ci-cd-setup
Generate CI/CD configuration for automated builds, tests, and distribution of iOS/macOS apps. Use when setting up GitHub Actions, Xcode Cloud, or fa…
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
CI/CD Setup Generator
Generate CI/CD configuration for automated builds, tests, and distribution of iOS/macOS apps.
When This Skill Activates
- User wants to automate their build and test process
- User mentions GitHub Actions, Xcode Cloud, or fastlane
- User wants to set up TestFlight or App Store deployment
- User asks about continuous integration for their app
Pre-Generation Checks
Before generating, verify:
- Existing CI Configuration
# Check for existing CI files
ls -la .github/workflows/ 2>/dev/null
ls -la ci_scripts/ 2>/dev/null
ls -la fastlane/ 2>/dev/null
- Project Structure
# Find Xcode project/workspace
find . -name "*.xcodeproj" -o -name "*.xcworkspace" | head -5
- Package Manager
# Check for SPM vs CocoaPods
ls Package.swift 2>/dev/null
ls Podfile 2>/dev/null
Configuration Questions
1. CI/CD Platform
- GitHub Actions (Recommended) - Full control, extensive marketplace
- Xcode Cloud - Native Apple integration, simpler setup
- Both - GitHub for PRs/tests, Xcode Cloud for releases
2. Distribution Method
- TestFlight - Beta testing via App Store Connect
- App Store - Production releases
- Direct (macOS only) - Notarized DMG/PKG distribution
- All - Full pipeline from dev to production
3. Include fastlane?
- Yes - Advanced automation, match for code signing
- No - Simpler setup using xcodebuild directly
4. Code Signing Approach
- Manual - Certificates in GitHub Secrets
- match (fastlane) - Git-based certificate management
- Xcode Cloud Managed - Apple handles signing
Generated Files
GitHub Actions
.github/workflows/
├── build-test.yml # PR checks, unit tests
├── deploy-testflight.yml # TestFlight deployment
└── deploy-appstore.yml # App Store submission
Xcode Cloud
ci_scripts/
├── ci_post_clone.sh # Post-clone setup
└── ci_pre_xcodebuild.sh # Pre-build configuration
fastlane
fastlane/
├── Fastfile # Lane definitions
├── Appfile # App configuration
└── Matchfile # Code signing (if using match)
SwiftLint
.swiftlint.yml # from templates/swiftlint/swiftlint.yml
Merging Skill Rule Fragments
Skills in this library may ship graduated enforcement as a
rules/swiftlint.yml fragment (opt_in_rules + custom_rules) — prose
rules turned into deterministic lint. When generating .swiftlint.yml:
- Start from
templates/swiftlint/swiftlint.yml. - For each skill the project actually uses, check for
skills/<category>/<skill>/rules/swiftlint.yml; append its
custom_rules entries and union its opt_in_rules.
- Respect fragment scoping comments — e.g.
observable_object_legacy
applies only to iOS 17+/macOS 14+ deployment targets, and
xctest_in_unit_tests must keep its UITests exclusion (XCUITest
legitimately requires XCTest).
- The generated
build-test.ymlruns thelintjob automatically once
.swiftlint.yml exists (if: hashFiles('.swiftlint.yml') != '').
Current fragments: security/ (hardcoded secrets), ios/coding-best-practices
(print-in-production, legacy ObservableObject, force_unwrapping/force_try),
testing/tdd-feature (XCTest scoped out of unit tests),
swift/concurrency (@unchecked Sendable without justification).
Integration Steps
GitHub Actions Setup
- Add Repository Secrets (Settings > Secrets and variables > Actions):
APP_STORE_CONNECT_API_KEY_ID- API Key IDAPP_STORE_CONNECT_API_ISSUER_ID- Issuer IDAPP_STORE_CONNECT_API_KEY_CONTENT- Private key (.p8 content)CERTIFICATE_P12- Base64-encoded .p12 certificateCERTIFICATE_PASSWORD- Certificate passwordPROVISIONING_PROFILE- Base64-encoded provisioning profile
- Create App Store Connect API Key:
- Go to App Store Connect > Users and Access > Keys
- Generate API Key with "App Manager" role
- Download the .p8 file (only available once)
- Export Certificate:
# Export from Keychain as .p12, then base64 encode
base64 -i certificate.p12 | pbcopy
Xcode Cloud Setup
- Enable Xcode Cloud in Xcode:
- Product > Xcode Cloud > Create Workflow
- Connect to App Store Connect
- Configure Workflow:
- Set start conditions (branch, PR, tag)
- Configure environment variables
- Set up post-actions (TestFlight, App Store)
- Add ci_scripts to repository for customization
fastlane Setup
- Install fastlane:
brew install fastlane
- Initialize (if starting fresh):
fastlane init
- Set up match (optional, for code signing):
fastlane match init
fastlane match development
fastlane match appstore
Best Practices
Caching
- Cache Swift Package Manager dependencies
- Cache DerivedData for faster builds
- Use selective caching to avoid stale artifacts
Secrets Management
- Never commit certificates or keys
- Use environment variables for sensitive data
- Rotate API keys periodically
Build Optimization
- Use incremental builds where possible
- Parallelize test execution
- Skip unnecessary steps on draft PRs
Notifications
- Slack/Discord integration for build status
- Email notifications for failures
- GitHub status checks for PRs
References
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
skills/generators/ci-cd-setup/SKILL.md