Agent skill

Release Devbox

by jetify-com in jetify-com/devbox

Cut a Devbox CLI release — recommend the version bump, write the release notes, and drive the draft or publish flow.

Apache-2.0Auto-check passedDevelopment

Install Release Devbox

skills CLI
$ npx skills add jetify-com/devbox --skill release-devbox -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jetify-com/devbox release-devbox --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jetify-com/devbox.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/release-devbox .claude/skills/release-devbox && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release-devbox
GitHub stars
12k
Token cost
~2.5k tokens
SKILL.md length
1,335 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Cut a Devbox CLI release — recommend the version bump, write the release notes, and drive the draft or publish flow.

  • Works in 4 steps: Look at what would ship → Ask how they want to release → Write the title and notes → …
  • Asked to release devbox
  • SKILL.md covers 1. Look at what would ship, 2. Ask how they want to release, 3. Write the title and notes and 4. Run it, plus 3 more sections
  • Calls gh and node; needs GITHUB_TOKEN

What it does

Release Devbox is an agent skill from jetify-com/devbox. Cut a Devbox CLI release — recommend the version bump, write the release notes, and drive the draft or publish flow. Use when asked to release devbox, cut a version, ship 0.x.y, publish a release, or when a release is stuck partway through and needs diagnosing or resuming.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Changelog and release notes. The repository describes itself as: Instant, easy, and predictable development environments. The licence is Apache-2.0.

When your agent uses it

  • Asked to release devbox
  • Publish a release
  • A release is stuck partway through and needs diagnosing

Example prompts

  • “/release-devbox”

Requirements

  • Docker
  • A credential in GITHUB_TOKEN

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Look at what would ship
  2. Ask how they want to release
  3. Write the title and notes
  4. Run it

What it can do on your machine

Read from SKILL.md and the folder at commit 3317b4d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Release Devbox loads about 2.5k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 1,335 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jetify-com/devbox at commit 3317b4d, republished under its Apache-2.0 licence (© jetify-com). 1,335 words, ~2,539 tokens.

Download SKILL.mdSave it as .claude/skills/release-devbox/SKILL.md (or your agent's skills folder).
name
release-devbox
description
Cut a Devbox CLI release — recommend the version bump, write the release notes, and drive the draft or publish flow. Use when asked to release devbox, cut a version, ship 0.x.y, publish a release, or when a release is stuck partway through and needs diagnosing or resuming.

Release the Devbox CLI

scripts/release.ts owns every mechanical step and the order they run in. Your job is the judgment: read what's shipping, recommend a version, write the title and notes, and help the user pick how to release.

Two entry points, both of which walk the whole pipeline:

CommandWhat it does
devbox run draft-releaseBuilds the release, leaves it as a draft for review
devbox run publish-releaseBuilds and takes it live, or finishes an existing draft

Read-only helpers: devbox run release-changes and devbox run release-status.

1. Look at what would ship

bash
devbox run release-changes

This prints the commits since the last release grouped by kind (breaking / features / fixes / other), the recommended version, and whether flake.nix needs bumping. Read it before saying anything about the release.

The recommendation follows devbox's own history: it's pre-1.0, so breaking changes take a minor bump (0.17.5 → 0.18.0) and everything else takes a patch bump — 0.17.4 shipped new features as a patch. Say what the script recommends and why, but sanity-check it against the actual diff. A release that removes whole subsystems deserves a minor bump even if nobody wrote feat!:.

2. Ask how they want to release

Present the three options and let the user choose — don't assume:

  1. Draft first (devbox run draft-release) — builds everything and stops at a draft. Right when the notes need review, or when the release is being coordinated with an announcement. This is the safe default.
  2. Publish directly (devbox run publish-release) — same pipeline, then takes it live. Right for routine patch releases.
  3. Publish an existing draft (devbox run publish-release) — if a draft is already sitting there, the command lists it and offers to finish it. Check with devbox run release-status first.

3. Write the title and notes

The script prompts for these in $EDITOR when a human drives it. When you're driving, write them yourself and pass them as flags — that's the point of doing this through an agent.

Get the raw material from GitHub's generated changelog:

bash
gh api repos/jetify-com/devbox/releases/generate-notes \
  -f tag_name=<version> -f previous_tag_name=<prev> -f target_commitish=main --jq '.body'

That's a dump of PR titles. Rewrite it into user-facing notes in the house style that 0.17.4 established and 0.18.0 is the cleanest example of:

markdown
## What's Changed

### 💥 Breaking Changes

* **What was removed** — what users must do instead, by @author ([#1234](https://github.com/jetify-com/devbox/pull/1234))

### ✨ New Features

* **Short bold lead-in** — what changed and why a user cares, by @author ([#1234](...))

### 🐛 Bug Fixes

* Plain one-liners for small fixes, by @author ([#1234](...)).
* **Group related fixes** — combine several PRs into one bullet when they share
  a root cause ([#1234](...)) and ([#1235](...)), by @author.

### 🧹 Maintenance

* Dependency bumps, CI work, docs. Group aggressively; nobody reads this section
  line by line.

## New Contributors
* @newperson made their first contribution in https://github.com/jetify-com/devbox/pull/1234

**Full Changelog**: https://github.com/jetify-com/devbox/compare/<prev>...<version>

Rules that matter:

  • Lead with impact, not the commit subject. "Shells in paths with spaces now work" beats "quote the shellrc source guard".
  • Breaking changes go first and say what to do instead. For a release that removes features, this is the whole story — say plainly what's gone and what replaces it, or that nothing does.
  • Only include sections with content. Drop the ones that are empty.
  • Keep attribution. Every bullet ends with by @author and its PR link.
  • Use plain backticks for code. Do not escape them as \`. Nothing re-interprets the body — goreleaser's Discord announcer is enabled: false in .goreleaser.yaml — and Markdown renders \` as a literal backtick rather than opening a code span. That's why 0.17.4's published notes are full of stray backslashes. The script unescapes any that slip through, but don't write them.

For the title, default to the bare version (0.18.0). A short theme suffix is fine when the release has one: 0.18.0 — Devbox goes fully local.

Show the user the title and full notes and get explicit sign-off before running anything. That's the last checkpoint before it goes live.

4. Run it

Save the notes to .context/release-notes-<version>.md, then:

bash
node scripts/release.ts --draft \
  --version 0.18.0 \
  --title "0.18.0" \
  --notes-file .context/release-notes-0.18.0.md \
  --yes

Swap --draft for --publish to go live. Notes on driving it as an agent:

  • --yes is required when you run it. Its confirmation prompts need a TTY, and your shell doesn't have one — without --yes it stops with "this step needs an answer but stdin is not a terminal". Only pass it after the user has signed off; it's skipping their checkpoint, not adding one.
  • It blocks for ~15 minutes waiting on cli-release. Run it in the background and check back, rather than letting the call time out.
  • It's resumable. Every step is idempotent, so if it fails partway, fix the cause and re-run the same command — it picks up where it left off rather than duplicating work.
  • --skip-cli-tests exists but is a loaded gun. It only skips the check that the latest cli-tests run on main isn't red; cli-release still runs the whole suite and fails the build if it isn't green. A run that's merely queued or in progress (the normal state right after the flake bump merges) doesn't block — only a finished, failed run does. Use the flag when that check is wrong (a flake you've confirmed), not to push past a genuinely red main.

If flake.nix needs bumping, the script offers to do the whole thing: it rewrites lastTag, refreshes vendor-hash and flake.lock, commits to bump-flake-<version>, pushes, opens the PR, and puts you back on main with a clean tree. Then it stops (exit 0 — this is a planned pause, not a failure) and prints the exact command to continue with, e.g. devbox run publish-release --version 0.18.2. That bump has to be reviewed and merged before the tag is pushed, otherwise the tagged commit ships the wrong version string. Get it merged and run the printed command; --version skips the version prompt and preflight pulls the new main and carries on. A re-run while the PR is still open stops immediately with its URL rather than opening a second one.

Preflight is picky about the checkout on purpose, since the tag lands on whatever HEAD is. A main that's merely behind origin/main and clean fast-forwards itself; anything else (wrong branch, dirty tree, local-only commits) stops with the command that fixes it.

Show full SKILL.md (423 more words)Show less

Why the order is what it is

Don't work around these; they're why the script exists.

  • Draft before tag. goreleaser runs with release.disable and only builds dist/; cli-release uploads that to the release for the tag, looking it up by tag with gh. With no draft it creates one from GitHub's generated notes — usable, but not the notes you wrote. (goreleaser used to do the upload itself, but it matched drafts by title, so any release with a real title got a silent duplicate draft with bare-commit-SHA notes. That's what shipped as the 0.17.5 release notes, and what stalled 0.18.0.)
  • Publish after the build. docker-image-release fires on the release event and immediately downloads the release tarballs to bake into the image. Publishing before cli-release uploads them fails the Docker build. That's exactly what happened on 0.17.3 and 0.17.5, both published from the GitHub UI, which creates the tag and publishes in one action.
  • Flake bump before the cli-tests check. The bump has to merge into main, which re-runs cli-tests there — so a result read before the bump is about a commit that won't be released. Settling the bump first also means a red main doesn't hide the fact that a bump PR is needed.
  • Publish from local credentials, not CI. GitHub doesn't trigger workflows from events raised by GITHUB_TOKEN. That's why CI-created edge releases never trigger docker-image-release, and why publishing can't just be a CI step.

If something is stuck

devbox run release-status reports the tag, draft, asset count, cli-release result and the current flake.nix version in one shot.

SymptomCauseFix
cli-release never startedTag push didn't landRe-run the same command
cli-release failed in testsRed main (see below)Fix the test, re-run
Draft has 0 assetsThe upload step didn't run or failedCheck cli-release's "Attach artifacts" step, re-run
Published but installer serves the old versioncli-post-release failed or is still runninggh run list --workflow=cli-post-release.yml
Docker build failedPublished before assets uploadedRe-run docker-image-release via workflow_dispatch with the tag

Known breakage

Check these are still true before blaming the release itself:

  • main was red from 2026-07-02 until #2951. The macOS zig-hello-world example test failed because build.zig used the pre-Zig-0.12 API while devbox.lock pinned zig 0.11.0; the upgrade to zig 0.16 fixed it. A red main blocks all releases — cli-release gates on the test suite — so check the current state rather than assuming either way.
  • flake.nix drifts. It sat at 0.17.3 through both the 0.17.4 and 0.17.5 releases. The script catches this now and opens the bump PR for you.

© jetify-com, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/release-devbox of jetify-com/devbox.

Open the folder on GitHubat commit 3317b4d

Compare with similar skills

Release Devbox next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Release Devbox compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Release Devbox this skilljetify-com/devbox12k—~2.5kAutomated safety check: PassApache-2.0
Simple Englishmoeru-ai/airi50k2 repos~4.6kAutomated safety check: PassMIT
StarRocks Release NotesStarRocks/starrocks12k—~1.9kAutomated safety check: NotesApache-2.0
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0
React Router Release Notes Prepremix-run/react-router57k—~1.1kAutomated safety check: PassMIT
Mole CLI Release Flowtw93/Mole69k—~2.5kAutomated safety check: PassGPL-3.0

Similar skills

  • Simple English

    moeru-ai/airi

    Write or rewrite technical text with the rules of ASD-STE100 Simplified Technical English so it is clear, unambiguous, and free of AI slop.

    50k GitHub starsUsed in 2 repos~4.6k tokens
    DevelopmentAuto-check passed
  • StarRocks Release Notes

    StarRocks/starrocks

    Drafts English release notes for a StarRocks patch release from the PRs merged into its release branch, then opens a documentation PR and hands translation to /translate.

    12k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check: notes
  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • React Router Release Notes Prep

    remix-run/react-router

    Polishes pending React Router change files before the versioning scripts run, and decides whether a long-form What's Changed section is warranted.

    57k GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Runbook for assessing and executing a Mole CLI release: distribution channels, pre-flight checks, capital-V tags, build artifacts and the handoff to curated release notes.

    69k GitHub stars~2.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Release

    PrefectHQ/fastmcp

    Cut a FastMCP release end to end. An agent skill from PrefectHQ/fastmcp.

    28k GitHub stars~2.9k tokensUpdated yesterday
    DevelopmentAuto-check passed

Categories

Questions about Release Devbox

What does Release Devbox do?

Cut a Devbox CLI release — recommend the version bump, write the release notes, and drive the draft or publish flow. Release Devbox is an agent skill from jetify-com/devbox. Cut a Devbox CLI release — recommend the version bump, write the release notes, and drive the draft or publish flow.

When should I use Release Devbox?

Release Devbox fits situations like: asked to release devbox; publish a release; A release is stuck partway through and needs diagnosing.

How do I install Release Devbox in Claude Code?

Run `npx skills add jetify-com/devbox --skill release-devbox -a claude-code`. Or copy the skill folder (.agents/skills/release-devbox in jetify-com/devbox) into .claude/skills/release-devbox in your project. Claude Code loads it when a task matches its description.

How do I install Release Devbox in Codex?

Run `npx skills add jetify-com/devbox --skill release-devbox -a codex`. Or copy the skill folder (.agents/skills/release-devbox in jetify-com/devbox) into .agents/skills/release-devbox in your project. Codex loads it when a task matches its description.

Can I use Release Devbox in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jetify-com/devbox --skill release-devbox -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release-devbox, .gemini/skills/release-devbox, .github/skills/release-devbox and .opencode/skills/release-devbox in your project.

What does Release Devbox need to run?

Going by SKILL.md and its folder, Release Devbox needs the command-line tools its instructions call (gh and node) and credentials named GITHUB_TOKEN. Our summary lists: Docker; A credential in GITHUB_TOKEN.

Does Release Devbox access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Release Devbox safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Release Devbox use?

Release Devbox is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Release Devbox use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Release Devbox?

Skills that share tags, products or a category with Release Devbox: Simple English (moeru-ai/airi, 50k stars), StarRocks Release Notes (StarRocks/starrocks, 12k stars), Cutting A Release (TriliumNext/Trilium, 38k stars) and React Router Release Notes Prep (remix-run/react-router, 57k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Release Devbox?

jetify-com (a GitHub organization) maintains it in jetify-com/devbox, which has 12,394 GitHub stars. The repository was last updated on October 6, 2026.

Source: jetify-com/devbox on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.