salesforce-ci-integration

v2026.09.24

Build fork-safe Salesforce CI with secretless static and fixture gates, protected non-production validation, and separately approved production promotion. Use when automating delivery. Trigger with "add Salesforce CI".

GitHub
Install command
npx skhub add jeremylongshore/salesforce-ci-integration
Markdown
SKILL.md

Fork-Safe Salesforce Continuous Integration

Overview

Separate deterministic untrusted-code checks from credentialed org validation so pull requests cannot access Salesforce secrets or mutate a customer org.

Prerequisites

  • Repository, Salesforce DX project, package layout, branch policy, and immutable dependency lock
  • Synthetic metadata and API fixtures plus an authorized validation org
  • CI, Salesforce admin, security, release, and code owners with environment protection rules

Tool Discipline

Use Read, Glob, and Grep to inspect approved repository and evidence files, WebFetch to re-check current first-party Salesforce documentation, and Write or Edit only for secretless plans, fixtures, configuration, and redacted receipts.

Current Contract

Salesforce CLI can validate and deploy source against authorized orgs, but exact commands, test levels, authentication, and metadata behavior vary with the pinned CLI and project. Fork pull requests must be treated as untrusted.

Authentication

Keep org authorization, certificates, secrets, and aliases out of fork-origin jobs, logs, caches, and artifacts. Resolve protected credentials only after trusted code, environment approval, and exact-head verification.

Instructions

  1. Pin runtime, package manager, Salesforce CLI, plugins, lockfiles, action SHAs, and generated-artifact checks.
  2. Create a secretless lane for formatting, linting, static analysis, unit tests, schema tests, fixture contracts, and source validation.
  3. Model auth expiry, permission denial, API-version drift, metadata conflict, partial deployment, limits, and rollback in fixtures.
  4. Restrict credentialed jobs to protected branches or environments with no fork secrets, minimal permissions, concurrency, and timeouts.
  5. Against an approved non-production org, verify identity, validate the bounded deployment, run required tests, and capture IDs.
  6. Require human approval and immutable artifact promotion before any production validation or deployment job.
  7. Reconcile deployed metadata and application health, publish a redacted receipt, and revoke temporary credentials.

Approval Boundaries

Do not expose secrets to pull requests, authenticate unreviewed code, auto-deploy to production, or lower required test levels or branch protection.

Output

Return the trust-boundary diagram, pinned CI configuration, secretless and protected gate results, org identity proof, validation IDs, promotion approval, and rollback evidence.

Error Handling

ConditionResponse
Fork job requests a Salesforce secretFail closed and keep the live-org lane skipped.
Validation org differs from the expected orgStop immediately, revoke the session, and correct environment binding.
Protected validation is flakyFix determinism or quarantine the lane explicitly; do not silently make it optional.

Example

A redacted completion receipt might look like this:

head=immutable; fork-lane=secretless-pass; protected-org=matched; validate=pass; tests=pass; production=manual

Resources

Next Steps

Run the workflow first in the lowest-risk authorized org and preserve its redacted receipt. Schedule a review against the next Salesforce seasonal release and the customer change calendar.

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

skills/.curated/salesforce-ci-integration

Default branch

main

Latest commit

e5a6c3b

Tree SHA

c2dc8e8