Dev Release
alecs5am/ralphy
Cut a Ralphy CLI release across GitHub Releases, Homebrew, and npm.
Kandev release and version-channel conventions — unified Stable SemVer plus deterministic npm-only Nightlies.
$ npx skills add kdlbs/kandev --skill release -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kdlbs/kandev release --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kdlbs/kandev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/release .claude/skills/release && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "release" agent skill from https://github.com/kdlbs/kandev/tree/main/.agents/skills/release into .claude/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kdlbs/kandev/tree/main/.agents/skills/releaseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kdlbs/kandev --skill release -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kdlbs/kandev release --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kdlbs/kandev.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/release .agents/skills/release && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "release" agent skill from https://github.com/kdlbs/kandev/tree/main/.agents/skills/release into .agents/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kdlbs/kandev --skill release -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kdlbs/kandev release --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kdlbs/kandev.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/release .cursor/skills/release && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "release" agent skill from https://github.com/kdlbs/kandev/tree/main/.agents/skills/release into .cursor/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kdlbs/kandev.git --path .agents/skills/release--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kdlbs/kandev --skill release -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kdlbs/kandev release --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kdlbs/kandev.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/release .gemini/skills/release && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "release" agent skill from https://github.com/kdlbs/kandev/tree/main/.agents/skills/release into .gemini/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kdlbs/kandev releaseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kdlbs/kandev --skill release -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kdlbs/kandev.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/release .github/skills/release && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "release" agent skill from https://github.com/kdlbs/kandev/tree/main/.agents/skills/release into .github/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kdlbs/kandev --skill release -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kdlbs/kandev release --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kdlbs/kandev.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/release .opencode/skills/release && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "release" agent skill from https://github.com/kdlbs/kandev/tree/main/.agents/skills/release into .opencode/skills/release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "release", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
releaseKandev release and version-channel conventions — unified Stable SemVer plus deterministic npm-only Nightlies.
Release is an agent skill from kdlbs/kandev. Kandev release and version-channel conventions — unified Stable SemVer plus deterministic npm-only Nightlies. Use when cutting a release, changing channels, debugging artifacts, or answering version-channel questions.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. It works with npm, Homebrew and GitHub. The repository describes itself as: AI Kanban & Development Environment. Orchestrate multiple agents, review changes, open PRs. Multi-provider, self-hostable, no telemetry. The licence is AGPL-3.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b734113. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bashnodepython3makeghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENRELEASE_PR_BYPASS_TOKENRELEASE_GPG_PRIVATE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Release loads about 2.6k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 1,281 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kdlbs/kandev at commit b734113, republished under its AGPL-3.0 licence (© kdlbs). 1,281 words, ~2,617 tokens.
.claude/skills/release/SKILL.md (or your agent's skills folder).Kandev Stable releases use a single SemVer X.Y.Z shared across all distribution channels.
npm also has an explicit prerelease-only nightly channel; it is not part of the unified Stable
artifact set.
apps/cli/package.json version → X.Y.Zkandev@X.Y.Z@kdlbs/runtime-{platform}@X.Y.Z (5 platforms; declared as optionalDependencies in main package)vX.Y.Z (three-part; legacy vM.m tags normalize to M.m.0)kdlbs/homebrew-kandev Formula/kandev.rb version "X.Y.Z"kdlbs/scoop-kandev bucket/kandev.json version, URL, and hashvX.Y.Z with standard platform archives kandev-{platform}.tar.gz, full offline archives kandev-{platform}-full.tar.gz, checksums, Windows ZIP equivalents, remote helper assets, and runtime-size-report.mdStable default archive names contain the standard runtime: host kandev, host agentctl, and
remote-helpers.json. The -full archives also contain all four remote helper executables. Stable
npm packages, Homebrew, Scoop, winget, Chocolatey, and Desktop use standard archives. Containers
and npm Nightlies stay full. Desktop keeps one standard installer and updater track.
npm, Homebrew, and Scoop are sibling channels, not chained. All three consume the same GitHub release artifacts; none depends on another package-manager channel.
For npm Nightly, Stable X.Y.Z plus a full main SHA produces
X.Y.(Z+1)-nightly.sha<first-12-lowercase-hex>. kandev and all five runtime packages publish at
that exact version under npm's nightly dist-tag. Nightly never moves latest and creates no Git
tag, GitHub Release, Homebrew formula, Scoop bucket update, Desktop feed/build, or container tag.
Stable runs entirely in CI via .github/workflows/release.yml, triggered by a maintainer from the GitHub Actions UI:
channel=stable → picks bump (patch/minor/major) → optional dry_run or desktop_validation_only.prepare job bumps version + regenerates CHANGELOG, opens release PR, squash-merges, tags vX.Y.Z.build-web, build-bundles, build-remote-helpers, build-desktop, and both Docker builds create the channel inputs.publish-release promotes staged standard archives to the existing default names, publishes full archives and helper assets, then attaches checksums, the size report, desktop artifacts, and notes.publish-npm publishes 5 @kdlbs/runtime-* packages + main kandev package to npmjs.update-homebrew-tap pushes updated Formula/kandev.rb to kdlbs/homebrew-kandev via SSH deploy key.update-scoop-bucket pushes updated bucket/kandev.json to kdlbs/scoop-kandev via its SSH deploy key.The Release workflow has a notify_contributors checkbox. It defaults to false. When selected, the workflow calls the reusable notification workflow after GitHub Release, npm, Homebrew, and Scoop publication all succeed. Dry runs, desktop validation, Nightly, cancellation before the notification job starts, and publication errors skip the call. Cancellation after posting starts can leave partial notices; rerun with the exact tag to complete safely.
For manual notices or recovery, run Notify release contributors from the main ref. Leave release_tag empty to select the latest published Stable release. Enter an exact tag to select another release. The dry_run checkbox previews the same PR selection and comment text without posting.
The helper reads PR links from the release notes. It posts only to merged PRs from this repository that belong to the selected release tag. It excludes bots and maintainers from cliff.toml. The job token posts as github-actions[bot]. Only notices from that bot or a listed maintainer count as already sent.
Each comment includes a hidden release ID marker. Repeat runs skip comments with that marker and the exact unmarked notice used for v0.97.0. After a partial run, use the separate workflow with the exact tag. It skips confirmed notices and retries only missing notices. Wait for GitHub rate limits to clear before retrying.
A normal Stable release creates its branch and pull request with GITHUB_TOKEN.
It uses RELEASE_PR_BYPASS_TOKEN only for an exact-head gh pr merge --admin.
Store this fine-grained personal access token in the protected release
environment. Its owner must remain an organization administrator. Select only
kdlbs/kandev and grant contents: write repository permission.
Record the token owner and expiration date. Rotate the environment secret before the token expires or the owner loses administrator access. The workflow must stop before tag creation when the token is missing or cannot bypass the ruleset.
After the merge, use GITHUB_TOKEN to read the PR state. Tag only the merge
commit that GitHub reports after it appears on origin/main.
Workflow-control invariant: When a channel intentionally skips a job, every
downstream job reachable through that dependency chain must use a status function
such as !cancelled() plus explicit needs.<job>.result == 'success' checks.
For a partial Stable release, preserve the existing signed tag and rerun with
backfill_tag; never run a normal bump against an existing tag. Declare Stable
complete only after publish-release, publish-npm, update-homebrew-tap, and
update-scoop-bucket each succeed and their artifacts are verified—an aggregate
green run can hide skipped publication jobs.
Required web, runtime, and desktop artifact uploads attempt up to three times,
with waits of 30 seconds and 60 seconds between attempts. They fail explicitly
when an expected file is missing. Desktop matrix targets use fail-fast: false
so a transient upload failure does not cancel sibling targets, but publication
still requires the complete matrix to succeed. Rerun a failed producer job in
the same workflow run after a transient failure. If the signed tag already
exists and the run remains partial, use backfill_tag for that tag after
checking which channels already succeeded.
Stable has no local release driver; the entire Stable flow runs in GHA. The Nightly metadata and
publication revalidation state machine lives in scripts/release/nightly-release.sh, which GHA
invokes for scheduled and manual Nightly runs.
The same workflow schedules npm Nightly with cron 0 12 * * *. It skips before building when
main has no commit after the latest Stable tag, the exact commit is already published, or a same
or newer main Nightly supersedes the scheduled commit. Eligible runs build only the shared web
bundle and five native runtime archives, then publish runtimes first and kandev last with OIDC
provenance. Stable and Nightly workflow runs share one non-cancelling release-wide concurrency
slot. Before publishing, Nightly rechecks the stable Git/npm baseline and the previously observed
nightly tag; a pending Stable tag or moved value safely suppresses stale publication.
Maintainers may run that same Nightly path from the Actions UI with the main ref and
channel=nightly. dry_run=true retains the real metadata and registry preflight but skips shared
builds and all npm writes. The shared form's required bump value is ignored for Nightly;
desktop_validation_only and backfill_tag are Stable-only and rejected when combined with it.
Validate Nightly automation changes with:
node --test scripts/release/nightly-version.test.mjs scripts/release/nightly-release.test.mjs
python3 .github/scripts/release-workflow-contract_test.py
bash -n scripts/release/nightly-release.sh scripts/release/publish-npm.shThe release workflow reads signing configuration from the GitHub release
environment. RELEASE_GPG_PRIVATE_KEY and the optional
RELEASE_GPG_PASSPHRASE are environment secrets. The full 40-character
RELEASE_GPG_FINGERPRINT is an environment variable, not a secret: the
workflow reads vars.RELEASE_GPG_FINGERPRINT, so storing it as a secret makes
normal-release preflight treat it as missing.
.github/release-signing-key.asc must contain exactly one public primary key
whose fingerprint matches that variable; never commit private key material.
backfill_tag repairs publication for an already-signed existing tag only and
does not bypass the normal-release signing checks.
Desktop signing is automatic. Complete macOS/Windows signing and notarization secrets produce signed artifacts; missing or incomplete signing inputs produce unsigned desktop artifacts and the GitHub release notes get an unsigned-artifact warning. desktop_validation_only=true builds artifacts from the current workflow ref for maintainer inspection and skips the release PR, tag, GitHub release, npm publish, Homebrew update, Scoop update, and public container tags.
The published npm shim (apps/cli/bin/native-shim.js) locates its bundled runtime via:
KANDEV_BUNDLE_DIR env var (set by Homebrew wrapper, used by tests).@kdlbs/runtime-{platform} npm package via require.resolve().bin/kandev directly. (--runtime-version is rejected by the native launcher.)When adding, renaming, or removing bundled helper binaries such as agentctl-<goos>-<goarch>, update every packaging surface in the same PR:
.github/workflows/release.yml bundle, macOS signing, and notarization loopsscripts/release/prepare-desktop-runtime.shscripts/release/verify-desktop-runtime.shscripts/release/remote-helper-assets.mjsapps/backend/internal/agent/runtime/lifecycle/remote_helper_manifest.go and the cache resolverscripts/release-desktop.test.shapps/desktop/AGENTS.md runtime resource listVerify with the helper build plus release-runtime tests, for example:
make -C apps/backend build-agentctl-remote
bash scripts/release-desktop.test.sh© kdlbs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/release of kdlbs/kandev.
Open the folder on GitHubat commit b734113
Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Release this skillkdlbs/kandev | 909 | — | ~2.6k | Automated safety check: Pass | AGPL-3.0 | |
| Dev Releasealecs5am/ralphy | 136 | — | ~757 | Automated safety check: Pass | Apache-2.0 | |
| ClickUp CLI Release Processkrodak/clickup-cli | 121 | — | ~906 | Automated safety check: Warn | MIT | |
| Kanvibe Release Deployrookedsysc/kanvibe | 143 | — | ~12k | Automated safety check: Notes | AGPL-3.0 | |
| Release Flowromankurnovskii/BrewMate | 301 | — | ~976 | Automated safety check: Pass | MIT | |
| Deploykangraemin/claude-inspector | 131 | — | ~739 | Automated safety check: Notes | MIT |
alecs5am/ralphy
Cut a Ralphy CLI release across GitHub Releases, Homebrew, and npm.
krodak/clickup-cli
Walks through releasing a new version of clickup-cli: pre-release checks, version bump, tagging, CI watch, release notes and the Homebrew update.
rookedsysc/kanvibe
A skill your agent uses whenever releasing or deploying KanVibe desktop from a clean, up-to-date dev checkout: ask only for the target version and release-note approval, then let the AI update…
romankurnovskii/BrewMate
Automate the full application release flow for BrewMate, including committing local changes, bumping version, waiting for GitHub Actions release build, and pushing the in-repo cask update…
kangraemin/claude-inspector
Claude Inspector macOS 배포 스킬. An agent skill from kangraemin/claude-inspector.
swimmwatch/cloakbrowser-mcp
Create, update, prepare, or review a cloakbrowser-mcp GitHub Pull Request only when the user explicitly requests PR work.
kdlbs/kandev
Generate a single-file HTML walkthrough that explains a PR's purpose, user impact, interface changes, compatibility risks, and implementation.
kdlbs/kandev
Diagnose Kandev bugs, running-instance issues, UI/browser failures, and runtime behavior.
kdlbs/kandev
Improve Kandev's AI harness from session learnings or explicit requests.
kdlbs/kandev
Create branded architecture, IT current-state, flowchart, sequence, state machine, ER/data model, timeline, swimlane, quadrant, radar/spider, polar chart (polar/radial lollipop), loop/flywheel…
kdlbs/kandev
Implement changes using Test-Driven Development (Red-Green-Refactor).
kdlbs/kandev
Run a broad local verification audit only when the user explicitly requests it or PR/CI remediation requires it.
Categories
Kandev release and version-channel conventions — unified Stable SemVer plus deterministic npm-only Nightlies. Release is an agent skill from kdlbs/kandev. Kandev release and version-channel conventions — unified Stable SemVer plus deterministic npm-only Nightlies.
Release fits situations like: cutting a release; changing channels; debugging artifacts; answering version-channel questions.
Run `npx skills add kdlbs/kandev --skill release -a claude-code`. Or copy the skill folder (.agents/skills/release in kdlbs/kandev) into .claude/skills/release in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kdlbs/kandev --skill release -a codex`. Or copy the skill folder (.agents/skills/release in kdlbs/kandev) into .agents/skills/release in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kdlbs/kandev --skill release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release, .gemini/skills/release, .github/skills/release and .opencode/skills/release in your project.
Going by SKILL.md and its folder, Release needs the command-line tools its instructions call (bash, node, python3, make and gh) and credentials named GITHUB_TOKEN, RELEASE_PR_BYPASS_TOKEN and RELEASE_GPG_PRIVATE_KEY. Our summary lists: Python 3; Docker; A credential in GITHUB_TOKEN; A credential in RELEASE_PR_BYPASS_TOKEN.
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Release is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Release: Dev Release (alecs5am/ralphy, 136 stars), ClickUp CLI Release Process (krodak/clickup-cli, 121 stars), Kanvibe Release Deploy (rookedsysc/kanvibe, 143 stars) and Release Flow (romankurnovskii/BrewMate, 301 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kdlbs (a GitHub organization) maintains it in kdlbs/kandev, which has 909 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 8, 2026.
Source: kdlbs/kandev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.