-breakdown
bitwarden
ประสานงานการตรวจสอบและอนุมัติข้ามทีมสำหรับ Bitwarden Tech Breakdown ใช้เมื่อระบุทีมที่ได้รับผลกระทบ สร้างตารางอนุมัติส่วนที่ 3 และติดตามผล...
assessing-jira-issue-relevance
bitwarden
ใช้เมื่อผู้ใช้ระบุคีย์ Jira issue เพียงหนึ่งรายการและถามว่ายังเกี่ยวข้องอยู่หรือไม่ ยังใช้งานได้หรือไม่ ยังรอดำเนินการอยู่หรือไม่ ยังเป็นบั๊กอยู่หรือไม่ ได้รับการแก้ไขแล้วหรือไม่ หรือสามารถ...
assessing-test-coverage
bitwarden
ใช้เมื่อต้องการตรวจสอบว่ามีการครอบคลุมการทดสอบใดอยู่แล้วสำหรับการเปลี่ยนแปลงเฉพาะ (PR, คีย์ Jira, เอกสาร Tech Breakdown, CSV ของ Testmo, พาธที่เปลี่ยนแปลง หรือชื่อที่ระบุ…
retrospecting
bitwarden
ดำเนินการวิเคราะห์เซสชัน Claude Code อย่างครอบคลุม โดยตรวจสอบประวัติ git, บันทึกการสนทนา, การเปลี่ยนแปลงโค้ด และรวบรวมความคิดเห็นจากผู้ใช้เพื่อสร้าง…
reviewing-incremental-changes
bitwarden
ใช้ทักษะนี้เมื่อตรวจสอบ PR ซ้ำที่มีความคิดเห็นอยู่แล้ว หรือเมื่อตอบกลับการเปลี่ยนแปลงของนักพัฒนาหลังจากการตรวจสอบครั้งแรก ใช้เมื่อมีเธรด PR อยู่หรือ…