harden-gitlab-ci
jrjsmrtn/project-orchestration-skillsHarden GitLab CI/CD pipelines for supply-chain security — SHA-pin `include:` and CI/CD components, scope the `CI_JOB_TOKEN` allowlist, protect and mask…
Scores out of 100 · grade B+
2026-08-06Works
40% of the score90/100
- References 1 file that is not in the repo: ./authenticate.sh.
Maintained
25% of the score100/100
- no commits in the last 12 weeks
Adopted
20% of the score15/100
- 12 stars on the source repo.
Documented
15% of the score81/100
- 2,466 words with worked examples.
Install
npx skills add jrjsmrtn/project-orchestration-skills/harden-gitlab-ciWhat the check found
| Finding | What it means |
|---|---|
| Missing files | It points at files that are not in the repository, so those steps will fail. |
Files it references that are not in the repository
What it says it does
Harden GitLab CI/CD pipelines for supply-chain security — SHA-pin `include:` and CI/CD components, scope the `CI_JOB_TOKEN` allowlist, protect and mask variables, pin job image digests, and use `id_tokens`/OIDC instead of long-lived secrets. Use when adding or auditing a `.gitlab-ci.yml`, before making a GitLab project public, when a supply-chain review flags CI gaps, or when standardizing pipeline hardening across GitLab projects (gitlab.com or self-hosted). GitLab-specific by design — for GitHub Actions use `harden-github-actions`; Forgejo/Gitea Actions are out of scope.
Also in jrjsmrtn/project-orchestration-skills
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| analyze-projectjrjsmrtn/project-orchestration-skills | clean | Skill | 12 stars | today | |
| harden-github-actionsjrjsmrtn/project-orchestration-skills | clean | Skill | 12 stars | today | |
| setup-architecture-as-codejrjsmrtn/project-orchestration-skills | Missing files | Skill | 12 stars | today | |
| setup-pre-commitjrjsmrtn/project-orchestration-skills | clean | Skill | 12 stars | today | |
| setup-container-securityjrjsmrtn/project-orchestration-skills | Missing files | Skill | 12 stars | today | |
| setup-git-hooksjrjsmrtn/project-orchestration-skills | Missing files | Skill | 12 stars | today |
Other git & workflow skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| finishing-a-development-branchobra/superpowers | clean | Git & workflow | 167,156 installs | 2 days ago | |
| using-git-worktreesobra/superpowers | clean | Git & workflow | 170,252 installs | 2 days ago | |
| git-guardrails-claude-codemattpocock/skills | clean | Git & workflow | 252,653 installs | today | |
| github-issuesgithub/awesome-copilot | clean | Git & workflow | 14,854 installs | today | |
| setup-pre-commitmattpocock/skills | clean | Git & workflow | 245,932 installs | today | |
| commitmicrosoft/vscode | clean | Git & workflow | 189k stars | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=jrjsmrtn%2Fproject-orchestration-skills)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
