Github Ops

作者 affaan-mef648e01899b無授權條款275K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫3 天前更新

GitHub操作、自動化、APIインテグレーション、およびCI/CDワークフロー。

僅含說明DevOps & Cloud
AI 產生的概覽

透過 gh CLI 指導 GitHub 儲存庫操作:議題分流、PR 管理、CI/CD 除錯、發佈與安全監控。

功能
此技能提供透過 gh CLI 管理 GitHub 儲存庫的說明,涵蓋議題分流(加上標籤、找出重複)、拉取請求審查與過期政策、CI/CD 失敗排查、發佈與變更日誌準備,以及 Dependabot 與密鑰掃描警示的檢查。它提供具體的 gh 指令,用來列出、加標籤、留言、檢視日誌與建立發佈,並附上品質閘門清單。其產出是分流決策、審查狀態評估、變更日誌與發佈指令,而非檔案。
適用情境
適用於對 GitHub 儲存庫的議題進行分流、審查或合併拉取請求、排查失敗的 CI 工作流程、準備發佈與變更日誌,或監控 Dependabot 與安全警示。也適合開源維護者處理貢獻者體驗與過期議題等工作。
執行需求
需要 gh CLI,並透過 gh auth login 設定已驗證的 GitHub 存取權限,同時需要連線至 GitHub API 的網路。此技能不附帶指令碼,僅為說明文件。

GitHub Operations

Manage GitHub repositories with a focus on community health, CI reliability, and contributor experience.

When to Activate

  • Triaging issues (classifying, labeling, responding, deduplicating)
  • Managing PRs (review status, CI checks, stale PRs, merge readiness)
  • Debugging CI/CD failures
  • Preparing releases and changelogs
  • Monitoring Dependabot and security alerts
  • Managing contributor experience on open-source projects
  • User says "check GitHub", "triage issues", "review PRs", "merge", "release", "CI is broken"

Tool Requirements

  • gh CLI for all GitHub API operations
  • Repository access configured via gh auth login

Issue Triage

Classify each issue by type and priority:

Types: bug, feature-request, question, documentation, enhancement, duplicate, invalid, good-first-issue

Priority: critical (breaking/security), high (significant impact), medium (nice to have), low (cosmetic)

Triage Workflow

  1. Read the issue title, body, and comments
  2. Check if it duplicates an existing issue (search by keywords)
  3. Apply appropriate labels via gh issue edit --add-label
  4. For questions: draft and post a helpful response
  5. For bugs needing more info: ask for reproduction steps
  6. For good first issues: add good-first-issue label
  7. For duplicates: comment with link to original, add duplicate label
bash
# Search for potential duplicatesgh issue list --search "keyword" --state all --limit 20
# Add labelsgh issue edit <number> --add-label "bug,high-priority"
# Comment on issuegh issue comment <number> --body "Thanks for reporting. Could you share reproduction steps?"

PR Management

Review Checklist

  1. Check CI status: gh pr checks <number>
  2. Check if mergeable: gh pr view <number> --json mergeable
  3. Check age and last activity
  4. Flag PRs >5 days with no review
  5. For community PRs: ensure they have tests and follow conventions

Stale Policy

  • Issues with no activity in 14+ days: add stale label, comment asking for update
  • PRs with no activity in 7+ days: comment asking if still active
  • Auto-close stale issues after 30 days with no response (add closed-stale label)
bash
# Find stale issues (no activity in 14+ days)gh issue list --label "stale" --state open
# Find PRs with no recent activitygh pr list --json number,title,updatedAt --jq '.[] | select(.updatedAt < "2026-03-01")'

CI/CD Operations

When CI fails:

  1. Check the workflow run: gh run view <run-id> --log-failed
  2. Identify the failing step
  3. Check if it is a flaky test vs real failure
  4. For real failures: identify the root cause and suggest a fix
  5. For flaky tests: note the pattern for future investigation
bash
# List recent failed runsgh run list --status failure --limit 10
# View failed run logsgh run view <run-id> --log-failed
# Re-run a failed workflowgh run rerun <run-id> --failed

Release Management

When preparing a release:

  1. Check all CI is green on main
  2. Review unreleased changes: gh pr list --state merged --base main
  3. Generate changelog from PR titles
  4. Create release: gh release create
bash
# List merged PRs since last releasegh pr list --state merged --base main --search "merged:>2026-03-01"
# Create a releasegh release create v1.2.0 --title "v1.2.0" --generate-notes
# Create a pre-releasegh release create v1.3.0-rc1 --prerelease --title "v1.3.0 Release Candidate 1"

Security Monitoring

bash
# Check Dependabot alertsgh api repos/{owner}/{repo}/dependabot/alerts --jq '.[].security_advisory.summary'
# Check secret scanning alertsgh api repos/{owner}/{repo}/secret-scanning/alerts --jq '.[].state'
# Review dependency bumps — merging is a user-authorized action (propose, never auto-merge)gh pr list --label "dependencies" --json number,title
  • Review safe dependency bumps and propose merges for user approval — never auto-merge
  • Flag any critical/high severity alerts immediately
  • Check for new Dependabot alerts weekly at minimum

Quality Gate

Before completing any GitHub operations task:

  • all issues triaged have appropriate labels
  • no PRs older than 7 days without a review or comment
  • CI failures have been investigated (not just re-run)
  • releases include accurate changelogs
  • security alerts are acknowledged and tracked

來源與署名

來源:affaan-m/ecc位於docs/ja-JP/skills/github-ops提交ef648e0

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架