For developers setting up CI on GitHub. Choose your language, versions and steps to get a clean, valid workflow file with safe default permissions.
Build industry projects on ByteLabs and add verified proof of your skills to your public profile.
You enter
Node.js, versions 20 and 22, branch main, on push, pull request and manual run, with lint, test and build
The tool shows
Valid YAML with permissions contents: read, a concurrency group, a matrix of 20 and 22, actions/checkout@v4, actions/setup-node@v4 with npm cache, then npm ci, npm run lint, npm test and npm run build
In your repository under .github/workflows/, as a .yml file. GitHub runs it on the triggers listed under on.
The GITHUB_TOKEN then can only read the code, so a compromised step cannot push or change settings. Jobs that publish packages get packages: write only for themselves.
Pin at least the major version, as this tool does. For the strictest supply-chain safety pin each action to a full commit SHA.
Yes. It is free, needs no sign-up and runs entirely in your browser, so what you type is not uploaded. You only sign in if you want to email a result to yourself or save it to your CareerByteCode profile.