Authoring GitHub Workflows
dotnet/skills
Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run.
Diagnose, fix, and manage Mini Diarium's Flatpak/Flathub packaging across the multi-repo ecosystem.
$ npx skills add fjrevoredo/mini-diarium --skill flathub-maintenance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install fjrevoredo/mini-diarium flathub-maintenance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/fjrevoredo/mini-diarium.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/flathub-maintenance .claude/skills/flathub-maintenance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "flathub-maintenance" agent skill from https://github.com/fjrevoredo/mini-diarium/tree/master/.agents/skills/flathub-maintenance into .claude/skills/flathub-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flathub-maintenance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/fjrevoredo/mini-diarium/tree/master/.agents/skills/flathub-maintenanceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add fjrevoredo/mini-diarium --skill flathub-maintenance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install fjrevoredo/mini-diarium flathub-maintenance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fjrevoredo/mini-diarium.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/flathub-maintenance .agents/skills/flathub-maintenance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "flathub-maintenance" agent skill from https://github.com/fjrevoredo/mini-diarium/tree/master/.agents/skills/flathub-maintenance into .agents/skills/flathub-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flathub-maintenance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add fjrevoredo/mini-diarium --skill flathub-maintenance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install fjrevoredo/mini-diarium flathub-maintenance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fjrevoredo/mini-diarium.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/flathub-maintenance .cursor/skills/flathub-maintenance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "flathub-maintenance" agent skill from https://github.com/fjrevoredo/mini-diarium/tree/master/.agents/skills/flathub-maintenance into .cursor/skills/flathub-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flathub-maintenance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/fjrevoredo/mini-diarium.git --path .agents/skills/flathub-maintenance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add fjrevoredo/mini-diarium --skill flathub-maintenance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install fjrevoredo/mini-diarium flathub-maintenance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fjrevoredo/mini-diarium.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/flathub-maintenance .gemini/skills/flathub-maintenance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "flathub-maintenance" agent skill from https://github.com/fjrevoredo/mini-diarium/tree/master/.agents/skills/flathub-maintenance into .gemini/skills/flathub-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flathub-maintenance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install fjrevoredo/mini-diarium flathub-maintenanceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add fjrevoredo/mini-diarium --skill flathub-maintenance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/fjrevoredo/mini-diarium.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/flathub-maintenance .github/skills/flathub-maintenance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "flathub-maintenance" agent skill from https://github.com/fjrevoredo/mini-diarium/tree/master/.agents/skills/flathub-maintenance into .github/skills/flathub-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flathub-maintenance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add fjrevoredo/mini-diarium --skill flathub-maintenance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install fjrevoredo/mini-diarium flathub-maintenance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fjrevoredo/mini-diarium.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/flathub-maintenance .opencode/skills/flathub-maintenance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "flathub-maintenance" agent skill from https://github.com/fjrevoredo/mini-diarium/tree/master/.agents/skills/flathub-maintenance into .opencode/skills/flathub-maintenance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "flathub-maintenance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
flathub-maintenanceDiagnose, fix, and manage Mini Diarium's Flatpak/Flathub packaging across the multi-repo ecosystem.
Flathub Maintenance is an agent skill from fjrevoredo/mini-diarium. Diagnose, fix, and manage Mini Diarium's Flatpak/Flathub packaging across the multi-repo ecosystem. Use when Flathub builds fail, the manifest or vendored sources (cargo-sources.json, node-sources.json) need regeneration, the runtime or permissions need bumping, AppStream metadata needs updating, or a Flathub PR needs manual intervention. Also use for initial Flathub submission changes, store listing updates, and any task touching flatpak/, .github/workflows/flathub-publish.yml, or the Flathub repo. Triggers…
Its SKILL.md is about 6.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code. Requires git, Python 3, node.
It sits in DevOps & Cloud. It works with GitHub Actions, GitHub and Git. The repository describes itself as: A local-only journal with serious encryption. Free, open source, and never touches the internet. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4627248. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitnpmnodeghbunFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comregistry.npmjs.orgdocs.flathub.orgdocs.flatpak.orgFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
FLATHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code. Requires git, Python 3, node.
From compatibility in the SKILL.md frontmatter.
Flathub Maintenance loads about 6.1k tokens when it runs. Until then it costs about 214 tokens; SKILL.md has 2,568 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from fjrevoredo/mini-diarium at commit 4627248, republished under its MIT licence (© fjrevoredo). 2,568 words, ~6,123 tokens.
.claude/skills/flathub-maintenance/SKILL.md (or your agent's skills folder).Manage Mini Diarium's Flatpak packaging end-to-end — from initial submission through release updates, build diagnosis, and long-term runtime maintenance.
docs/FLATPAK_MAINTENANCE.md — file inventory, invariants, failure signatures, validation checklist, runtime docsdocs/releasing/RELEASING.md — "Automated Flathub Publishing" section explains the publish workflow.github/workflows/flathub-publish.yml — the actual automation that generates sources and opens the Flathub PRflatpak/rewrite-manifest.py — transforms the local type: dir manifest into a pinned type: git manifestflatpak/io.github.fjrevoredo.mini-diarium.yml — the local Flatpak manifest (source of truth)If any of these files are missing or unreadable, stop and tell the user.
Mini Diarium's Flatpak presence spans 3 separate systems:
| System | Repository | Role |
|---|---|---|
| Main repo | github.com/fjrevoredo/mini-diarium | Source of truth for the manifest, lockfiles, fonts, metadata, and CI workflow |
| Flathub repo | github.com/flathub/io.github.fjrevoredo.mini-diarium | Holds the live manifest + vendored sources; receives automated PRs from the workflow |
| Vorarbeiter CI | github.com/flathub-infra/vorarbeiter/actions | Flathub's build system — every PR to the Flathub repo triggers a test build here |
The publish workflow (flathub-publish.yml) bridges main → Flathub:
git worktreecargo-sources.json and node-sources.json from lockfilesrewrite-manifest.py to convert type: dir → type: gitKey insight for diagnosis: failures can originate in any of the 3 systems, and fixes may need to land in one or both repos.
Before doing any work, locate the local checkouts.
Step 1: Check for .agents/flathub-paths.md. If it exists, read the paths from it:
main_repo: /absolute/path/to/mini-diarium
flathub_repo: /absolute/path/to/flathub-repoStep 2: If that file doesn't exist, try common locations:
D:\Repos\mini-diarium, D:\Repos\io.github.fjrevoredo.mini-diarium/mnt/d/Repos/mini-diarium, /mnt/d/Repos/io.github.fjrevoredo.mini-diarium~/Repos/mini-diarium, ~/Repos/io.github.fjrevoredo.mini-diariumStep 3: If still not found, ask the user for the paths. If the user doesn't have a local Flathub repo clone, clone it:
git clone https://github.com/flathub/io.github.fjrevoredo.mini-diarium.git <path>After discovery: offer to create .agents/flathub-paths.md so future sessions skip the search.
flatpak/io.github.fjrevoredo.mini-diarium.yml)Uses type: dir with path: .. for local validation builds. All build command paths are relative
to the repo root. For local validation:
flatpak-builder --user --install --force-clean build-dir flatpak/io.github.fjrevoredo.mini-diarium.yml
flatpak run io.github.fjrevoredo.mini-diariumThe workflow replaces the type: dir source block with:
- type: git
url: https://github.com/fjrevoredo/mini-diarium
commit: <sha>The rest of the manifest (build commands, finish-args, runtime) is preserved verbatim. Build command paths must work identically in both source modes.
All paths in build-commands are relative to the build directory, which is the repo root in both modes.
Never use ../ or nested prefixes that only resolve in one context.
cargo-sources.json, node-sources.json)These files do not exist in the main repo — they are generated artifacts:
flathub-publish.yml workflow during a releaseFLATPAK_MAINTENANCE.mdThe Flathub repo carries the generated copies alongside the manifest. When diagnosing build failures, treat these files as potentially stale if lockfiles changed without re-generation.
generate-node-sources.mjs scriptLocated at flatpak/generate-node-sources.mjs. Generates node-sources.json from package-lock.json and an .npm cache.
Usage:
node flatpak/generate-node-sources.mjs package-lock.json output.json "$HOME/.npm"How it works:
node_modules/ entry from lock.packages that has resolved + integrity.content-length.content-length on HEAD requests. When this happens, the script falls back to a full GET download of the tarball. This can be very slow when many packages are missing from the cache.type: file content entry and a type: inline index entry. Esbuild binaries get special type: archive entries with only-arches constraints.Fallback when generation fails:
node flatpak/check-node-sources.mjs package-lock.json node-sources.json to find all missing packages.package-lock.json, never from bun.lock. The two lockfiles can have different sha512 hashes for the same package@version (bun and npm may resolve different tarball contents). Using bun.lock integrity will cause "Wrong sha512 checksum" errors in vorarbeiter. Verify with: node -e "const l=JSON.parse(require('fs').readFileSync('package-lock.json','utf8')); console.log(l.packages['node_modules/<name>'].integrity)"node-sources.json in URL-sorted order:Content entry format:
{
"type": "file",
"url": "<resolved tarball URL>",
"sha512": "<integrity hex (base64 decoded)>",
"dest-filename": "<hex chars after position 4>",
"dest": "flatpak-node/npm-cache/_cacache/content-v2/sha512/<hex[0:2]>/<hex[2:4]>"
}Index entry format:
{
"type": "inline",
"contents": "<sha1-of-index-json>\t<index-json>",
"dest-filename": "<sha1-of-key chars after position 4>",
"dest": "flatpak-node/npm-cache/_cacache/index-v5/<sha1-of-key[0:2]>/<sha1-of-key[2:4]>"
}The index JSON object is: {"key":"make-fetch-happen:request-cache:<url>","integrity":"<integrity>","time":0,"size":<tarball-size>,"metadata":{"url":"<url>","reqHeaders":{},"resHeaders":{}}}. Compute the SHA1 of the full JSON string for the contents prefix, and the SHA1 of the key string for the index path.
Critical ordering rule: When inserting entries or re-sorting, shell and script entries must always appear after ALL archive entries. flatpak-builder processes node-sources.json sequentially — a cp in a shell command that runs before its archive is extracted will fail. Only sort URL-bearing entries (type file, archive); leave shell and script entries at the end. Run node flatpak/check-node-sources.mjs after any modification to verify both coverage and ordering.
See flatpak/check-node-sources.mjs for the companion gap-detection script.
The Flathub repo may contain a patches/ directory with .patch files. These are
temporary Flathub-only patches applied during the build to fix issues that haven't
been fixed upstream yet. Common patch scenarios: missing metainfo fields (e.g., <url type="vcs-browser">),
developer ID format fixes, AppStream compliance.
Rule: Remove patches as soon as the upstream fix is merged and the manifest can point at a commit that includes the fix. Do not carry permanent Flathub-only patches.
files/fonts or ../fonts not found)Symptom: install: cannot stat 'files/fonts/*.ttf': No such file or directory
Diagnosis: The manifest references a font path that doesn't exist in the source checkout.
Fonts live at fonts/*.ttf in the repo root (10 .ttf files + LICENSES.md).
Fix location: BOTH repos need the fix.
flatpak/io.github.fjrevoredo.mini-diarium.yml — change to fonts/*.ttf
(this fixes future releases via the publish workflow)io.github.fjrevoredo.mini-diarium.yml — same change
(this fixes the current PR so it can pass vorarbeiter)Push to Flathub repo:
cd <flathub-repo>
git checkout update-<x.y.z> # the PR branch
# edit io.github.fjrevoredo.mini-diarium.yml
git add io.github.fjrevoredo.mini-diarium.yml
git commit -m "fix: correct font install path"
git push origin update-<x.y.z>Then comment bot, build on the Flathub PR to trigger a new vorarbeiter build.
ENOTCACHED — vendored node sources incompleteSymptom: npm ERR! ENOTCACHED during npm ci --offline, e.g. request to https://registry.npmjs.org/<pkg> failed: cache mode is 'only-if-cached' but no cached response is available.
Diagnosis: node-sources.json is missing one or more packages declared in package-lock.json. The vendored sources are generated from the lockfile — if the lockfile is stale or the generation was incomplete, npm ci --offline fails because it cannot reach the network.
Root cause chain: package-lock.json → node-sources.json (generated by the publish workflow) → vorarbeiter npm ci --offline. A break at any link causes ENOTCACHED.
Hidden root cause — --package-lock-only with --legacy-peer-deps: The canonical npm command from CLAUDE.md (npm install --package-lock-only --legacy-peer-deps) can produce lockfile entries without resolved and integrity fields for some packages (e.g. peer dep aggregators like @tiptap/extensions). Since generate-node-sources.mjs skips entries without these fields (line 152), the vendored sources are silently incomplete. Running a full npm install --legacy-peer-deps (without --package-lock-only) forces npm to download and resolve all packages, producing complete entries.
First diagnostic step: Run node flatpak/check-node-sources.mjs <package-lock.json> <node-sources.json> to discover ALL missing packages at once. The npm ci error only reports the first failure — there may be more.
Second diagnostic step: If check-node-sources.mjs reports missing packages, check whether package-lock.json itself is the source of the gap — search for the missing package in the lockfile and verify its entry has both resolved and integrity fields.
Fix — two repos, two actions:
Main repo (prevent recurrence): Regenerate the lockfile with real npm so future releases ship a healthy one:
npm install --package-lock-only --ignore-scripts --legacy-peer-depsVerify with check-node-sources.mjs afterward. Commit and push.
Flathub repo (fix current PR): Either re-run the publish workflow (if the lockfile fix is committed and the workflow can regenerate from it), or manually patch node-sources.json with the missing entries and force-push to the PR branch:
cd <flathub-repo>
git checkout update-<x.y.z>
node flatpak/check-node-sources.mjs ../mini-diarium/package-lock.json node-sources.json
# Add missing entries (see generate-node-sources.mjs docs for format)
git add node-sources.json
git commit -m "fix: add missing npm packages to node-sources.json"
git push --force-with-lease origin update-<x.y.z>Then comment bot, build on the Flathub PR to trigger a new vorarbeiter build.
package-lock.json — lockfile integrity gapSymptom: The app builds and works locally (bun resolves everything from bun.lock), but vorarbeiter fails with ENOTCACHED because the publish workflow only reads package-lock.json.
Diagnosis: Two possible causes:
bun.lock is current but package-lock.json was never regenerated with real npm after a package.json change. Run node flatpak/check-node-sources.mjs and compare.package-lock.json was regenerated with npm install --package-lock-only --legacy-peer-deps, but some entries lack resolved/integrity (see Failure 2 "Hidden root cause" above). Search: Select-String -Path package-lock.json -Pattern '"node_modules/zip-stream"' -Context 0,5 and check for resolved field.Fix — when regenerating the lockfile:
npm install --package-lock-only --ignore-scripts --legacy-peer-depsnpm may say "up to date" but still modify the file if packages were added since the last generation.
Fix — when lockfile entries are missing resolved/integrity: Delete node_modules/ and run a full install:
npm install --legacy-peer-depsThen run bun install to sync bun.lock. Verify with check-node-sources.mjs.
cargo-sources.json staleSymptom: perhaps a crate was updated and forgotten to be re-vendored?
Diagnosis: Cargo.lock changed but cargo-sources.json wasn't regenerated.
Fix location: The publish workflow regenerates it automatically from the tagged tree.
If the workflow failed before generation, re-running it should work. If it was generated but
wrong, check that the tagged commit has the correct Cargo.lock.
Symptom: Cannot find module '@rolldown/binding-linux-arm64-gnu' or similar
Diagnosis: node-sources.json is missing arch-specific optional native packages
(@esbuild/linux-*, @rolldown/binding-linux-*, lightningcss-linux-*, etc.).
Fix: The generate-node-sources.mjs script must be run with the correct .npm cache.
Check that the workflow's "Generate node-sources.json" step is using the tagged tree's
package-lock.json, not the checkout's.
Symptom: Failed to find package "@esbuild/linux-x64" or esbuild fails to execute
Diagnosis: The ESBUILD_BINARY_PATH env var is not set or the cached esbuild binary is missing.
Fix: The manifest's build-options.env must include:
ESBUILD_BINARY_PATH: /run/build/mini-diarium/flatpak-node/cache/esbuild/bin/esbuild-currentThis path is set by the vendored esbuild package in node-sources.json. If it breaks, the
node-sources.json is likely stale or was generated without the esbuild binary cache.
Symptom: Vorarbeiter build passes but AppStream validation fails (treated as a blocker).
Diagnosis: Missing or invalid <developer>, <url>, <release>, <content_rating>, or
screenshot URLs in data/linux/io.github.fjrevoredo.mini-diarium.metainfo.xml.
Fix location: Main repo — the tagged commit's metainfo is what Flathub validates. Cut a new release after fixing, or manually patch the Flathub PR manifest if the fix is cosmetic and the main repo fix will land in the next release.
Symptom: Build fails with SDK/runtime errors.
Diagnosis: The manifest's runtime-version or sdk-extensions don't match available
GNOME runtimes or Freedesktop SDK extension branches.
Fix: Check the current available runtimes at Flathub docs. The manifest uses
org.gnome.Platform//50 with org.freedesktop.Sdk.Extension.rust-stable and
org.freedesktop.Sdk.Extension.node20 on branch 25.08. When bumping the runtime,
re-check the matching SDK extension branches.
Symptom: The publish workflow exits with FLATHUB_TOKEN secret is not set.
Diagnosis: The GitHub Actions secret is missing from the main repo.
Fix:
public_repo scope on an account
that has write access to flathub/io.github.fjrevoredo.mini-diariumfjrevoredo/mini-diarium, go to Settings → Secrets and variables → ActionsFLATHUB_TOKEN with the token valuePublish to Flathub workflowSee docs/FLATPAK_MAINTENANCE.md "Required GitHub Secret: FLATHUB_TOKEN" section for details.
| What changed | Fix in main repo? | Fix in Flathub repo? |
|---|---|---|
| Build command (install path, env var, flag) | Yes (for future releases) | Yes (for current PR) |
| Vendored deps (cargo-sources, node-sources) | Workflow regenerates them | Workflow pushes them |
| Manifest source type/path | Handled by rewrite-manifest.py | N/A |
| finish-args / permissions | Yes | Yes (until next workflow run) |
| runtime / SDK extensions | Yes | Yes |
| Desktop file / metainfo / icons | Yes | No (comes from git source) |
| Fonts / bundled assets | Yes (path fix) + ensure files exist | Yes (path fix in current PR) |
https://github.com/flathub/io.github.fjrevoredo.mini-diarium/pullsThe flathubbot comments on the PR with links. Look for "Started test build" comments.
The build number is in the URL: runs/<number>.
Alternatively, browse: https://github.com/flathub-infra/vorarbeiter/actions
Comment bot, build on the Flathub PR. Only collaborators can trigger builds.
cd <flathub-repo>
git checkout update-<x.y.z>
# make changes
git add .
git commit -m "fix: <description>"
git push --force-with-lease origin update-<x.y.z>Note: the publish workflow uses --force-with-lease, so force-pushing the same branch is safe.
Only needed if the automated workflow can't run or a quick fix is needed:
cd <flathub-repo>
git checkout master
git pull
git checkout -b update-<x.y.z>
# copy manifest, cargo-sources.json, node-sources.json from main repo
git add .
git commit -m "Update to <x.y.z>"
git push origin update-<x.y.z>
gh pr create \
--repo flathub/io.github.fjrevoredo.mini-diarium \
--base master \
--head update-<x.y.z> \
--title "Update to <x.y.z>" \
--body "Automated update from https://github.com/fjrevoredo/mini-diarium/releases/tag/v<x.y.z>"runtime-version in both manifests (local + Flathub)25.08 currently)flatpak-builderFLATPAK_MAINTENANCE.md with the new valuesfinish-args)finish-args in the local manifest--share=network, --filesystem=home, or broad filesystem permissions
without a real runtime requirement and a reviewer-ready justificationFLATPAK_MAINTENANCE.md "Permissions" sectiondata/linux/io.github.fjrevoredo.mini-diarium.metainfo.xmlappstreamcli validate data/linux/io.github.fjrevoredo.mini-diarium.metainfo.xml<release version="x.y.z"> block is correct for the tagged releaseAlready completed, but for reference:
type: git pointing to a release commitcargo-sources.json and node-sources.json<developer>, <launchable>, <url>, <content_rating>flathub/io.github.fjrevoredo.mini-diariumWhen a vorarbeiter build fails:
gh CLI (see "Accessing Vorarbeiter Build Logs" below)FLATPAK_MAINTENANCE.md and the "Common Failures" section abovenode flatpak/check-node-sources.mjs <lockfile> <node-sources.json> to find ALL missing packages at once, not just the first failurebot, buildPrimary path (preferred): Use the gh CLI to fetch logs programmatically.
gh api repos/flathub-infra/vorarbeiter/actions/runs/<run-id>/jobs \
--jq '.jobs[] | select(.name | startswith("build")) | {name, id, conclusion}'gh run view <run-id> --repo flathub-infra/vorarbeiter --log --job <job-id>Select-Object -Last 80 (PowerShell) or tail -80 (bash) to see the end of the log where the error appears.Fallback: If gh is unavailable or unauthenticated, use the question tool to ask the user:
"The
ghCLI is not available. Would you like to configure it, or should I fall back to you pasting the error logs manually?"
- "Configure gh CLI" → guide through
gh auth login- "I'll paste the logs" → ask for the content of the failing step from the build URL
Last resort: Reproduce the failure with a local flatpak-builder build.
| Item | Value |
|---|---|
| App ID | io.github.fjrevoredo.mini-diarium |
| Main repo | https://github.com/fjrevoredo/mini-diarium |
| Flathub repo | https://github.com/flathub/io.github.fjrevoredo.mini-diarium |
| Vorarbeiter CI | https://github.com/flathub-infra/vorarbeiter/actions |
| Flathub PRs | https://github.com/flathub/io.github.fjrevoredo.mini-diarium/pulls |
| GNOME runtime | org.gnome.Platform//50 |
| Rust SDK | org.freedesktop.Sdk.Extension.rust-stable on 25.08 |
| Node SDK | org.freedesktop.Sdk.Extension.node20 on 25.08 |
| Flathub docs | https://docs.flathub.org/docs/category/for-app-authors |
| Runtime docs | https://docs.flatpak.org/en/latest/flatpak-builder-command-reference.html |
docs/FLATPAK_MAINTENANCE.md first — it has the authoritative invariant and failure listscargo-sources.json or node-sources.json by hand — they're generatedflatpak-builder locally if possible, or at minimum verify path correctnessflatpak/io.github.fjrevoredo.mini-diarium.yml and run rewrite-manifest.py to see the outputbot, build on the PR after pushing fixes so vorarbeiter picks up the change© fjrevoredo, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/flathub-maintenance of fjrevoredo/mini-diarium.
Open the folder on GitHubat commit 4627248
Flathub Maintenance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Flathub Maintenance this skillfjrevoredo/mini-diarium | 309 | — | ~6.1k | Automated safety check: Pass | MIT | |
| Authoring GitHub Workflowsdotnet/skills | 5.6k | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| OpenWork Release Processdifferent-ai/openwork | 24k | — | ~2.3k | Automated safety check: Pass | Custom licence | |
| Atmos Procloudposse/atmos | 1.4k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| GitHub Repo Managementtaracodlabs/aiden | 852 | — | ~938 | Automated safety check: Pass | Apache-2.0 | |
| Release Publishbkywksj/knowledge-base | 330 | — | ~6.2k | Automated safety check: Pass | Custom licence |
dotnet/skills
Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run.
different-ai/openwork
Cuts an OpenWork desktop release through a tag-driven GitHub Actions workflow that makes no commits, with pre-tag checks on open fix PRs and verification afterward.
cloudposse/atmos
Atmos Pro setup and workflows: settings.pro, GitHub OIDC, affected and inventory uploads, stack locks, pro commit, workflow dispatch, merge queues, and drift detection
taracodlabs/aiden
GitHub repos: create, clone, fork, archive (gh CLI + git). An agent skill from taracodlabs/aiden.
bkywksj/knowledge-base
发布 Tauri 桌面应用新版本,处理版本号同步、Git tag、GitHub Actions 构建、Release 仓库产物同步、Cloudflare R2 上传、update.json 生成、自动更新发布和文档站重建。
jeremylongshore/tons-of-skills-marketplace
Configure Vercel CI/CD with GitHub Actions, preview deployments, and automated testing.
fjrevoredo/mini-diarium
Create, update, review, and execute manual Markdown implementation plans when harness planning mode is not being used.
fjrevoredo/mini-diarium
CRITICAL: Use for performance optimization. An agent skill from fjrevoredo/mini-diarium.
fjrevoredo/mini-diarium
SolidJS framework development skill for building reactive web applications with fine-grained reactivity.
fjrevoredo/mini-diarium
Tauri v2 cross-platform app development with Rust backend. An agent skill from fjrevoredo/mini-diarium.
fjrevoredo/mini-diarium
Enter exploration mode: a thinking partner for researching and thinking through ideas and problems before implementation.
fjrevoredo/mini-diarium
A skill your agent uses when asking about Rust code style or best practices.
Works with
Categories
Diagnose, fix, and manage Mini Diarium's Flatpak/Flathub packaging across the multi-repo ecosystem. Flathub Maintenance is an agent skill from fjrevoredo/mini-diarium. Diagnose, fix, and manage Mini Diarium's Flatpak/Flathub packaging across the multi-repo ecosystem.
Flathub Maintenance fits situations like: flathub builds fail; vendored sources (cargo-sources.json; Node-sources.json) need regeneration; permissions need bumping.
Run `npx skills add fjrevoredo/mini-diarium --skill flathub-maintenance -a claude-code`. Or copy the skill folder (.agents/skills/flathub-maintenance in fjrevoredo/mini-diarium) into .claude/skills/flathub-maintenance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add fjrevoredo/mini-diarium --skill flathub-maintenance -a codex`. Or copy the skill folder (.agents/skills/flathub-maintenance in fjrevoredo/mini-diarium) into .agents/skills/flathub-maintenance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fjrevoredo/mini-diarium --skill flathub-maintenance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/flathub-maintenance, .gemini/skills/flathub-maintenance, .github/skills/flathub-maintenance and .opencode/skills/flathub-maintenance in your project.
Going by SKILL.md and its folder, Flathub Maintenance needs the command-line tools its instructions call (git, npm, node, gh and bun) and credentials named FLATHUB_TOKEN. Our summary lists: Python 3; Node.js. Compatibility (from SKILL.md): Designed for Claude Code. Requires git, Python 3, node..
SKILL.md names 4 domains. In commands or code: github.com, registry.npmjs.org, docs.flathub.org and docs.flatpak.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Flathub Maintenance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.1k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Flathub Maintenance: Authoring GitHub Workflows (dotnet/skills, 5.6k stars), OpenWork Release Process (different-ai/openwork, 24k stars), Atmos Pro (cloudposse/atmos, 1.4k stars) and GitHub Repo Management (taracodlabs/aiden, 852 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
fjrevoredo (a GitHub user) maintains it in fjrevoredo/mini-diarium, which has 309 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 9, 2026.
Source: fjrevoredo/mini-diarium on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.