action-remediate

bởi bitwarden

Trước khi tiếp tục, hãy xác minh rằng người dùng có các phát hiện kiểm toán để thực hiện. Các phát hiện này phải đến từ lần chạy trước đó của kỹ năng action-audit. Xác nhận:

npx skills add https://github.com/bitwarden/ai-plugins --skill action-remediate

Rules

  • No mutating API calls without confirmation. gh api GET requests are allowed freely. Any call using -X POST, -X PUT, -X PATCH, or -X DELETE must be shown to the user and approved before execution.
  • Never force-push, delete branches, or delete repositories.
  • Only modify files under .github/. Do not touch application code, scripts, or configuration outside of workflow files.
  • Show a diff and get confirmation before handing off for commit.
  • All PRs must be created as drafts.
  • Flag uncertainty. If a finding is ambiguous or a fix could break a workflow, stop and ask rather than guessing.

Step 1: Confirm Audit Findings

Before proceeding, verify that the user has audit findings to act on. These should come from a prior run of the action-audit skill. Confirm:

  • Which repos to remediate (all, a subset, or specific ones)
  • The remediation approach:
    • pin to main — for internal bitwarden/ actions: change the ref to @main
    • pin update — for external actions: update to a verified 40-character SHA with an inline version comment
    • replace — swap to a different action entirely
  • The target SHA, replacement action, or confirmation that @main is the fix

If any of this is unclear, ask the user before continuing.

Step 2: Apply Fixes Per Repo

For each selected repo:

  1. Ask the user for the base directory where their repos are cloned (if not already known). Check if a local clone exists at <base-dir>/<repo>. If not, inform the user and skip that repo.

  2. Create a fix branch:

    git checkout -b fix/action-remediation-<action-name-slug>
    
  3. Apply the fix to each affected file based on the remediation approach:

    • Pin to main (internal bitwarden/ actions): Replace the ref with @main — e.g., uses: bitwarden/gh-actions/action@v1 → uses: bitwarden/gh-actions/action@main. No SHA resolution needed.
    • Pin update (external actions): Replace the uses: line with uses: <action>@<sha> # <original-ref>
    • Replace: Before applying, verify the replacement action is on Bitwarden's approved actions list in bitwarden/workflow-linter. Then swap uses: <old-action>@<ref> with uses: <new-action>@<sha> # <tag>
  4. Show a git diff of changes in this repo and get confirmation before proceeding.

Step 3: Commit, Push, and Create PRs

Do not run the staging, commit, or push commands yourself. For each repo, present the block below for the user to run manually as a suggestion:

git add .github/
git commit -m "Remediate <action-name> action usage"
git push -u origin fix/action-remediation-<action-name-slug>

Once the user confirms the push, create the draft PR:

gh pr create \
  --title "Remediate <action-name> action usage" \
  --body "$(cat <<'EOF'
## Summary

Remediates usage of `<action-name>` across this repository.

**Action taken:** <pin updated to `<sha>` / replaced with `<new-action>`>

**Reason:** <compromised action / deprecated action / unpinned reference>
EOF
)" \
  --draft

Step 4: Final Summary

Output a summary of all actions taken:

RepoFiles ChangedPR CreatedNotes
............

Remind the user that code search results may have a lag and to verify no repos were missed by checking manually if this is a security incident.

Thêm skills từ bitwarden

figma-to-angular
bitwarden
Kỹ năng này chuyển đổi bản thiết kế Figma thành một component Angular được triển khai đầy đủ với các story Storybook trong monorepo Bitwarden Clients. Đầu ra phải khớp với thiết kế về mặt hình ảnh đồng thời tuân thủ tất cả các quy ước codebase.
force-multiplier
bitwarden
Áp dụng một ý định trên nhiều mục tiêu cùng lúc — một loạt kho lưu trữ trong hệ sinh thái Bitwarden, hoặc nhiều dự án trong một monorepo — như N nhất quán,…
analyzing-git-sessions
bitwarden
Phân tích các commit git và thay đổi trong một khung thời gian hoặc phạm vi commit, cung cấp các bản tóm tắt có cấu trúc cho việc xem xét mã, hồi tưởng, nhật ký công việc hoặc phiên làm việc…
coordinating-cross-team-breakdown
bitwarden
Phối hợp đánh giá và phê duyệt giữa các nhóm cho một Bản Phân Tích Kỹ Thuật Bitwarden. Sử dụng khi xác định các nhóm bị ảnh hưởng, xây dựng bảng phê duyệt Phần 3, theo dõi…
assessing-jira-issue-relevance
bitwarden
Sử dụng khi người dùng cung cấp một mã số vấn đề Jira duy nhất và hỏi liệu vấn đề đó có còn liên quan, còn áp dụng, còn đang chờ xử lý, còn là lỗi, đã được sửa, hay có thể…
assessing-test-coverage
bitwarden
Sử dụng khi xác định mức độ bao phủ kiểm thử ĐÃ tồn tại cho một thay đổi cụ thể (một PR, khóa Jira, tài liệu Tech Breakdown, CSV Testmo, các đường dẫn đã thay đổi, hoặc các mục được đặt tên…
retrospecting
bitwarden
Thực hiện phân tích toàn diện các phiên Claude Code, xem xét lịch sử git, nhật ký hội thoại, thay đổi mã nguồn và thu thập phản hồi từ người dùng để tạo ra…
reviewing-incremental-changes
bitwarden
Sử dụng kỹ năng này khi xem lại một PR đã có bình luận hoặc khi phản hồi các thay đổi của nhà phát triển sau lần xem xét ban đầu. Áp dụng khi có các luồng thảo luận trong PR hoặc…