GitHub Actions, Renovate, the two-branch release model, signing, and promotion.

Apache-2.0Auto-check passedDevOps & Cloud

Install CI

skills CLI
$ npx skills add projectbluefin/finpilot --skill ci -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install projectbluefin/finpilot ci --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/projectbluefin/finpilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ci .claude/skills/ci && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ci
GitHub stars
126
Token cost
~1.5k tokens
SKILL.md length
808 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

GitHub Actions, Renovate, the two-branch release model, signing, and promotion.

  • Works in 4 steps: Open a pull request against main. → Wait for validate and the image build. → Merge. main publishes :stable-testing. → …
  • Changing workflows
  • SKILL.md covers Workflows, The release model, Signing and Renovate, plus 1 more section
  • Calls just, gh and git; needs RENOVATE_TOKEN

What it does

CI is an agent skill from projectbluefin/finpilot. GitHub Actions, Renovate, the two-branch release model, signing, and promotion. Use when changing workflows, dependency policy, or releasing.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions. The repository describes itself as: Build your own custom Bluefin. The licence is Apache-2.0.

When your agent uses it

  • Changing workflows
  • Dependency policy

Example prompts

  • “/ci”

Requirements

  • Docker
  • A credential in RENOVATE_TOKEN

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Open a pull request against main.
  2. Wait for validate and the image build.
  3. Merge. main publishes :stable-testing.
  4. Review and merge the promotion PR to publish :stable.

What it can do on your machine

Read from SKILL.md and the folder at commit 8e0eb5d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • just
    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • RENOVATE_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

CI loads about 1.5k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 808 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from projectbluefin/finpilot at commit 8e0eb5d, republished under its Apache-2.0 licence (© projectbluefin). 808 words, ~1,493 tokens.

Download SKILL.mdSave it as .claude/skills/ci/SKILL.md (or your agent's skills folder).
name
ci
description
GitHub Actions, Renovate, the two-branch release model, signing, and promotion. Use when changing workflows, dependency policy, or releasing.

CI

Workflows

WorkflowTriggerDoes
build-image.ymlpush to main or stable, dispatchBuilds, signs, and pushes the image.
execute-release.ymlpush to stablePromotes the candidate digest. Does not rebuild.
promote-main-to-stable.ymldaily schedule, dispatchOpens the squash promotion PR and runs the release gate on it.
sync-stable-to-main.ymlpush to stableMerges stable hotfixes back into main.
pr-validation.ymlpull requestThe validate check: shellcheck and hadolint.
validate-brewfiles.ymlpull requestBrewfiles, without evaluating them.
validate-flatpaks.ymlpull requestFlatpak preinstall files against Flathub.
validate-justfiles.ymlpull requestjust check.
validate-renovate.ymlpull requestRenovate config.
unit-tests.ymlpush, pull requestThe bats suite.
renovate.ymlschedule, config changeRuns Renovate.
clean.ymlscheduleDeletes images older than 90 days.

Most are thin callers of reusable workflows in projectbluefin/actions.

The release model

main publishes :stable-testing. stable never rebuilds: promotion is a squash PR from main to stable, and execute-release.yml copies the digest :testing resolves to. The README owns the release table and the promotion gate's current limits.

The factory reusable puts its release gate and its auto-merge enrollment behind one input, enqueue_promotion. A personal repository cannot enroll — there is no merge queue, and gh pr merge --auto refuses without a merge method — so enrollment is off, and promote-main-to-stable.yml runs the gate itself in its own gate job to keep the pre-merge check. That gate resolves :testing when it runs, so it attests the current candidate. The binding comes from execute-release.yml passing source_branch: main, which makes the reusable refuse to promote at all once main has moved past the promotion commit; a manual dispatch is exempt, because that path is deliberate recovery.

The same reusable builds the squash branch, and it stages deletions with git diff --diff-filter=D. Git reports a moved file as a rename, so a path main moved survives on its old path and the branch's tree stops matching main's — the state the guard above refuses, but only after the PR is merged. repair-promotion-branch in promote-main-to-stable.yml rebuilds the branch from main's tree when it has drifted, and the validate check fails a promotion PR whose tree does not match main. The sweep belongs to projectbluefin/actions; the one-line fix there is --no-renames.

Signing

Keyless OIDC via Cosign. There are no keys to generate or store; the workflow needs id-token: write and packages: write. Unsigned images fail the promotion gate. The README has the command to verify an image.

The promotion gate is the only enforcement point. Nothing checks the signature on an installed system, so 00-image-info.sh writes an unverified update transport (ostree-unverified-image:docker://…) and the README says so. ostree-image-signed: would send the client to /etc/containers/policy.json, which Common supplies with no scope for this namespace — it would verify against the "" catch-all, insecureAcceptAnything, and report success having checked nothing. Adding a scope does not rescue it while signing stays keyless: containers/image matches a Fulcio certificate on subjectEmail alone (mandatory, exact, with a standing FIXME for URI SANs in signature/fulcio_cert.go), and a GitHub Actions certificate names its workflow in a URI SAN with no email to match. Device-side verification is a key-based signing change first, a policy change second. tests/contract/image-signing_test.bats fails if either side moves alone.

The identity regexp the release workflows pass to the reusables is scoped with github.repository, not github.repository_owner. Matching the owner and then any repository accepts a signature minted by any repository in the org, and github.repository keeps the scope correct in a fork without hardcoding it.

Show full SKILL.md (251 more words)Show less

Renovate

Self-hosted through projectbluefin/actions, running every six hours. It pins GitHub Actions to SHAs and updates image digests. The policy lives in .github/renovate.json: updates below a major automerge once checks pass; majors wait for a pull request — except quay.io/fedora-ostree-desktops/*, where cross-major bumps do not open a PR at all (the rule is enabled: false). A Fedora major rebase for that namespace is a deliberate manual step: bump the tag in Containerfile by hand when the next major is released and validated.

Renovate needs the RENOVATE_TOKEN secret and auto-merge enabled. Both are onboarding steps. The secret is optional: with it unset the workflow logs a skip and the run stays green, which is how upstream runs, where an org-wide app does the work instead. The check sits in its own token job because a job that calls a reusable workflow cannot hold steps, and jobs.<job_id>.if cannot read the secrets context — secrets in a job-level if is a parse error, not a skip.

Automerge deliberately covers GitHub Actions SHA bumps, which reverses a guard upstream kept. Those SHAs run in jobs holding packages: write, id-token: write, and secrets: inherit, and PR builds are disabled, so a bump merges with only shellcheck, hadolint, and the test suite having run. Putting the guard back is one rule — matchManagers: ["github-actions"] with automerge: false.

Making a change

  1. Open a pull request against main.
  2. Wait for validate and the image build.
  3. Merge. main publishes :stable-testing.
  4. Review and merge the promotion PR to publish :stable.

© projectbluefin, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/ci of projectbluefin/finpilot.

Open the folder on GitHubat commit 8e0eb5d

Compare with similar skills

CI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CI this skillprojectbluefin/finpilot126—~1.5kAutomated safety check: PassApache-2.0
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
GitHub Actions Templatesbartstc/vite-ts-react-template12214 repos~1.9kAutomated safety check: PassMIT
Nushellccusage/ccusage19k—~938Automated safety check: PassCustom licence
Repo Hygiene Scan and FixQwenLM/qwen-code28k—~1.7kAutomated safety check: PassApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence

Similar skills

  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • GitHub Actions Templates

    bartstc/vite-ts-react-template

    Create production-ready GitHub Actions workflows for automated testing, building, and deploying applications.

    122 GitHub starsUsed in 14 repos~1.9k tokens
    DevOps & CloudAuto-check passed
  • Nushell

    ccusage/ccusage

    Guides ccusage Nushell scripts. An agent skill from ccusage/ccusage.

    19k GitHub stars~938 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.

    28k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • CI Failure Triage and Repair

    Chachamaru127/claude-code-harness

    Diagnoses failing CI pipelines and tests, deciding first whether the test or the implementation is at fault, and hands hard cases to a dedicated fixer subagent.

    3.2k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check: notes

More from projectbluefin/finpilot

  • Customize

    projectbluefin/finpilot

    Decide where a package, app, or command belongs — dnf5 at build time, Homebrew, Flatpak, or ujust — and how each is validated.

    126 GitHub stars~625 tokensUpdated today
    Auto-check passed
  • Onboarding

    projectbluefin/finpilot

    Bootstrap a new image from this template: rename the project, enable Actions and Renovate, protect the branch, and reach a first green build.

    126 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Overview

    projectbluefin/finpilot

    Architecture, repository layout, and file map for this template.

    126 GitHub stars~740 tokensUpdated today
    Auto-check passed
  • Troubleshooting

    projectbluefin/finpilot

    Symptom to cause to fix for build, CI, and runtime failures, plus the pre-commit checklist.

    126 GitHub stars~605 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about CI

What does CI do?

GitHub Actions, Renovate, the two-branch release model, signing, and promotion. CI is an agent skill from projectbluefin/finpilot. GitHub Actions, Renovate, the two-branch release model, signing, and promotion.

When should I use CI?

CI fits situations like: changing workflows; dependency policy.

How do I install CI in Claude Code?

Run `npx skills add projectbluefin/finpilot --skill ci -a claude-code`. Or copy the skill folder (.agents/skills/ci in projectbluefin/finpilot) into .claude/skills/ci in your project. Claude Code loads it when a task matches its description.

How do I install CI in Codex?

Run `npx skills add projectbluefin/finpilot --skill ci -a codex`. Or copy the skill folder (.agents/skills/ci in projectbluefin/finpilot) into .agents/skills/ci in your project. Codex loads it when a task matches its description.

Can I use CI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add projectbluefin/finpilot --skill ci -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ci, .gemini/skills/ci, .github/skills/ci and .opencode/skills/ci in your project.

What does CI need to run?

Going by SKILL.md and its folder, CI needs the command-line tools its instructions call (just, gh and git) and credentials named RENOVATE_TOKEN. Our summary lists: Docker; A credential in RENOVATE_TOKEN.

Does CI access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is CI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does CI use?

CI is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does CI use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to CI?

Skills that share tags, products or a category with CI: Analyze GitHub Action Logs (withastro/astro, 63k stars), GitHub Actions Templates (bartstc/vite-ts-react-template, 122 stars), Nushell (ccusage/ccusage, 19k stars) and Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CI?

projectbluefin (a GitHub organization) maintains it in projectbluefin/finpilot, which has 126 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 8, 2026.

Source: projectbluefin/finpilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.