action-remediate

tarafından bitwarden

Devam etmeden önce, kullanıcının üzerinde işlem yapabileceği denetim bulgularına sahip olduğunu doğrulayın. Bunlar, action-audit becerisinin önceki bir çalıştırmasından gelmelidir. Onaylayın:

npx skills add https://github.com/bitwarden/ai-plugins --skill action-remediate

Rules

  • No mutating API calls without confirmation. gh api GET requests are allowed freely. Any call using -X POST, -X PUT, -X PATCH, or -X DELETE must be shown to the user and approved before execution.
  • Never force-push, delete branches, or delete repositories.
  • Only modify files under .github/. Do not touch application code, scripts, or configuration outside of workflow files.
  • Show a diff and get confirmation before handing off for commit.
  • All PRs must be created as drafts.
  • Flag uncertainty. If a finding is ambiguous or a fix could break a workflow, stop and ask rather than guessing.

Step 1: Confirm Audit Findings

Before proceeding, verify that the user has audit findings to act on. These should come from a prior run of the action-audit skill. Confirm:

  • Which repos to remediate (all, a subset, or specific ones)
  • The remediation approach:
    • pin to main — for internal bitwarden/ actions: change the ref to @main
    • pin update — for external actions: update to a verified 40-character SHA with an inline version comment
    • replace — swap to a different action entirely
  • The target SHA, replacement action, or confirmation that @main is the fix

If any of this is unclear, ask the user before continuing.

Step 2: Apply Fixes Per Repo

For each selected repo:

  1. Ask the user for the base directory where their repos are cloned (if not already known). Check if a local clone exists at <base-dir>/<repo>. If not, inform the user and skip that repo.

  2. Create a fix branch:

    git checkout -b fix/action-remediation-<action-name-slug>
    
  3. Apply the fix to each affected file based on the remediation approach:

    • Pin to main (internal bitwarden/ actions): Replace the ref with @main — e.g., uses: bitwarden/gh-actions/action@v1 → uses: bitwarden/gh-actions/action@main. No SHA resolution needed.
    • Pin update (external actions): Replace the uses: line with uses: <action>@<sha> # <original-ref>
    • Replace: Before applying, verify the replacement action is on Bitwarden's approved actions list in bitwarden/workflow-linter. Then swap uses: <old-action>@<ref> with uses: <new-action>@<sha> # <tag>
  4. Show a git diff of changes in this repo and get confirmation before proceeding.

Step 3: Commit, Push, and Create PRs

Do not run the staging, commit, or push commands yourself. For each repo, present the block below for the user to run manually as a suggestion:

git add .github/
git commit -m "Remediate <action-name> action usage"
git push -u origin fix/action-remediation-<action-name-slug>

Once the user confirms the push, create the draft PR:

gh pr create \
  --title "Remediate <action-name> action usage" \
  --body "$(cat <<'EOF'
## Summary

Remediates usage of `<action-name>` across this repository.

**Action taken:** <pin updated to `<sha>` / replaced with `<new-action>`>

**Reason:** <compromised action / deprecated action / unpinned reference>
EOF
)" \
  --draft

Step 4: Final Summary

Output a summary of all actions taken:

RepoFiles ChangedPR CreatedNotes
............

Remind the user that code search results may have a lag and to verify no repos were missed by checking manually if this is a security incident.

bitwarden tarafından daha fazla skill

figma-to-angular
bitwarden
Bu beceri, bir Figma tasarım spesifikasyonunu, Bitwarden Clients monorepo'sunda Storybook hikayeleriyle birlikte tamamen uygulanmış bir Angular bileşenine dönüştürür. Çıktı, tüm kod tabanı kurallarına uyarken görsel olarak tasarımla eşleşmelidir.
force-multiplier
bitwarden
Tek bir niyeti aynı anda birçok hedefe uygulayın — Bitwarden ekosistemindeki bir depo filosuna veya bir monorepo içindeki birçok projeye — N tutarlı,…
analyzing-git-sessions
bitwarden
Git commit'lerini ve belirli bir zaman aralığı veya commit aralığındaki değişiklikleri analiz eder; kod incelemesi, retrospektifler, iş günlükleri veya oturumlar için yapılandırılmış özetler sunar.
coordinating-cross-team-breakdown
bitwarden
Bitwarden Teknik Dökümü için ekipler arası inceleme ve onayı koordine edin. Etkilenen ekipleri belirlerken, Bölüm 3 onay tablosunu oluştururken, takip ederken… kullanın.
assessing-jira-issue-relevance
bitwarden
Kullanıcı tek bir Jira sorun anahtarı sağladığında ve bunun hâlâ geçerli olup olmadığını, hâlâ uygulanabilir olup olmadığını, hâlâ beklemede olup olmadığını, hâlâ bir hata olup olmadığını, düzeltilip düzeltilmediğini veya…
assessing-test-coverage
bitwarden
Belirli bir değişiklik için (bir PR, Jira anahtarı, Tech Breakdown dokümanı, Testmo CSV'si, değiştirilen yollar veya adlandırılmış…) hangi test kapsamının ZATEN mevcut olduğunu belirlerken kullanın.
retrospecting
bitwarden
Claude Code oturumlarının kapsamlı analizini gerçekleştirir, git geçmişini, konuşma günlüklerini, kod değişikliklerini inceler ve kullanıcı geri bildirimlerini toplayarak…
reviewing-incremental-changes
bitwarden
Bu beceriyi, halihazırda yorumlar bulunan bir PR'ı yeniden incelerken veya ilk inceleme sonrası geliştirici değişikliklerine yanıt verirken kullanın. PR iş parçacıkları mevcut olduğunda veya…