All skills
vercel-labs avatar

/deployments-cicd

@b06012d official

Vercel deployment and CI/CD expert guidance. Use when deploying, promoting, rolling back, inspecting deployments, building with --prebuilt, or configuring CI workflow files for Vercel.

  • 5 files
  • 19.5 KB
  • Updated 18 hours ago
  • GitHub

Use this Skill: https://skilld.dev/gh/vercel-labs/vercel-plugin/deployments-cicd

This session only. Nothing lands on disk.

referencesdeployment-checks.md

≈972 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Deployment Checks

Deployment Checks hold each production deployment until every required check passes, then assign production domains automatically. Vercel keeps building from Git, and only a tested build goes live.

  • Keep auto-assignment of production domains on. The checks decide when it happens.
  • Add checks in Settings → Build and Deployment → Deployment Checks.
  • Force Promote on the deployment page bypasses the checks.
Source What it checks
Vercel (native) Runs the lint and typecheck (or type-check, check-types) scripts from package.json, skipping a check with no matching script. Each check can be limited to specific environments
GitHub Commit statuses and GitHub Actions check runs on the deployed commit. Requires Vercel for GitHub
Integrations Marketplace integrations for testing, monitoring, and observability

Test Each Deployment with GitHub Actions

Vercel sends the vercel.deployment.ready repository dispatch event after it creates a deployment and before checks run. Test the deployment it names, and report the result with vercel/repository-dispatch/actions/status@v1. That action sets a commit status on the deployed commit when the job finishes; require that status as a GitHub check.

name: E2E
on:
  repository_dispatch:
    types: [vercel.deployment.ready]

jobs:
  e2e:
    runs-on: ubuntu-latest
    permissions:
      actions: read
      contents: read
      statuses: write
    steps:
      - uses: vercel/repository-dispatch/actions/status@v1
      - uses: actions/checkout@v4
        with:
          ref: ${{ github.event.client_payload.git.sha }}
      - run: npm ci && npx playwright install --with-deps
      - run: npx playwright test
        env:
          BASE_URL: ${{ github.event.client_payload.url }}
          VERCEL_AUTOMATION_BYPASS_SECRET: ${{ secrets.VERCEL_AUTOMATION_BYPASS_SECRET }}
  • GitHub runs repository_dispatch workflows from the default branch, so check out client_payload.git.sha to test the deployed commit.
  • The status name defaults to <workflow> | <job> (<project> - <environment>), which keeps one status per environment. Renaming the workflow or job renames the status, so select the check again.

Reach Protected Deployments from CI

Standard Protection covers every URL except production domains, including the URL of a production deployment waiting on checks.

Browser tests: create a Protection Bypass for Automation secret, store it as a CI secret, and send it on every request:

// playwright.config.ts
import { defineConfig } from '@playwright/test';

const bypass = process.env.VERCEL_AUTOMATION_BYPASS_SECRET;
if (!bypass) throw new Error('VERCEL_AUTOMATION_BYPASS_SECRET is required');

export default defineConfig({
  use: {
    baseURL: process.env.BASE_URL,
    extraHTTPHeaders: {
      'x-vercel-protection-bypass': bypass,
      'x-vercel-set-bypass-cookie': 'true',
    },
  },
});

Scripted requests: add GitHub Actions as a Trusted Source instead of storing a secret. Scope the rule to the repository and the environments the job may reach, grant the job id-token: write, and send the token from core.getIDToken() in the x-vercel-trusted-oidc-idp-token header.

For agent or local access to a protected URL: ⤳ skill: access-protected-vercel-deployment.

Source: SKILL.md on GitHub

No third-party reports yet.

Signed by skilld at b06012d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 14 hours ago.

Activeupdated 18 hours ago
Other metadata
metadata
{
  "priority": 6,
  "docs": [
    "https://vercel.com/docs/deployments",
    "https://vercel.com/docs/git",
    "https://vercel.com/docs/deployments/promoting-a-deployment",
    "https://vercel.com/docs/deployment-checks"
  ],
  "sitemap": "https://vercel.com/sitemap.xml",
  "pathPatterns": [
    ".github/workflows/*.yml",
    ".github/workflows/*.yaml",
    ".gitlab-ci.yml",
    "bitbucket-pipelines.yml",
    "vercel.json",
    "apps/*/vercel.json"
  ],
  "bashPatterns": [
    "\\bvercel\\s+deploy\\b",
    "\\bvercel\\s+--prod\\b",
    "\\bvercel\\s+promote\\b",
    "\\bvercel\\s+rollback\\b",
    "\\bvercel\\s+inspect\\b",
    "\\bvercel\\s+build\\b",
    "\\bvercel\\s+deploy\\s+--prebuilt\\b"
  ]
}
validate
[
  {
    "pattern": "cron:\\s*['\"]|from\\s+['\"](node-cron)['\"]|cron\\.schedule\\(",
    "message": "Manual cron scheduling detected. Use Vercel Cron Jobs (vercel.json crons) for platform-native scheduled tasks.",
    "severity": "recommended",
    "skipIfFileContains": "vercel\\.json.*crons|@vercel/cron"
  }
]
retrieval
{
  "aliases": [
    "deploy",
    "ci cd",
    "continuous deployment",
    "release pipeline"
  ],
  "intents": [
    "deploy to vercel",
    "set up ci cd",
    "promote deployment",
    "rollback deploy"
  ],
  "entities": [
    "vercel deploy",
    "preview",
    "production",
    "rollback",
    "promote",
    "CI workflow"
  ]
}

README badge

README badge for vercel-labs/vercel-plugin/deployments-cicd