Agent skill

Cb Release

by BlkLeg in BlkLeg/CircuitBreaker

How a Circuit Breaker release is cut, approved, published and followed up — the candidate→approval→promote flow in release.yml, the release environment gate, the make release- targets, the…

MITAuto-check passedDevelopment

Install Cb Release

skills CLI
$ npx skills add BlkLeg/CircuitBreaker --skill cb-release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BlkLeg/CircuitBreaker cb-release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BlkLeg/CircuitBreaker.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/cb-release .claude/skills/cb-release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cb-release
GitHub stars
201
Token cost
~1.8k tokens
SKILL.md length
776 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

How a Circuit Breaker release is cut, approved, published and followed up — the candidate→approval→promote flow in release.yml, the release environment gate, the make release- targets, the…

  • Works in 8 steps: Never push a v* tag. A hand-pushed tag… → The release environment must exist with… → promote-verify needs contents: write… → …
  • Promote a version
  • SKILL.md covers The flow, Rules that each cost a failed…, Diagnosing a red Release run and What a release does NOT prove, plus 1 more section
  • Calls make, git and gh; needs GITHUB_TOKEN

What it does

Cb Release is an agent skill from BlkLeg/CircuitBreaker. How a Circuit Breaker release is cut, approved, published and followed up — the candidate→approval→promote flow in release.yml, the release environment gate, the make release- targets, the post-release follow-up PR that bumps VERSION and rotates the CHANGELOG, and how to diagnose and recover a failed release. Use this whenever the user asks to tag, release, ship, publish or promote a version, bump VERSION, edit CHANGELOG release headings, touch release.yml or release-followup.yml, clean up draft releases, or when…

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Changelog and release notes. It works with GitHub. The repository describes itself as: Bring your homelab to life. A self-hosted IPAM and service mapper that visualizes complex hardware, compute, and network relationships in real-time. The licence is MIT.

When your agent uses it

  • Promote a version
  • Edit CHANGELOG release headings
  • Touch release.yml
  • Release-followup.yml

Example prompts

  • “/cb-release”

Requirements

  • Node.js
  • A credential in GITHUB_TOKEN

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Never push a v* tag. A hand-pushed tag runs only tag-verify, which
  2. The release environment must exist with a required reviewer. GitHub
  3. promote-verify needs contents: write although it only reads. GitHub
  4. Promote runs on the candidate's exact commit. promote-verify
  5. A tag created by GITHUB_TOKEN fires no push: tags: workflow, and a
  6. VERSION is the only hand-edited version (GOV-09). Everything else is
  7. CHANGELOG headings: released versions read ## [X.Y.Z] — YYYY-MM-DD
  8. Prereleases (X.Y.Z-rc.N) have no mechanical next version

What it can do on your machine

Read from SKILL.md and the folder at commit fc44f2e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • git
    • gh
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, gh and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cb Release loads about 1.8k tokens when it runs. Until then it costs about 150 tokens; SKILL.md has 776 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~150
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BlkLeg/CircuitBreaker at commit fc44f2e, republished under its MIT licence (© BlkLeg). 776 words, ~1,815 tokens.

Download SKILL.mdSave it as .claude/skills/cb-release/SKILL.md (or your agent's skills folder).
name
cb-release
description
How a Circuit Breaker release is cut, approved, published and followed up — the candidate→approval→promote flow in release.yml, the `release` environment gate, the make release-* targets, the post-release follow-up PR that bumps VERSION and rotates the CHANGELOG, and how to diagnose and recover a failed release. Use this whenever the user asks to tag, release, ship, publish or promote a version, bump VERSION, edit CHANGELOG release headings, touch release.yml or release-followup.yml, clean up draft releases, or when a Release run is red. Never push a v* tag by hand — read this first.

Circuit Breaker — Releasing

A release is one dispatch and one human approval. The tag is the last thing that happens, created when the draft is published. Nobody makes a tag by hand.

The flow

make release-candidate            (from main, HEAD must be on origin)
  └─ release.yml channel=candidate promote=true
       gate → build → artifact-smoke → installer-journey (6 distros)
       → image (amd64+arm64) → runtime-parity → Stage Draft Release
       → Discord: "vX draft staged, waiting for you"
       → release-environment-guard, promote-verify
       → promote  ⏸ waits for approval on the `release` environment
                  (Review deployments on the run page, or GitHub mobile)
       → publish draft = tag created → post-publish verifies the
         published assets, dispatches e2e.yml and release-followup.yml
       → Discord: "vX is published"
release-followup.yml (on dev)
  └─ bumps VERSION to next patch, dates the CHANGELOG heading, opens
     `## [next] — unreleased`, deletes stale drafts ≤ vX, opens a PR
     into dev, dispatches the required checks onto it
TargetDoes
make release-candidateThe normal path: build, gate, stage, then wait for approval and publish
make release-stage-onlyStop at the draft (promote=false), e.g. to soak it for a while
make release-promotePublish an already-staged draft (channel=stable). Must run on the same commit the draft was built from

Approving is the moment to soak if you want to: gh release download vX --pattern '*linux_amd64.tar.gz' then install.sh --local-bundle <tarball> --unattended --no-tls. The approval can wait days; nothing re-builds.

Rules that each cost a failed release to learn

  1. Never push a v* tag. A hand-pushed tag runs only tag-verify, which fails on purpose and prints the delete command. If you created a local tag, git tag -d vX.
  2. The release environment must exist with a required reviewer. GitHub silently creates a missing environment unprotected and runs straight through, which would publish without anyone approving. release-environment-guard fails the run in its first minute unless the required_reviewers rule is there. "Prevent self-review" must stay off while there is only one maintainer, or nobody can approve.
  3. promote-verify needs contents: write although it only reads. GitHub hides draft releases from tokens without push access; with read, gh release view says "release not found" for a draft that exists (v0.4.4, PR #161). test_jobs_that_read_the_draft_can_see_it guards this.
  4. Promote runs on the candidate's exact commit. promote-verify compares candidate.json's commit with GITHUB_SHA. So a fix to release.yml itself cannot promote an existing draft: merge the fix, then cut a new candidate from the new main commit. The candidate job deletes and replaces the old draft of the same version.
  5. A tag created by GITHUB_TOKEN fires no push: tags: workflow, and a release it publishes fires no release: published workflow. That is why post-publish dispatches e2e.yml and release-followup.yml explicitly — workflow_dispatch is the one event GITHUB_TOKEN can start.
  6. VERSION is the only hand-edited version (GOV-09). Everything else is generated by scripts/check_version_parity.py --write (make version-sync). The follow-up PR does both for you after each release.
  7. CHANGELOG headings: released versions read ## [X.Y.Z] — YYYY-MM-DD (UTC publish date); the next one reads ## [X.Y.Z] — unreleased. scripts/release_checklist.py requires a ## [VERSION] heading before a draft may be staged. scripts/post_release_bump.py does the rotation; a version bump must never rename the previous section (that is how the 0.4.3 notes were lost into 0.4.4).
  8. Prereleases (X.Y.Z-rc.N) have no mechanical next version: release-followup fails on them by design. Bump VERSION by hand after an rc.
Show full SKILL.md (343 more words)Show less

Diagnosing a red Release run

Start from the failing job, not the run conclusion:

Failing jobUsually meansDo
Derive Versionversion input ≠ VERSION at that refDispatch on the right ref or fix the input
release-environment-guardEnvironment missing or lost its reviewerSettings → Environments → release → Required reviewers
Verify the candidate before promoting: "has no draft to promote"No draft for VERSION, or the token cannot see draftsgh release list; check rule 3
… "the draft was built from X"Promote dispatched on a different commitDispatch on the candidate's commit, or cut a new candidate
… "no longer matches candidate.json" / digest movedDraft assets or the :X-candidate image changed after stagingRe-run the candidate; never hand-edit a draft
Stage Draft Release: "already published"VERSION was not bumped after the last releaseMerge the follow-up PR (or bump VERSION)
post-publishThe published release is broken (asset name, checksum, selftest, API discovery)Treat as an incident: users can download it now
tag-verifySomeone pushed a taggit push origin :refs/tags/vX

gh run view <id> --log-failed | tail -60 gets the error. Per CLAUDE.md, never call a red release check flaky or stale without reproducing it.

What a release does NOT prove

The release gates run artifact-smoke, installer-journey and runtime-parity, which cover packaging. They do not run the browser E2E or the composed agent E2E (quarantined as QUAR-001, issue #162). A release after a frontend dependency bump or an agent change still needs npx playwright test or make e2e-local locally first — see CLAUDE.md "What the gates do NOT cover".

Touching release.yml

  • Read tests/build/test_release_publication_is_gated.py, test_release_approval_gate.py, test_workflow_job_graph.py and test_release_paths_run_before_the_tag.py first; they encode the graph.
  • No continue-on-error and no always() on release jobs. Conditions use !cancelled() && !failure() plus explicit needs.<job>.result == 'success'.
  • Every ${{ }} reaches shell through env:, quoted.
  • New workflow_dispatch inputs need the # checkov:skip=CKV_GHA_7 comment or the required Checkov check goes red.
  • Only promote may declare environment: release.
  • The change only takes effect for releases dispatched from a ref that contains it; a fix on dev does nothing until it reaches main.

Notifications and the other bots are described in cb-automation.

© BlkLeg, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/cb-release of BlkLeg/CircuitBreaker.

Open the folder on GitHubat commit fc44f2e

Compare with similar skills

Cb Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cb Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cb Release this skillBlkLeg/CircuitBreaker201—~1.8kAutomated safety check: PassMIT
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0
Mole CLI Release Flowtw93/Mole70k—~2.5kAutomated safety check: PassGPL-3.0
Draft Release Notesjamiepine/voicebox57k—~941Automated safety check: PassMIT
Mole Release Notes Publishertw93/Mole70k—~1.9kAutomated safety check: PassGPL-3.0
Release Bumpjamiepine/voicebox57k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.

    70k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Draft Release Notes

    jamiepine/voicebox

    Writes or refreshes the Unreleased section of CHANGELOG.md as a themed narrative built from the commits, PRs and diff since the last version tag.

    57k GitHub stars~941 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Publishes curated, bilingual release notes for an existing Mole version tag with gh release edit, including contributor thanks and reactions, after the release workflow finishes.

    70k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Release Bump

    jamiepine/voicebox

    Ends a release cycle by moving the Unreleased changelog notes under a dated version heading, bumping version files with bumpversion and tagging the commit.

    57k GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Cut Release

    jfernandez/bpftop

    Cut a new versioned release of bpftop — pick the version, open a version-bump PR, sign-tag the merge commit on main, and draft GitHub release notes in the project's established format.

    2.7k GitHub stars~2k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

More from BlkLeg/CircuitBreaker

  • Cb Build Test

    BlkLeg/CircuitBreaker

    How Circuit Breaker is built, tested, packaged, and kept secret-safe — the make dev/verify/test targets, the PostgreSQL integration test database and its fixtures, the mono Docker image and native…

    201 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Cb Code Quality

    BlkLeg/CircuitBreaker

    Circuit Breaker code conventions and the quality gates that actually block a push — ruff, mypy, eslint, the pytest coverage ratchet, and the make verify tiers.

    201 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Cb Realtime API

    BlkLeg/CircuitBreaker

    How Circuit Breaker moves data between backend and frontend — the NATS internal bus, Redis pub/sub, the WebSocket stream endpoints and their first-message JWT handshake, SSE log/event streams, and…

    201 GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed
  • Cb Security Hardening

    BlkLeg/CircuitBreaker

    Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

    201 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check passed
  • Cb Automation

    BlkLeg/CircuitBreaker

    The maintenance automation around Circuit Breaker — which bots and scheduled workflows exist (Discord notifications, ledger watch, branch cleanup, Dependabot lockfile sync, the required-checks…

    201 GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Cb Release

What does Cb Release do?

How a Circuit Breaker release is cut, approved, published and followed up — the candidate→approval→promote flow in release.yml, the release environment gate, the make release- targets, the…. Cb Release is an agent skill from BlkLeg/CircuitBreaker.yml, the release environment gate, the make release- targets, the post-release follow-up PR that bumps VERSION and rotates the CHANGELOG, and how to diagnose and recover a failed release.

When should I use Cb Release?

Cb Release fits situations like: promote a version; edit CHANGELOG release headings; touch release.yml; release-followup.yml.

How do I install Cb Release in Claude Code?

Run `npx skills add BlkLeg/CircuitBreaker --skill cb-release -a claude-code`. Or copy the skill folder (.claude/skills/cb-release in BlkLeg/CircuitBreaker) into .claude/skills/cb-release in your project. Claude Code loads it when a task matches its description.

How do I install Cb Release in Codex?

Run `npx skills add BlkLeg/CircuitBreaker --skill cb-release -a codex`. Or copy the skill folder (.claude/skills/cb-release in BlkLeg/CircuitBreaker) into .agents/skills/cb-release in your project. Codex loads it when a task matches its description.

Can I use Cb Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BlkLeg/CircuitBreaker --skill cb-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cb-release, .gemini/skills/cb-release, .github/skills/cb-release and .opencode/skills/cb-release in your project.

What does Cb Release need to run?

Going by SKILL.md and its folder, Cb Release needs the command-line tools its instructions call (make, git, gh and npx) and credentials named GITHUB_TOKEN. Our summary lists: Node.js; A credential in GITHUB_TOKEN.

Does Cb Release access the network?

SKILL.md contains no URLs. Its commands use git, gh and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cb Release safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cb Release use?

Cb Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cb Release use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cb Release?

Skills that share tags, products or a category with Cb Release: Cutting A Release (TriliumNext/Trilium, 38k stars), Mole CLI Release Flow (tw93/Mole, 70k stars), Draft Release Notes (jamiepine/voicebox, 57k stars) and Mole Release Notes Publisher (tw93/Mole, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cb Release?

BlkLeg (a GitHub user) maintains it in BlkLeg/CircuitBreaker, which has 201 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 5, 2026.

Source: BlkLeg/CircuitBreaker on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.