SKILL.md
GitHub Release Skill
Critical Rules
NEVER run gh release create or gh release delete.
Blocked by hooks. Immutable releases (GA Oct 2025) make tag names permanent — a lightweight tag from gh release create burns that name forever, unrecoverably. CI creates releases from signed tags.
gh release edit is allowed ONLY for --notes / --notes-file to overhaul the release description after CI publishes. All other gh release edit flags are blocked.
No editorializing in release notes, PR/commit text and docs — state what a release does, not how good the work is; no self-praise or narrating the expected. See references/no-editorializing.md.
Start Here
scripts/release-status.sh -R owner/repo reports the phase and a computed NEXT, exiting 0 only when finished. scripts/release-notes-status.sh checks the published body.
Release Flow
- Detect ecosystem — find the project type's version files (see
references/ecosystem-detection.md) - Determine next version — from conventional commits or user input (major/minor/patch)
- Bump version files — every ecosystem-specific one, consistently
- Update CHANGELOG.md — add a release section with date and changes
- Create release branch and PR —
release/vX.Y.Z, always via PR (branch protection typically blocks direct pushes) - After PR merge —
git checkout main && git pull, assert HEAD equals the remote tip (stale-worktree guard), then tagmain's HEAD, never therelease/vX.Y.Ztip:git tag -s vX.Y.Z -m "vX.Y.Z"— seereferences/release-process.mdPhase 3. - Push tag —
git push origin vX.Y.Ztriggers CI - CI publishes release — artifacts, checksums, auto-generated notes
- Overhaul release description — rewrite CI's notes into a narrative;
@mentionevery contributor and reporter inline at their change, never as a## Contributorssection. Source them fromscripts/harvest-contributors.sh, nevergit log. Verify withscripts/release-notes-status.sh. Seereferences/release-process.mdPhase 5. - Do NOT re-run the release workflow after step 9 — many regenerate the body each run, overwriting the overhaul. For downstream retries, use a dispatcher — see
references/ter-republish.md.
Commands
/release— full release flow (detect, bump, PR, tag)/release-prepare— bump versions and open PR only (no tag)/release-status— check release health (version drift, unsigned tags, missing workflows)
Delegation
- Supply chain security (SLSA, SBOMs, attestations): delegate to
enterprise-readinessskill - Branch strategy and conventional commits: delegate to
git-workflowskill
References
references/release-process.mdreferences/ecosystem-detection.md— version-file patternsreferences/immutable-releases.md— immutable releases, tag burningreferences/supply-chain-security.md— SLSA, Sigstorereferences/recovery-procedures.md— burned tags, stuck drafts, drift, body clobberingreferences/ter-republish.md— TER re-publishreferences/typo3-ter-publishing.md— TYPO3 TER publish gotchasreferences/ci-workflow-templates.md— CI workflow templatesreferences/no-editorializing.md— no self-praise