proomt

Search

Search posts, papers, and topics

All posts

SitePoint16 min readtutorialintermediate

Automating DevSecOps Static Analysis with GitHub Actions and Agent Skills

Summary

The article shows how to package an AST‑based TypeScript security scanner as an Agent Skill, run it in a GitHub Actions workflow on every PR, and upload SARIF v2.1.0 results to get native inline annotations. It also covers enforcing the scan as a required status check in branch protection.

  • Define a SKILL.md manifest to declare inputs, outputs, and sandbox constraints for a reusable static scanner.
  • Implement an AST‑based TypeScript scanner using the TypeScript Compiler API to detect secrets, eval, innerHTML, and prototype‑pollution patterns.
  • Configure a GitHub Actions workflow that runs the scanner via tsx, outputs SARIF, and uploads it with codeql-action/upload-sarif for inline PR annotations.
  • Add the workflow as a required status check in branch protection to make security feedback mandatory.

TypeScript developers and DevSecOps teams who want automated, shift‑left security checks integrated directly into GitHub pull‑request workflows.

6/10

Related reading

  1. Optimizing GitHub Actions for Agent PRs: Speculative Test Slicing and AST Impact Analysis

    A step‑by‑step guide for handling the flood of pull requests generated by code‑generation agents. It builds a TypeScript CLI that uses ts‑morph to do AST‑level change‑impact analysis, maps affected symbols to tests, and runs only those tests in a “speculative” GitHub Actions job while a full‑suite verification runs in the background. The article includes concrete CLI code, dependency choices, con…

    SitePointsitepoint.com17 min
  2. Blog: How to Build a DevOps Agent

    This blog walks through the open‑source DevOps Agent Kit, which lets Claude Code or Cursor act as a DevOps assistant by connecting to CloudBees Unify, Jira, and Slack via MCP servers and to GitHub via the CLI. It provides a repeatable setup (Docker, Node, env file) and seven slash commands for pipeline overview, triage, security, release readiness, flag management, CI health scoring, and Jira tic…

    Codeshipcloudbees.com10 min
  3. Build a Typed Context Compaction Gate for AI Agents

    A step‑by‑step tutorial showing how to build a typed context‑compaction gate for AI agents in TypeScript using LangChain and Zod. It defines a discriminated‑union schema for keep/summarize/discard actions, implements a fast gpt‑4o‑mini classifier, validates decisions at runtime, and wires the gate as middleware in an agent loop, with testing and production‑grade tuning advice.

    SitePointsitepoint.com16 min
  4. Eliminating AI Code Hallucinations with TypeScript Compiler Diagnostics and TDD Loops

    The article shows how to replace raw TypeScript compiler output with a programmatic JSON feedback loop that merges diagnostics and Vitest test failures, feeding the structured data back to an LLM coding agent for self‑correction. It provides concrete code for extracting, enriching, validating, and de‑duplicating errors, and demonstrates token savings and deterministic iteration until compilation…

    SitePointsitepoint.com15 min