# How the GitHub Actions Workflow Builds and Releases No AI Slop: CI/CD Pipeline Explained

> Learn how the No AI Slop GitHub Actions workflow automates builds and releases. This CI/CD pipeline validates plugins and publishes releases using version tags.

- Repository: [Peter Yang/no-ai-slop](https://github.com/petergyang/no-ai-slop)
- Tags: how-to-guide
- Published: 2026-09-13

---

**The No AI Slop repository uses a two-stage CI/CD pipeline defined in [`.github/workflows/plugin.yml`](https://github.com/petergyang/no-ai-slop/blob/main/.github/workflows/plugin.yml) that validates plugin integrity on every push and automatically publishes GitHub Releases when version tags are pushed.**

The **No AI Slop** plugin is an open-source project by `petergyang` designed to enforce content standards. Its build system ensures that only validated, properly structured plugin packages reach end users through a fully automated GitHub Actions workflow.

## Overview of the Two-Stage Workflow

The pipeline splits responsibilities into distinct **Validate** and **Release** jobs. This separation ensures that every code change undergoes integrity checks while restricting publication privileges to tagged versions only. The workflow leverages Python 3.12 for build consistency and uses GitHub's artifact system to pass validated binaries between jobs.

## The Validation Job: Continuous Integration

### Trigger Conditions

The **Validate** job executes on every pull request, every push to the `main` branch, and any tag matching the `v*` pattern. This comprehensive coverage ensures that broken builds never reach the release stage.

### Build Process and Artifact Upload

The job performs four critical steps. First, `actions/checkout` retrieves the source code. Then `actions/setup-python` configures Python 3.12 specifically. The workflow executes `python scripts/build_plugin.py` to assemble the plugin package. Finally, `actions/upload-artifact` stores the resulting `dist/no-ai-slop-plugin-*.zip` as an artifact named *no-ai-slop-plugin*.

This artifact persistence is crucial because it allows the subsequent Release job to download the exact binary that passed validation, eliminating rebuild risks.

## The Release Job: Automated Publishing

### Tag-Based Deployment

Unlike the validation stage, the **Release** job triggers exclusively when a tag prefixed with `v` is pushed (for example, `v1.2.3`). This gatekeeping ensures that only explicitly versioned commits become public releases.

### Artifact Handling and GitHub CLI Integration

The Release job begins by downloading the pre-built artifact into the `dist/` directory using `actions/download-artifact`. Rather than rebuilding, it publishes the validated binary directly. The workflow then executes:

```bash
gh release create "$GITHUB_REF_NAME" dist/no-ai-slob-plugin-*.zip \
    --generate-notes --verify-tag

```

This command uses the built-in `GITHUB_TOKEN` for authentication, attaches the ZIP file to the release, and auto-generates release notes based on commit history. The `--verify-tag` flag ensures the tag exists before creating the release.

## Inside the Build Script ([`scripts/build_plugin.py`](https://github.com/petergyang/no-ai-slop/blob/main/scripts/build_plugin.py))

Heavy lifting occurs in **[`scripts/build_plugin.py`](https://github.com/petergyang/no-ai-slop/blob/main/scripts/build_plugin.py)**, which orchestrates three distinct phases:

### Source Validation

The script first validates the plugin manifest located at [`.codex-plugin/plugin.json`](https://github.com/petergyang/no-ai-slop/blob/main/.codex-plugin/plugin.json). It verifies that required metadata fields exist, checks prompt length constraints, and confirms that skill files ([`skills/no-ai-slop/SKILL.md`](https://github.com/petergyang/no-ai-slop/blob/main/skills/no-ai-slop/SKILL.md) and [`skills/no-ai-slop/eval.md`](https://github.com/petergyang/no-ai-slop/blob/main/skills/no-ai-slop/eval.md)) and assets (`assets/no-ai-slop.png`) are present and accessible.

### Package Assembly

Upon validation success, the script assembles the package by copying the manifest, skill definitions, evaluation scripts, and legal documents into a temporary `dist/no-ai-slop` directory. It then compresses these contents into `no-ai-slop-plugin-<version>.zip`, where the version is extracted from the manifest.

### Post-Build Verification

Before completion, the script performs integrity checks on the archive. It confirms the ZIP contains exactly the expected file set and validates the archive structure to prevent corruption.

## Local Build Commands

Developers can replicate the CI behavior locally using the same script that powers the pipeline:

```bash

# Full build with artifact retention

python scripts/build_plugin.py

# Validation-only mode (cleans up temporary files)

python scripts/build_plugin.py --check

```

The `--check` flag performs all validation and assembly steps but removes the temporary `dist/no-ai-slop` directory and the ZIP archive afterward, mimicking a dry-run for CI verification.

## Key Files in the Build Pipeline

Understanding the workflow requires familiarity with these specific components:

- **[`.github/workflows/plugin.yml`](https://github.com/petergyang/no-ai-slop/blob/main/.github/workflows/plugin.yml)** – Defines the two-job CI pipeline that separates validation from release duties.
- **[`scripts/build_plugin.py`](https://github.com/petergyang/no-ai-slop/blob/main/scripts/build_plugin.py)** – Python build script handling validation, packaging, and verification.
- **[`.codex-plugin/plugin.json`](https://github.com/petergyang/no-ai-slop/blob/main/.codex-plugin/plugin.json)** – Manifest containing metadata (name, version, interface) consumed by the build process.
- **[`skills/no-ai-slop/SKILL.md`](https://github.com/petergyang/no-ai-slop/blob/main/skills/no-ai-slop/SKILL.md)** – Primary skill definition bundled into the distribution.
- **[`skills/no-ai-slop/eval.md`](https://github.com/petergyang/no-ai-slop/blob/main/skills/no-ai-slop/eval.md)** – Evaluation criteria included in the package.
- **`assets/no-ai-slop.png`** – Visual asset incorporated into the final ZIP.

## Summary

- The GitHub Actions workflow uses a **two-stage architecture**: continuous validation on every commit and conditional releases on version tags.
- **Python 3.12** executes [`scripts/build_plugin.py`](https://github.com/petergyang/no-ai-slop/blob/main/scripts/build_plugin.py) to validate manifests, assemble packages, and verify ZIP integrity.
- Artifacts persist between jobs using GitHub's **upload-artifact** and **download-artifact** actions to ensure release binaries match validated builds.
- The **Release job** uses the GitHub CLI (`gh release create`) with automatic note generation and tag verification to publish distributions.
- Local builds mirror CI behavior through the same Python script, supporting a `--check` mode for validation without artifact retention.

## Frequently Asked Questions

### What triggers the No AI Slop release workflow?

The Release job triggers exclusively when you push a Git tag beginning with `v`, such as `v1.0.0` or `v2.3.1`. This restriction ensures that only explicitly versioned commits generate public releases, while the Validation job runs on every pull request and main branch push.

### How does the build script validate the plugin before packaging?

The **[`scripts/build_plugin.py`](https://github.com/petergyang/no-ai-slop/blob/main/scripts/build_plugin.py)** script performs rigorous source validation by checking that [`.codex-plugin/plugin.json`](https://github.com/petergyang/no-ai-slop/blob/main/.codex-plugin/plugin.json) contains required fields, verifying prompt length constraints, and confirming the existence of skill files ([`SKILL.md`](https://github.com/petergyang/no-ai-slop/blob/main/SKILL.md), [`eval.md`](https://github.com/petergyang/no-ai-slop/blob/main/eval.md)) and assets (`no-ai-slop.png`) before attempting assembly.

### Can I build the No AI Slop plugin locally without GitHub Actions?

Yes. Run `python scripts/build_plugin.py` from the repository root to generate the ZIP distribution locally. Use `python scripts/build_plugin.py --check` to perform validation and assembly without retaining build artifacts, which mimics the CI validation behavior without consuming disk space.

### What files are included in the final plugin ZIP?

The final archive contains the plugin manifest ([`plugin.json`](https://github.com/petergyang/no-ai-slop/blob/main/plugin.json)), skill definitions ([`SKILL.md`](https://github.com/petergyang/no-ai-slop/blob/main/SKILL.md) and [`eval.md`](https://github.com/petergyang/no-ai-slop/blob/main/eval.md)), visual assets (`no-ai-slop.png`), and any included legal documents. The build script verifies that exactly these expected files are present before marking the build as successful.