
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
sdlc-ai-workflow
Advanced tools
Complete SDLC Workflow Plugin for Claude Code: 26 agents, 43 skills, 14 commands, 6 phases. Covers planning → design → development → testing → deployment → operations, with industry-standard SDLC best practices embedded in every agent.
Topics: sdlc workflow automation agents claude-code orchestration devops testing security code-review architecture ai-powered
AI-powered end-to-end software development orchestration — 26 specialized agents collaborate across 6 SDLC phases with real-time monitoring and automated quality gates.
A complete SDLC Workflow in a Plugin: 26 agents across 6 phases, 43 knowledge skills, 14 commands. Covers planning → design → development → testing → deployment → operations, with industry-standard SDLC best practices embedded in every agent.
Built for: Claude Code users, development teams, automation engineers, DevOps practitioners
Key Benefits:
sudo npm install -g sdlc-ai-workflow
sdlc-ai-workflow install
Restart Claude Code. Done!
Update later:
sudo npm install -g sdlc-ai-workflow@latest
sdlc-ai-workflow install
npm run ui command (web-based dashboard)npm run init-dashboard command./projects/<feature-name>/ directory./sdlc-plan "feature", Product Manager will ask 32 questions across 4 phases (problem, users, constraints, success). Answer honestly and specifically.sudo npm install -g sdlc-ai-workflow@latestnpm run ui or npm run init-dashboard/sdlc-plan "your feature" and answer the grill-me questionsgit clone https://github.com/saitarrun/sdlc-ai-workflow
cd sdlc-ai-workflow
npm install
npm run install-local
Restart Claude Code.
See INSTALLATION.md for:
Traditional development workflows require manual handoffs between specialists (architects → engineers → testers → ops). Each transition loses context, creates delays, and introduces errors.
SDLC Workflow automates the entire software development lifecycle with AI agents that:
Rapid Prototyping — From idea to tested, deployed prototype in hours
/sdlc "build a user authentication system" --parallel
Consistent Quality — Every project follows industry standards without manual oversight
Team Scaling — Reduce onboarding time by automating knowledge transfer
Continuous Improvement — Track metrics across all SDLC phases
All agents auto-load phase-specific skills — agents automatically apply relevant methodologies to produce industry-standard outputs.
New agents in Phase 1 & 2:
Phase 1 — Planning, Strategy & Requirements
Phase 2 — Design & Prototyping
Phase 3 — Development & Coding
Phase 4 — Testing & Security Auditing
Phase 5 — Infrastructure & Deployment
Phase 6 — Production, Maintenance & Monitoring
| Command | Phase | Purpose |
|---|---|---|
/sdlc | All | Master orchestrator with 6-phase gates and shared state |
/sdlc --parallel | All | Run all phases with agents working in parallel |
/sdlc-parallel | Any | Run phase with agents collaborating in parallel |
/sdlc-plan | 1 | Requirements gathering → PRD + stories + threat model |
/sdlc-design | 2 | UX research → wireframes + component spec |
/sdlc-dev | 3 | Full-stack implementation per architecture |
/sdlc-test | 4 | Test suite + security audits (AppSec + pen test) |
/sdlc-deploy | 5 | CI/CD pipeline + cloud IaC |
/sdlc-ops | 6 | SLOs + security monitoring + data pipelines |
/sdlc-review | Any | Industry-standard PR review with gh pr comments |
Skills inject methodology into agents (no tools/model — pure knowledge context). Organized by phase + utilities:
Phase 1 — Planning & Requirements
skill-requirements — INVEST criteria, QUANTS frameworkskill-prd-synthesis — Convert conversation context into PRDskill-plan-breakdown — Break plan into vertical-slice issuesskill-issue-triage — Triage workflow for bugs/featuresPhase 2 — Design & Prototyping
skill-ux-design — User journeys, personas, wireframingskill-prototype — Throwaway code to validate design assumptionsPhase 3 — Development & Coding
skill-code-standards — Clean Code, SOLID, DRY, namingskill-architecture — ADR format, coupling/cohesion, fitness functionsskill-architecture-refactor — Find deepening opportunities, improve testabilityskill-zoom-out — Understand code at higher abstraction levelPhase 4 — Testing & Security Auditing
skill-code-quality — Linting, testing pyramid, SAST/SCA, security standards, CI/CD gatesskill-code-review — Code review taxonomy, peer review cultureskill-pr-review — Multi-agent parallel PR review, CLAUDE.md compliance, git history, confidence scoringskill-testing — Testing Pyramid, F.I.R.S.T., test doublesskill-tdd — Test-driven development: red-green-refactor loopskill-playwright — Browser automation, E2E testing, visual regression, cross-browser validationskill-diagnose — Disciplined bug diagnosis, reproduce → hypothesise → instrument → fixskill-threat-modeling — STRIDE, PASTA, attack surface mappingskill-security-audit — OWASP Top 10, CWE taint analysisPhase 5 — Infrastructure & Deployment
skill-cicd — Hermetic builds, presubmit gates, trunk-based devskill-precommit-hooks — Pre-commit enforcement for quality gatesskill-cloud-infra — Terraform, IaC patterns, cloud servicesPhase 6 — Operations & Maintenance
skill-ops-sre — SLO/SLI, QUANTS, error budgets, toil measurementskill-documentation — Audience-first writing, docs-as-codeUtilities & Meta
skill-caveman — Ultra-compressed communication, 75% token reductionskill-grill-me — Relentless design review, decision tree interrogationskill-handoff — Compact session for agent handoffskill-teach — Teach skill/concept over multiple sessionsskill-write-skill — Create new agent skillsskill-git-safety — Git destructive operation guards# Build a feature end-to-end
/sdlc "your feature description"
# Build faster with parallel agents (2-3x speedup)
/sdlc "your feature description" --parallel
# Review a PR with code-review-graph analysis
/sdlc-review --pr 1 --with-graph
Need to remember commands? Run the interactive menu:
npm run menu
# OR
sdlc
Full command reference: See QUICK_REFERENCE.md
Run the full 6-phase SDLC pipeline end-to-end:
/sdlc "build a user authentication system"
The command will:
./projects/<feature-name>/ for shared stateThe orchestrator manages agent dependencies, maintains an execution queue, and broadcasts real-time status updates:
npm run orchestrator -- --dir /path/to/project --port 4242 --run-id <optional-run-id>
Features:
./projects/<feature-name>/collaboration-log.jsonAPI Endpoints:
GET /api/runs — List all runsGET /api/runs/:id — Get specific run details with agent statusesPOST /api/agent/spawn/:agent — Mark agent as workingPOST /api/agent/complete/:agent — Mark agent as completePOST /api/agent/block/:agent — Mark agent as blockedGET /events — Server-Sent Events stream for real-time updatesEvery SDLC run creates an organized project directory with clear separation of concerns:
./projects/<feature-name>/
├── docs/ ← All documentation
│ ├── 01-grill-summary.md ← Grill-me interview (source of truth)
│ ├── 01-roadmap.md ← Product vision and milestones
│ ├── 01-requirements.md ← User stories + acceptance criteria
│ ├── 01-architecture.md ← ADR, tech stack, design
│ ├── 01-threat-model.md ← STRIDE threats + security controls
│ ├── ARCHITECTURE.mmd ← Mermaid diagrams (components, deployment)
│ ├── 02-user-journeys.md ← Personas and journey maps
│ ├── 02-wireframes.md ← UI designs + component specs
│ ├── 03-implementation.log ← Dev phase summary
│ ├── 04-test-cases.md ← Test strategy and coverage
│ ├── 04-security.md ← OWASP audit + pen test findings
│ ├── 05-pipeline.log ← CI/CD execution results
│ ├── 06-slo.md ← SLOs, error budgets, runbooks
│ ├── 06-secops.md ← Security monitoring setup
│ ├── 06-data-pipelines.md ← ETL/ELT workflows
│ └── SUMMARY.md ← Final summary
│
├── frontend/ ← Frontend application
│ ├── src/
│ │ ├── components/ ← Reusable UI components
│ │ ├── pages/ ← Page-level components
│ │ └── services/ ← API clients, utilities
│ ├── public/ ← Static assets
│ ├── package.json
│ └── Dockerfile
│
├── backend/services/ ← Microservices architecture
│ ├── api-gateway/ ← Entry point for all requests
│ │ ├── src/
│ │ ├── package.json
│ │ └── Dockerfile
│ ├── <domain-service>/ ← One directory per service
│ │ ├── src/
│ │ ├── migrations/ ← Database migrations
│ │ ├── tests/
│ │ ├── package.json
│ │ └── Dockerfile
│ └── ...
│
└── deployment/ ← Infrastructure & DevOps
├── .github/workflows/ ← GitHub Actions CI/CD
├── docker/ ← Containerization
│ ├── docker-compose.yml ← Local dev orchestration
│ └── Dockerfiles/ ← Multi-stage builds
├── k8s/ ← Kubernetes manifests
├── terraform/ or helm/ ← Infrastructure as Code
└── ...
Key Principles:
services/ with api-gateway + domain servicesFor faster iteration, run individual phases:
/sdlc-plan "add OAuth login" # Phase 1 only
/sdlc-design # Phase 2 only
/sdlc-dev --stack backend,frontend # Phase 3 (backend + frontend)
/sdlc-test --layer all --run # Phase 4 (full test + security)
/sdlc-deploy --trigger # Phase 5 (CI/CD + cloud)
/sdlc-ops --framework prometheus # Phase 6 (SRE + monitoring)
Perform industry-standard review on any PR:
/sdlc-review --pr 1 # Review PR #1 with 3 parallel agents
The command posts inline comments via gh pr comment, confidence-filtered to show only high-confidence issues.
Enhanced review with visual dependency analysis:
/sdlc-review --pr 1 --with-graph # Review PR #1 with dependency visualization
This includes:
See INTEGRATIONS.md for full details on code-review-graph capabilities.
All 20 agents work in parallel with real-time communication and shared context:
./projects/<feature-name>/ with context.json for shared statecollaboration-log.json)Sequential (Old Way):
SoftwareArchitect ──► FrontendEngineer ──► BackendEngineer ──► DatabaseEngineer
12m 12m 12m 12m
= 48 minutes total
Parallel (New Way):
SoftwareArchitect (12m)
│
(publishes architecture)
│
┌───┴────┬──────────┐
▼ ▼ ▼
FE (12m) BE (12m) DB (12m) ◄── All run in parallel
└────┬────┘
▼
Integration (3m)
= 25 minutes total (2x speedup)
# Run all phases with parallel agents
/sdlc "build a user auth system" --parallel
# Run specific phase with parallelization
/sdlc-parallel phase-3 --max-workers=4 --feedback-loops
# Show real-time collaboration log
/sdlc --show-collaboration-log --verbose
See AGENT_COLLABORATION.md for full documentation.
The plugin now enforces comprehensive code quality standards across 5 dimensions:
All agents come with working configurations:
See skill-code-quality for complete documentation and implementation examples.
All development agents enforce:
d, info, data)Create agents/new-agent-name.md with frontmatter:
---
name: new-agent-name
description: When to invoke this agent...
tools: Read, Bash, Write, etc.
model: haiku|sonnet|opus
color: optional-hex-or-name
---
Write the system prompt in the body with book principles embedded
Update skills/ to reference relevant methodologies if needed
Integrate into a command or the master /sdlc orchestrator
Create skills/skill-name/SKILL.md with frontmatter:
---
name: skill-name
description: This skill should be used when the user asks to "..."
version: 1.0.0
---
Write methodology content that agents will load automatically
Add optional reference files in skills/skill-name/references/
make validate
make uninstall
Test the plugin with sample features:
Phase 1 — Planning: /sdlc-plan "add user profile page"
Phase 2 — Design: /sdlc-design
Phase 3 — Development: /sdlc-dev --stack backend,frontend
Phase 4 — Testing: /sdlc-test --layer all --run
Phase 5 — Deployment: /sdlc-deploy --trigger
Phase 6 — Operations: /sdlc-ops --framework prometheus
End-to-end: /sdlc "build a user authentication system"
MIT (or as specified by the user)
Reference docs archived in docs/:
docs/INTEGRATION.md — code-review-graph integrationdocs/AGENT_DEVELOPMENT_GUIDE.md — Agent anatomydocs/AGENT_COLLABORATION.md — Parallel execution detailsdocs/AGENT_SKILLS_MANIFEST.md — Skill mapping referenceTo extend this plugin with new agents, skills, or commands, follow the patterns documented in CLAUDE.md.
FAQs
Complete SDLC Workflow Plugin for Claude Code: 26 agents, 43 skills, 14 commands, 6 phases. Covers planning → design → development → testing → deployment → operations, with industry-standard SDLC best practices embedded in every agent.
We found that sdlc-ai-workflow demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.