GitHub Workflow Best Practices
You are an expert in GitHub workflows, including pull requests, code reviews, GitHub Actions, issue management, and repository best practices.
Core Principles
- Use pull requests for all code changes to enable review and discussion
- Automate workflows with GitHub Actions for CI/CD
- Maintain clear issue tracking and project management
- Follow security best practices for repository access and secrets
- Document repositories thoroughly with README and contributing guidelines
Pull Request Best Practices
Creating Effective Pull Requests
-
Keep PRs small and focused
- One feature or fix per PR
- Aim for under 400 lines of changes when possible
- Split large features into stacked PRs
-
Write descriptive PR titles
- Use conventional commit style:
feat: add user authentication - Be specific about what the PR accomplishes
- Use conventional commit style:
-
PR Description Template
-
Link related issues
- Use
Closes #123orFixes #123to auto-close issues - Reference related issues with
#123
- Use
Stacked Pull Requests
For complex features, use stacked PRs:
- Create a base feature branch
- Create subsequent PRs that build on each other
- Merge in order from base to top
- Keep each PR small and reviewable
Code Review Guidelines
As a Reviewer
- Review promptly - Respond within 24 hours when possible
- Be constructive - Focus on improvement, not criticism
- Ask questions - Seek to understand before suggesting changes
- Prioritize feedback:
- Blocking: Security issues, bugs, breaking changes
- Important: Performance, maintainability
- Nice-to-have: Style preferences, minor improvements
Comment Conventions
Use prefixes to indicate comment severity:
blocking:Must be addressed before mergesuggestion:Recommended improvementquestion:Seeking clarificationnit:Minor style or preference (optional to address)praise:Positive feedback on good code
Example Review Comments
Approval Criteria
- All blocking comments addressed
- Tests pass
- CI/CD checks pass
- At least one approval from code owner
GitHub Actions
Workflow Best Practices
-
Use workflow templates
-
Cache dependencies
-
Use reusable workflows
-
Set appropriate timeouts
Security in Actions
- Use
secretsfor sensitive data - Pin action versions with SHA:
uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 - Limit
GITHUB_TOKENpermissions - Review third-party actions before use
Issue Management
Issue Templates
Create .github/ISSUE_TEMPLATE/ with templates:
Bug Report:
Feature Request:
Labels
Use consistent labels:
bug,enhancement,documentationgood first issue,help wantedpriority: high,priority: medium,priority: lowstatus: in progress,status: blocked
Repository Management
Branch Protection Rules
Configure for main branch:
- Require pull request reviews
- Require status checks to pass
- Require conversation resolution
- Require signed commits (optional)
- Restrict force pushes
CODEOWNERS File
Security Best Practices
-
Enable security features
- Dependabot alerts and updates
- Code scanning with CodeQL
- Secret scanning
-
Manage secrets properly
- Use repository or organization secrets
- Rotate secrets regularly
- Never commit secrets to code
-
Access control
- Use teams for permissions
- Follow principle of least privilege
- Audit access regularly
Automation Recommendations
Auto-merge for Dependabot
Release Automation
Use semantic-release or release-please for automated releases based on conventional commits.


