Agent skill

TrueLicense Maven Central Release

by christian-schlichtherle in christian-schlichtherle/truelicense

Documents how TrueLicense is published to Maven Central from a version tag, the plugin constraints behind it and how to rehearse a release locally.

Apache-2.0Auto-check passedDevelopment

Install TrueLicense Maven Central Release

skills CLI
$ npx skills add christian-schlichtherle/truelicense --skill release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install christian-schlichtherle/truelicense release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/christian-schlichtherle/truelicense.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/release .claude/skills/release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release
GitHub stars
399
Token cost
~846 tokens
SKILL.md length
383 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Documents how TrueLicense is published to Maven Central from a version tag, the plugin constraints behind it and how to rehearse a release locally.

  • Cutting a TrueLicense release by pushing a version tag
  • SKILL.md covers Dry run and After a release
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Changing the sonatype-oss-release profile or the publishing setup

What it does

Pushing a tag that starts with v triggers the release workflow, which takes the version from the tag, runs the full build on JDK 8 and publishes to the Central Publisher Portal. Nothing is committed back, so the pom stays on a snapshot version. The skill records the constraints around the central-publishing Maven plugin so the agent does not break this setup.

Key points: the plugin loads on every build that activates the sonatype-oss-release profile, replaces the deploy plugin and adds a publish goal to each module, so the usual deploy-skip property has no effect. An empty tests jar plus an exclude-artifacts setting keep the integration-test module out of the bundle. The profile also turns on javadoc, sources, signing and the obfuscation check, and publishing without it ships unobfuscated artifacts, which has happened for two earlier versions.

Since no CI covers the release path before a tag, the skill describes a local dry run: set a throwaway pre-release version, deploy with the profile against an unreachable endpoint with invalid credentials, and expect a failure at the last module. You then inspect the bundle for jar, sources, javadoc, pom and signature files across all 15 published modules plus the root POM.

When your agent uses it

  • Cutting a TrueLicense release by pushing a version tag
  • Changing the sonatype-oss-release profile or the publishing setup
  • Debugging why an artifact did or did not reach Maven Central
  • Rehearsing the release locally after changing the publishing wiring

Example prompts

  • “Walk me through cutting the next TrueLicense release.”
  • “I changed the publishing plugin config; run a local dry run and check the bundle contents.”
  • “Why did the integration-test module end up in the Central bundle?”
  • “Check that the sonatype-oss-release profile still produces signed javadoc and sources jars.”

Requirements

  • JDK 8 and the Maven wrapper in the repository
  • Central Publisher Portal credentials and signing secrets, listed in the repo README

What it can do on your machine

Read from SKILL.md and the folder at commit 697ff98. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

TrueLicense Maven Central Release loads about 846 tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 383 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~846

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from christian-schlichtherle/truelicense at commit 697ff98, republished under its Apache-2.0 licence (© christian-schlichtherle). 383 words, ~846 tokens.

Download SKILL.mdSave it as .claude/skills/release/SKILL.md (or your agent's skills folder).
name
release
description
How TrueLicense is published to Maven Central, the constraints of the central-publishing-maven-plugin wiring, and how to rehearse a release locally. Use when cutting a release, changing anything in the publishing setup or the sonatype-oss-release profile, or debugging what does or does not reach Central.

Releasing

Pushing a v* tag triggers .github/workflows/release.yml, which derives the version from the tag, runs the full build on JDK 8 and publishes to the Central Publisher Portal. Nothing is committed back; pom.xml stays a snapshot. See README.md for the secrets it needs.

Constraints worth knowing before changing any of this:

  • central-publishing-maven-plugin declares <extensions>true</extensions>, so its lifecycle participant loads on every build that activates sonatype-oss-release — including the JDK 8 compile job, not just deploy. Any replacement has to stay Java 8 compatible.
  • That participant removes maven-deploy-plugin and injects a publish goal into every module's deploy phase. maven.deploy.skip is therefore inert, and there is no per-module opt-out: it declines to install itself only if some module declares the plugin with its own executions, and that decision is global. skipPublishing is evaluated after staging, so it does not spare a module whose artifact has no file.
  • Hence tests builds an empty jar, and excludeArtifacts keeps it out of the bundle. Both are needed: the first so the release does not abort on the last module, the second so an integration-test module never reaches Central.
  • sonatype-oss-release is what enables javadoc, sources, signing and verify-obfuscate-main-classes. Only the two workflows activate it. Anything that publishes without it publishes unobfuscated artifacts — which is how 4.0.1 and 4.0.3 shipped.
Show full SKILL.md (171 more words)Show less

Dry run

The release path has no CI coverage until a tag is pushed, so rehearse it locally before a first release or after changing the wiring. An unreachable endpoint and a throwaway settings file make publishing impossible:

bash
./mvnw versions:set -DnewVersion=4.1.0-PORTALTEST          # the bundle path only runs for a non-SNAPSHOT version
./mvnw -s /tmp/dryrun-settings.xml clean deploy -P sonatype-oss-release \
       -DskipTests -DcentralBaseUrl=http://127.0.0.1:1
unzip -l target/central-publishing/central-bundle.zip
./mvnw versions:revert

where /tmp/dryrun-settings.xml holds a <server><id>central</id> with deliberately invalid credentials. Failing at the last module with Deployment failed while publishing is the expected outcome — that is the upload hitting the dead endpoint. Check the bundle rather than the log: .jar, -sources.jar, -javadoc.jar, .pom and a .asc for each, across all 15 published modules plus the root POM, and no truelicense-tests. Signing needs the passphrase cached in the gpg-agent, or pinentry blocks the build; add -Dgpg.keyname=<fingerprint> if your keyring holds more than one usable key.

Nothing local covers the Portal's own validation of the bundle.

After a release

Bump the truelicense-maven-plugin pin in the root POM's <pluginManagement> to the version just published — the project builds itself with its own previously released plugin — and re-run the JDK 8 / 17 / 25 builds. See Bootstrapping gotcha in CLAUDE.md.

© christian-schlichtherle, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/release of christian-schlichtherle/truelicense.

Open the folder on GitHubat commit 697ff98

Compare with similar skills

TrueLicense Maven Central Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

TrueLicense Maven Central Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
TrueLicense Maven Central Release this skillchristian-schlichtherle/truelicense399—~846Automated safety check: PassApache-2.0
Cline Desktop App Releasecline/cline70k—~4.5kAutomated safety check: PassApache-2.0
EverOS Release WorkflowEverMind-AI/EverOS13k—~1.3kAutomated safety check: PassApache-2.0
Cline CLI Release Publishercline/cline70k—~3.4kAutomated safety check: WarnApache-2.0
Release Lithoxylmahmoud/lithoxyl146—~1.3kAutomated safety check: PassBSD-3-Clause
LobeHub Version Releaselobehub/lobehub83k—~1.2kAutomated safety check: PassCustom licence

Similar skills

  • Covers preparing, tagging and publishing a Cline desktop app release on the stable, beta or nightly channel through the desktop-publish GitHub workflow.

    70k GitHub stars~4.5k tokensUpdated today
    DevelopmentAuto-check passed
  • EverOS Release Workflow

    EverMind-AI/EverOS

    Walks through cutting a versioned everos release: bump the version, update the changelog, tag it, and review the drafted GitHub Release page before publishing.

    13k GitHub stars~1.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Walks through releasing the Cline CLI package to npm: release notes, version bump, matching git tag, and either the GitHub workflow or a local publish.

    70k GitHub stars~3.4k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Release Lithoxyl

    mahmoud/lithoxyl

    Walks through releasing the lithoxyl Python package to PyPI: CalVer version bump, tagging, pushing and checking the published release.

    146 GitHub stars~1.3k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Guides the release PR flow, the CI rules that tag a release and the writing of GitHub Release notes for a repo that develops on a canary branch.

    83k GitHub stars~1.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Release Coherence

    macalbert/envilder

    Unified release coherence workflow for any component (CLI, GHA, or SDK).

    138 GitHub stars~1.3k tokensUpdated 6 days ago
    DevelopmentAuto-check passed

More from christian-schlichtherle/truelicense

  • Maven POM Refactor Check

    christian-schlichtherle/truelicense

    Verifies that a pom.xml change did not silently alter Maven build behavior by diffing the effective POMs before and after.

    399 GitHub stars~883 tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about TrueLicense Maven Central Release

What does TrueLicense Maven Central Release do?

Documents how TrueLicense is published to Maven Central from a version tag, the plugin constraints behind it and how to rehearse a release locally. Pushing a tag that starts with v triggers the release workflow, which takes the version from the tag, runs the full build on JDK 8 and publishes to the Central Publisher Portal. Nothing is committed back, so the pom stays on a snapshot version.

When should I use TrueLicense Maven Central Release?

TrueLicense Maven Central Release fits situations like: cutting a TrueLicense release by pushing a version tag; changing the sonatype-oss-release profile or the publishing setup; debugging why an artifact did or did not reach Maven Central; rehearsing the release locally after changing the publishing wiring.

How do I install TrueLicense Maven Central Release in Claude Code?

Run `npx skills add christian-schlichtherle/truelicense --skill release -a claude-code`. Or copy the skill folder (.claude/skills/release in christian-schlichtherle/truelicense) into .claude/skills/release in your project. Claude Code loads it when a task matches its description.

How do I install TrueLicense Maven Central Release in Codex?

Run `npx skills add christian-schlichtherle/truelicense --skill release -a codex`. Or copy the skill folder (.claude/skills/release in christian-schlichtherle/truelicense) into .agents/skills/release in your project. Codex loads it when a task matches its description.

Can I use TrueLicense Maven Central Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add christian-schlichtherle/truelicense --skill release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release, .gemini/skills/release, .github/skills/release and .opencode/skills/release in your project.

What does TrueLicense Maven Central Release need to run?

SKILL.md names no scripts, command-line tools or credentials: TrueLicense Maven Central Release is instructions for the agent only. Our summary lists: JDK 8 and the Maven wrapper in the repository; Central Publisher Portal credentials and signing secrets, listed in the repo README.

Does TrueLicense Maven Central Release access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is TrueLicense Maven Central Release safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does TrueLicense Maven Central Release use?

TrueLicense Maven Central Release is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does TrueLicense Maven Central Release use?

About 846 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to TrueLicense Maven Central Release?

Skills that share tags, products or a category with TrueLicense Maven Central Release: Cline Desktop App Release (cline/cline, 70k stars), EverOS Release Workflow (EverMind-AI/EverOS, 13k stars), Cline CLI Release Publisher (cline/cline, 70k stars) and Release Lithoxyl (mahmoud/lithoxyl, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains TrueLicense Maven Central Release?

christian-schlichtherle (a GitHub user) maintains it in christian-schlichtherle/truelicense, which has 399 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on August 10, 2026.

Source: christian-schlichtherle/truelicense on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.