feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills

Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.

All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
This commit is contained in:
mukul975
2026-04-06 11:17:40 +02:00
parent e8105a2f4d
commit efca3ec611
754 changed files with 12847 additions and 2832 deletions
@@ -1,17 +1,28 @@
---
name: integrating-sast-into-github-actions-pipeline
description: >
This skill covers integrating Static Application Security Testing (SAST) tools—CodeQL
and Semgrep—into GitHub Actions CI/CD pipelines. It addresses configuring automated code
scanning on pull requests and pushes, tuning rules to reduce false positives, uploading
SARIF results to GitHub Advanced Security, and establishing quality gates that block merges
when high-severity vulnerabilities are detected.
description: 'This skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub
Actions CI/CD pipelines. It addresses configuring automated code scanning on pull requests and pushes, tuning rules to reduce
false positives, uploading SARIF results to GitHub Advanced Security, and establishing quality gates that block merges when
high-severity vulnerabilities are detected.
'
domain: cybersecurity
subdomain: devsecops
tags: [devsecops, cicd, sast, codeql, semgrep, secure-sdlc]
tags:
- devsecops
- cicd
- sast
- codeql
- semgrep
- secure-sdlc
version: 1.0.0
author: mahipal
license: Apache-2.0
nist_csf:
- PR.PS-01
- GV.SC-07
- ID.IM-04
- PR.PS-04
---
# Integrating SAST into GitHub Actions Pipeline