Create Release Checklist
software-mansion/smelter
Generate a GitHub release-checklist issue for a full (non-RC) release of the Smelter server and/or the TypeScript SDK.
Prepares and ships truST changes - changelog and version updates, CI parity, pre-push checks, the exact-SHA release-candidate guard, merge, tag and release verification.
$ npx skills add johannesPettersson80/trust-platform --skill trust-ci-release-gates -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install johannesPettersson80/trust-platform trust-ci-release-gates --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/johannesPettersson80/trust-platform.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/trust-ci-release-gates .claude/skills/trust-ci-release-gates && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "trust-ci-release-gates" agent skill from https://github.com/johannesPettersson80/trust-platform/tree/main/.codex/skills/trust-ci-release-gates into .claude/skills/trust-ci-release-gates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trust-ci-release-gates", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/johannesPettersson80/trust-platform/tree/main/.codex/skills/trust-ci-release-gatesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add johannesPettersson80/trust-platform --skill trust-ci-release-gates -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install johannesPettersson80/trust-platform trust-ci-release-gates --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/johannesPettersson80/trust-platform.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/trust-ci-release-gates .agents/skills/trust-ci-release-gates && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "trust-ci-release-gates" agent skill from https://github.com/johannesPettersson80/trust-platform/tree/main/.codex/skills/trust-ci-release-gates into .agents/skills/trust-ci-release-gates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trust-ci-release-gates", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add johannesPettersson80/trust-platform --skill trust-ci-release-gates -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install johannesPettersson80/trust-platform trust-ci-release-gates --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/johannesPettersson80/trust-platform.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/trust-ci-release-gates .cursor/skills/trust-ci-release-gates && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "trust-ci-release-gates" agent skill from https://github.com/johannesPettersson80/trust-platform/tree/main/.codex/skills/trust-ci-release-gates into .cursor/skills/trust-ci-release-gates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trust-ci-release-gates", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/johannesPettersson80/trust-platform.git --path .codex/skills/trust-ci-release-gates--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add johannesPettersson80/trust-platform --skill trust-ci-release-gates -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install johannesPettersson80/trust-platform trust-ci-release-gates --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/johannesPettersson80/trust-platform.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/trust-ci-release-gates .gemini/skills/trust-ci-release-gates && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "trust-ci-release-gates" agent skill from https://github.com/johannesPettersson80/trust-platform/tree/main/.codex/skills/trust-ci-release-gates into .gemini/skills/trust-ci-release-gates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trust-ci-release-gates", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install johannesPettersson80/trust-platform trust-ci-release-gatesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add johannesPettersson80/trust-platform --skill trust-ci-release-gates -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/johannesPettersson80/trust-platform.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/trust-ci-release-gates .github/skills/trust-ci-release-gates && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "trust-ci-release-gates" agent skill from https://github.com/johannesPettersson80/trust-platform/tree/main/.codex/skills/trust-ci-release-gates into .github/skills/trust-ci-release-gates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trust-ci-release-gates", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add johannesPettersson80/trust-platform --skill trust-ci-release-gates -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install johannesPettersson80/trust-platform trust-ci-release-gates --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/johannesPettersson80/trust-platform.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/trust-ci-release-gates .opencode/skills/trust-ci-release-gates && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "trust-ci-release-gates" agent skill from https://github.com/johannesPettersson80/trust-platform/tree/main/.codex/skills/trust-ci-release-gates into .opencode/skills/trust-ci-release-gates/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trust-ci-release-gates", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
trust-ci-release-gatesPrepares and ships truST changes - changelog and version updates, CI parity, pre-push checks, the exact-SHA release-candidate guard, merge, tag and release verification.
Trust CI Release Gates is an agent skill from johannesPettersson80/trust-platform. Prepares and ships truST changes - changelog and version updates, CI parity, pre-push checks, the exact-SHA release-candidate guard, merge, tag and release verification. Use for commit or push preparation, version bumps, CI workflow or gate-script changes, release candidates, merges, tags, GitHub releases and VS Code Marketplace checks.
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts (for example `scripts/compiler_passthrough.sh`, `scripts/release_candidate_cleanup.py` and `scripts/release_candidate_cleanup_tests.py`).
It sits in Development, covering Changelog and release notes. It works with Visual Studio Code, GitHub, Rust and TypeScript. The repository describes itself as: truST Platform — IEC 61131‑3 Structured Text tooling suite. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b7d8ffb. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 8 files in scripts/ (Python and Shell), which the agent can run.
Shell commands in SKILL.md call:
justgitnpmcargopython3bashghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, npm and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Trust CI Release Gates loads about 3.6k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 1,806 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from johannesPettersson80/trust-platform at commit b7d8ffb, republished under its Apache-2.0 licence (© johannesPettersson80). 1,806 words, ~3,628 tokens.
.claude/skills/trust-ci-release-gates/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.Hard rule (AGENTS.md): all logic is in Rust. Logic is anything whose result is stored, sent to a runtime or PLC, or decides an engineering or operator outcome. TypeScript only presents (drawing, layout, mouse interaction, view state) and forwards requests to Rust. Never add logic in TypeScript. Existing TypeScript logic is debt to move into Rust, not to extend.
Before a push, read the diff for this: a change that adds or grows logic in TypeScript does not ship.
CHANGELOG.md under ## [Unreleased], in
### Added, ### Changed or ### Fixed. User-visible means runtime behaviour, CLI flags and
output, the standard library, tutorials and docs, and test harness behaviour. Purely internal
changes need no entry.[workspace.package].version in Cargo.toml, unless
the user says not to.editors/vscode/package.json and the root version entries of editors/vscode/package-lock.json
to the same version.Before implementation is frozen, read the current workflows and guard scripts. In the existing task record, map each required job to its command, toolchain, targets/features, evidence and prerequisites. Distinguish the pinned/MSRV compiler from floating CI stable; record the actual versions used. Keep native Windows/macOS proof separate from Linux cross-compilation. Review new tests and their imports, feature gates and registrations as part of the full diff before spending the batch. For a related candidate, read the preceding failure ledger and its corrected commands, including compiler environment, temporary-path and platform prerequisites; carry those corrections into the new command map before freezing.
Choose the release path before scheduling commands. Once implementation is complete, perform the
single final formatting and required generated-file preparation on the builder with the guard's exact
toolchain and configuration, including touched include! fragments. This is the preparation phase of the
planned batch, not a per-edit check or another full test run. Copy back and review its complete diff
before the authorized commit. The exact-SHA guard then validates that clean committed source;
its formatting step must leave the tree unchanged. Never restore formatter output during a running
guard to make the final cleanliness check pass.
If an exact-SHA guard is required, commit only when authorized, then use prepare for the checks it
already runs. Do not run just test-all once
before the commit and again inside prepare merely to satisfy two descriptions of the same gate.
Required scope batches remain distinct when explicitly authorized; their evidence cannot substitute
for the exact-SHA artifact. A commit, rebase or source change requires evidence for the new candidate.
.github/workflows/ and the guard. A host
just clippy or just test-all is not cross-platform parity.prepare once; add only required checks it does not cover:
just fmt, just clippy, just test-all, and applicable area checks below:trust-lsp tests or dependency/config resolution: ./scripts/prepush_ci_gate.sh. It
includes the test-path hygiene check and the Windows GNU check of trust-lsp's tests.RUSTFLAGS=-Dwarnings cargo check -p trust-runtime --all-targets and
./scripts/runtime_mesh_tls_stability_gate.sh --iterations 8.crates/trust-runtime/tests/ci_cicd_contract.rs or
tests/fixtures/ci/**):
cargo test -p trust-runtime --test ci_cicd_contract --test config_schema_command --test registry_command.trust-runtime change:
./scripts/check_runtime_cross_target_warnings.sh --install-missing --require-cross.editors/vscode/**, scripts/captures/**, capture assets or the
capture workflow): python3 -m unittest scripts.tests.test_capture_lifecycle -v. The VS Code
npm test does not replace it.npm run lint && npm run compile && npm test in editors/vscode.xtask/config/full_map_policy.json:
cargo run -p xtask -- architecture-doctor --full-map.git remote get-url origin, git remote get-url --push origin and
gh auth status --hostname github.com. Never print credentials.workflow scope cannot push .github/workflows/**. In that
case, set the SSH push URL:
git config remote.origin.pushurl git@github.com:johannesPettersson80/trust-platform.git.git ls-remote --exit-code "$(git remote get-url --push origin)" HEAD.These pushes go through the guard in this skill's scripts/:
main pushes;origin/main.Prepare. Freeze one clean candidate and prepare its exact-SHA artifact in a clean builder worktree:
python3 .codex/skills/trust-ci-release-gates/scripts/release_candidate_guard.py \
prepare --remote-worktree '<clean exact-SHA trust-builder worktree>'AGENTS.md and .codex/skills/ with the primary checkout;bash scripts/supply_chain_gate.sh and bash scripts/architecture_safety_gate.sh;just test-all on the builder;Push once. The shared pre-push hook (scripts/pre-push, which git config core.hooksPath
points at) rejects a release-sensitive push that has no passing artifact for the exact head and
base. Never bypass it.
Wait for every required check. If any check fails, collect the whole failure set and every
failed job log before editing:
release_candidate_guard.py collect-failures --pr <number> --wait.
*-retry-rescued.txt artifacts even
when GitHub marks the job green. A passing automatic retry does not close
the first failure: retain it, identify its cause and obtain the applicable
correction/validation authorization before merge.Merge only with release_candidate_guard.py check-merge --pr <number> --execute.
Release a version change.
v<version> from the same main SHA.release_candidate_guard.py verify-release --candidate-head <reviewed-head> --branch <candidate-branch>.
It checks:Clean up. verify-release then runs audit-post-merge.
clean.After a second failed candidate, or two hours without merge readiness, report the complete blocker list, elapsed time and next action. Continue only within the current scope and retry authorization; this report is not a new permission gate when the user already authorized continued corrections.
Use precise readiness claims:
check-merge allows it.verify-release confirms the tag, workflow, assets and Marketplace requirements.A passing earlier scope or old-head CI cannot establish a later state. Report the active stage, actual elapsed time and remaining stages; do not describe unpushed corrections as GitHub results.
In PR text, Closes, Fixes and Resolves close an issue on merge; Addresses does not. Check
that the intended issues are closed after the merge.
Shared scripts: local runs and CI call the same scripts: scripts/prepush_ci_gate.sh,
scripts/supply_chain_gate.sh and scripts/architecture_safety_gate.sh. Do not copy their
commands into workflows.
New gates: a new gate also updates scripts/generate_release_gate_report.py.
Version guard: keep the version-release-guard job in .github/workflows/ci.yml and
scripts/check_version_release_evidence.py in line with the release workflow's triggers. Give it a
time budget above the slowest cold release path.
Docs Captures:
main;Target storage: use a strict descendant of ~/.cache/codex-targets/, /tmp/, or
/mnt/HC_Volume_107089260/builder-storage/cargo-targets/. The shared path policy
requires the volume mount, canonical paths and current-user ownership; leases
and idle-only removal apply unchanged. Keep the 80 GiB floor on the target's
actual filesystem. Do not substitute a symlink to bypass target-root policy.
Exact-candidate disk bounds:
CARGO_INCREMENTAL=0;RUSTC_WRAPPER and CARGO_BUILD_RUSTC_WRAPPER set to /usr/bin/env;scripts/compiler_passthrough.sh installed on PATH as sccache;CC=cc and CXX=c++ for native builds only;env -u CC -u CXX so native overrides cannot
select a host compiler for the target; reuse the guard's separate native and
cross-target environments in supplemental commands;just test-all; do not force one job;TMPDIR inside the task's own target.Between Clippy and just test-all, recheck available space on the validated
target filesystem. Preserve the warm target when the existing 80 GiB floor is
met. Otherwise reclaim only that target through
scripts/remove_cargo_target_if_idle.sh, prepare its directories again and
recheck the same floor. A busy target, unreadable space measurement or still
insufficient space fails the stage; never delete an active target or lower the floor.
Script style: gate scripts fail fast and pass shellcheck (set -euo pipefail). With set -u,
do not expand arrays that may be empty.
Regression tests for gate tooling: name the focused test so that
scripts/check_regression_test_first.py finds it (test_*.py, tests.py, or a test or tests
directory). When it proves an existing failing command, add a Regression-test-first: line to the
commit or PR.
Verification report: pull requests and candidates run
scripts/verification_report_gate.py --strict --smoke. The exhaustive verification tooling runs
only in the scheduled workflow.
Missing tools: after fixing a missing tool in one workflow, search .github/workflows/ for the
same tool, because ci.yml and release.yml drift apart.
VS Code CI: keep xvfb in the VS Code CI job.
unix:// endpoint in a shared fixture; use tcp://127.0.0.1:0;to_string_lossy() paths into TOML fixtures, because Windows backslashes break
them;ci_cicd_contract with -- --test-threads=1.set_nonblocking(false) on every stream accepted from a nonblocking listener.
Windows inherits the flag; Linux does not.© johannesPettersson80, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 8 other files (scripts) in .codex/skills/trust-ci-release-gates of johannesPettersson80/trust-platform.
Open the folder on GitHubat commit b7d8ffb
Trust CI Release Gates next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Trust CI Release Gates this skilljohannesPettersson80/trust-platform | 222 | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Create Release Checklistsoftware-mansion/smelter | 734 | — | ~1.9k | Automated safety check: Notes | Custom licence | |
| Release Roundethereumjs/ethereumjs-monorepo | 2.8k | — | ~2k | Automated safety check: Pass | None | |
| Worktrunk Release Workflowmax-sixty/worktrunk | 9.2k | — | ~7.5k | Automated safety check: Pass | Custom licence | |
| Release Roslynatordotnet/roslynator | 3.5k | — | ~1k | Automated safety check: Pass | Custom licence | |
| Release VersionGOODBOY008/r-shell | 153 | — | ~4k | Automated safety check: Pass | MIT |
software-mansion/smelter
Generate a GitHub release-checklist issue for a full (non-RC) release of the Smelter server and/or the TypeScript SDK.
ethereumjs/ethereumjs-monorepo
Runs a coordinated EthereumJS npm release round in six human-gated phases — intent and readiness, CHANGELOG, version bump, publish (human executes), post-publish verification, and announcements.
max-sixty/worktrunk
Walks a maintainer through cutting a Worktrunk release: sync the release branch, pass two test gates, review the changes, then publish.
dotnet/roslynator
A skill your agent uses when shipping a roslynator release, rolling CHANGELOG.md [Unreleased], updating the VS Code extension changelog, creating a GitHub v release, or optionally tagging cli-v.
GOODBOY008/r-shell
Release a new r-shell version and create a published GitHub release with contributor credits.
web-infra-dev/rslint
Prepare a stable release PR for the unified rslint npm packages by updating package versions and rule/TypeScript release metadata.
johannesPettersson80/trust-platform
Runs truST builds and tests on the shared trust-builder machine.
johannesPettersson80/trust-platform
Routes truST behaviour changes from the written specification to a native executable test.
johannesPettersson80/trust-platform
Keeps truST's architecture simple and well separated, and runs the automated architecture checks.
johannesPettersson80/trust-platform
Guides work on truST's HMI - the HMI Builder editor, page files, the runtime display at /hmi, bindings, commands and writes, authorization, alarms and trends, the plant library and the HMI tests.
johannesPettersson80/trust-platform
Guides IEC 61131-3 Structured Text language work in truST - lexer, parser, types, semantics, standard functions and function blocks, OOP, namespaces and editor features - checked against the standard.
johannesPettersson80/trust-platform
Builds and verifies truST's VS Code extension - commands, webviews, snippets, debug flows, Control Studio, HMI Builder, Devices & Connections and the test harness.
Works with
Categories
Prepares and ships truST changes - changelog and version updates, CI parity, pre-push checks, the exact-SHA release-candidate guard, merge, tag and release verification. Trust CI Release Gates is an agent skill from johannesPettersson80/trust-platform. Prepares and ships truST changes - changelog and version updates, CI parity, pre-push checks, the exact-SHA release-candidate guard, merge, tag and release verification.
Trust CI Release Gates fits situations like: push preparation; gate-script changes; release candidates; GitHub releases and VS Code Marketplace checks.
Run `npx skills add johannesPettersson80/trust-platform --skill trust-ci-release-gates -a claude-code`. Or copy the skill folder (.codex/skills/trust-ci-release-gates in johannesPettersson80/trust-platform) into .claude/skills/trust-ci-release-gates in your project. Claude Code loads it when a task matches its description.
Run `npx skills add johannesPettersson80/trust-platform --skill trust-ci-release-gates -a codex`. Or copy the skill folder (.codex/skills/trust-ci-release-gates in johannesPettersson80/trust-platform) into .agents/skills/trust-ci-release-gates in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add johannesPettersson80/trust-platform --skill trust-ci-release-gates -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/trust-ci-release-gates, .gemini/skills/trust-ci-release-gates, .github/skills/trust-ci-release-gates and .opencode/skills/trust-ci-release-gates in your project.
Going by SKILL.md and its folder, Trust CI Release Gates needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (just, git, npm, cargo, python3 and bash). Our summary lists: Python 3; A Bash shell.
SKILL.md contains no URLs. Its commands use git, npm and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Trust CI Release Gates is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Trust CI Release Gates: Create Release Checklist (software-mansion/smelter, 734 stars), Release Round (ethereumjs/ethereumjs-monorepo, 2.8k stars), Worktrunk Release Workflow (max-sixty/worktrunk, 9.2k stars) and Release Roslynator (dotnet/roslynator, 3.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
johannesPettersson80 (a GitHub user) maintains it in johannesPettersson80/trust-platform, which has 222 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 11, 2026.
Source: johannesPettersson80/trust-platform on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.