Agent skill

Release

by kdlbs in kdlbs/kandev

Kandev release and version-channel conventions — unified Stable SemVer plus deterministic npm-only Nightlies.

AGPL-3.0Auto-check passedDevelopment

Install Release

skills CLI
$ npx skills add kdlbs/kandev --skill release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kdlbs/kandev release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kdlbs/kandev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/release .claude/skills/release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
release
GitHub stars
909
Token cost
~2.6k tokens
SKILL.md length
1,281 words
Files
1
Skills in repo
45
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Kandev release and version-channel conventions — unified Stable SemVer plus deterministic npm-only Nightlies.

  • Works in 7 steps: Maintainer clicks "Run workflow" → keeps… → prepare job bumps version + regenerates… → build-web, build-bundles,… → …
  • Cutting a release
  • SKILL.md covers Version targets, Release flow, Contributor notices and Release PR ruleset bypass, plus 3 more sections
  • Calls bash, node and python3; needs GITHUB_TOKEN and RELEASE_PR_BYPASS_TOKEN

What it does

Release is an agent skill from kdlbs/kandev. Kandev release and version-channel conventions — unified Stable SemVer plus deterministic npm-only Nightlies. Use when cutting a release, changing channels, debugging artifacts, or answering version-channel questions.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with npm, Homebrew and GitHub. The repository describes itself as: AI Kanban & Development Environment. Orchestrate multiple agents, review changes, open PRs. Multi-provider, self-hostable, no telemetry. The licence is AGPL-3.0.

When your agent uses it

  • Cutting a release
  • Changing channels
  • Debugging artifacts
  • Answering version-channel questions

Example prompts

  • “/release”

Requirements

  • Python 3
  • Docker
  • A credential in GITHUB_TOKEN
  • A credential in RELEASE_PR_BYPASS_TOKEN

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Maintainer clicks "Run workflow" → keeps channel=stable → picks bump (patch/minor/major) → optional dry_run or desktop_validation_only.
  2. prepare job bumps version + regenerates CHANGELOG, opens release PR, squash-merges, tags vX.Y.Z.
  3. build-web, build-bundles, build-remote-helpers, build-desktop, and both Docker builds create the channel inputs.
  4. publish-release promotes staged standard archives to the existing default names, publishes full archives and helper assets, then attaches…
  5. publish-npm publishes 5 @kdlbs/runtime-* packages + main kandev package to npmjs.
  6. update-homebrew-tap pushes updated Formula/kandev.rb to kdlbs/homebrew-kandev via SSH deploy key.
  7. update-scoop-bucket pushes updated bucket/kandev.json to kdlbs/scoop-kandev via its SSH deploy key.

What it can do on your machine

Read from SKILL.md and the folder at commit b734113. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash
    • node
    • python3
    • make
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • RELEASE_PR_BYPASS_TOKEN
    • RELEASE_GPG_PRIVATE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Release loads about 2.6k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 1,281 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kdlbs/kandev at commit b734113, republished under its AGPL-3.0 licence (© kdlbs). 1,281 words, ~2,617 tokens.

Download SKILL.mdSave it as .claude/skills/release/SKILL.md (or your agent's skills folder).
name
release
description
Kandev release and version-channel conventions — unified Stable SemVer plus deterministic npm-only Nightlies. Use when cutting a release, changing channels, debugging artifacts, or answering version-channel questions.

Release & Versioning

Kandev Stable releases use a single SemVer X.Y.Z shared across all distribution channels. npm also has an explicit prerelease-only nightly channel; it is not part of the unified Stable artifact set.

Version targets

  • apps/cli/package.json version → X.Y.Z
  • npm main package: kandev@X.Y.Z
  • npm runtime packages: @kdlbs/runtime-{platform}@X.Y.Z (5 platforms; declared as optionalDependencies in main package)
  • Git tag: vX.Y.Z (three-part; legacy vM.m tags normalize to M.m.0)
  • Homebrew formula: kdlbs/homebrew-kandev Formula/kandev.rb version "X.Y.Z"
  • Scoop bucket: kdlbs/scoop-kandev bucket/kandev.json version, URL, and hash
  • GitHub release: vX.Y.Z with standard platform archives kandev-{platform}.tar.gz, full offline archives kandev-{platform}-full.tar.gz, checksums, Windows ZIP equivalents, remote helper assets, and runtime-size-report.md

Stable default archive names contain the standard runtime: host kandev, host agentctl, and remote-helpers.json. The -full archives also contain all four remote helper executables. Stable npm packages, Homebrew, Scoop, winget, Chocolatey, and Desktop use standard archives. Containers and npm Nightlies stay full. Desktop keeps one standard installer and updater track.

npm, Homebrew, and Scoop are sibling channels, not chained. All three consume the same GitHub release artifacts; none depends on another package-manager channel.

For npm Nightly, Stable X.Y.Z plus a full main SHA produces X.Y.(Z+1)-nightly.sha<first-12-lowercase-hex>. kandev and all five runtime packages publish at that exact version under npm's nightly dist-tag. Nightly never moves latest and creates no Git tag, GitHub Release, Homebrew formula, Scoop bucket update, Desktop feed/build, or container tag.

Release flow

Stable runs entirely in CI via .github/workflows/release.yml, triggered by a maintainer from the GitHub Actions UI:

  1. Maintainer clicks "Run workflow" → keeps channel=stable → picks bump (patch/minor/major) → optional dry_run or desktop_validation_only.
  2. prepare job bumps version + regenerates CHANGELOG, opens release PR, squash-merges, tags vX.Y.Z.
  3. build-web, build-bundles, build-remote-helpers, build-desktop, and both Docker builds create the channel inputs.
  4. publish-release promotes staged standard archives to the existing default names, publishes full archives and helper assets, then attaches checksums, the size report, desktop artifacts, and notes.
  5. publish-npm publishes 5 @kdlbs/runtime-* packages + main kandev package to npmjs.
  6. update-homebrew-tap pushes updated Formula/kandev.rb to kdlbs/homebrew-kandev via SSH deploy key.
  7. update-scoop-bucket pushes updated bucket/kandev.json to kdlbs/scoop-kandev via its SSH deploy key.

Contributor notices

The Release workflow has a notify_contributors checkbox. It defaults to false. When selected, the workflow calls the reusable notification workflow after GitHub Release, npm, Homebrew, and Scoop publication all succeed. Dry runs, desktop validation, Nightly, cancellation before the notification job starts, and publication errors skip the call. Cancellation after posting starts can leave partial notices; rerun with the exact tag to complete safely.

For manual notices or recovery, run Notify release contributors from the main ref. Leave release_tag empty to select the latest published Stable release. Enter an exact tag to select another release. The dry_run checkbox previews the same PR selection and comment text without posting.

The helper reads PR links from the release notes. It posts only to merged PRs from this repository that belong to the selected release tag. It excludes bots and maintainers from cliff.toml. The job token posts as github-actions[bot]. Only notices from that bot or a listed maintainer count as already sent.

Each comment includes a hidden release ID marker. Repeat runs skip comments with that marker and the exact unmarked notice used for v0.97.0. After a partial run, use the separate workflow with the exact tag. It skips confirmed notices and retries only missing notices. Wait for GitHub rate limits to clear before retrying.

Release PR ruleset bypass

A normal Stable release creates its branch and pull request with GITHUB_TOKEN. It uses RELEASE_PR_BYPASS_TOKEN only for an exact-head gh pr merge --admin.

Store this fine-grained personal access token in the protected release environment. Its owner must remain an organization administrator. Select only kdlbs/kandev and grant contents: write repository permission.

Record the token owner and expiration date. Rotate the environment secret before the token expires or the owner loses administrator access. The workflow must stop before tag creation when the token is missing or cannot bypass the ruleset.

After the merge, use GITHUB_TOKEN to read the PR state. Tag only the merge commit that GitHub reports after it appears on origin/main.

Workflow-control invariant: When a channel intentionally skips a job, every downstream job reachable through that dependency chain must use a status function such as !cancelled() plus explicit needs.<job>.result == 'success' checks. For a partial Stable release, preserve the existing signed tag and rerun with backfill_tag; never run a normal bump against an existing tag. Declare Stable complete only after publish-release, publish-npm, update-homebrew-tap, and update-scoop-bucket each succeed and their artifacts are verified—an aggregate green run can hide skipped publication jobs.

Required web, runtime, and desktop artifact uploads attempt up to three times, with waits of 30 seconds and 60 seconds between attempts. They fail explicitly when an expected file is missing. Desktop matrix targets use fail-fast: false so a transient upload failure does not cancel sibling targets, but publication still requires the complete matrix to succeed. Rerun a failed producer job in the same workflow run after a transient failure. If the signed tag already exists and the run remains partial, use backfill_tag for that tag after checking which channels already succeeded.

Show full SKILL.md (444 more words)Show less

Stable has no local release driver; the entire Stable flow runs in GHA. The Nightly metadata and publication revalidation state machine lives in scripts/release/nightly-release.sh, which GHA invokes for scheduled and manual Nightly runs.

The same workflow schedules npm Nightly with cron 0 12 * * *. It skips before building when main has no commit after the latest Stable tag, the exact commit is already published, or a same or newer main Nightly supersedes the scheduled commit. Eligible runs build only the shared web bundle and five native runtime archives, then publish runtimes first and kandev last with OIDC provenance. Stable and Nightly workflow runs share one non-cancelling release-wide concurrency slot. Before publishing, Nightly rechecks the stable Git/npm baseline and the previously observed nightly tag; a pending Stable tag or moved value safely suppresses stale publication.

Maintainers may run that same Nightly path from the Actions UI with the main ref and channel=nightly. dry_run=true retains the real metadata and registry preflight but skips shared builds and all npm writes. The shared form's required bump value is ignored for Nightly; desktop_validation_only and backfill_tag are Stable-only and rejected when combined with it.

Validate Nightly automation changes with:

bash
node --test scripts/release/nightly-version.test.mjs scripts/release/nightly-release.test.mjs
python3 .github/scripts/release-workflow-contract_test.py
bash -n scripts/release/nightly-release.sh scripts/release/publish-npm.sh

Release-tag signing configuration

The release workflow reads signing configuration from the GitHub release environment. RELEASE_GPG_PRIVATE_KEY and the optional RELEASE_GPG_PASSPHRASE are environment secrets. The full 40-character RELEASE_GPG_FINGERPRINT is an environment variable, not a secret: the workflow reads vars.RELEASE_GPG_FINGERPRINT, so storing it as a secret makes normal-release preflight treat it as missing.

.github/release-signing-key.asc must contain exactly one public primary key whose fingerprint matches that variable; never commit private key material. backfill_tag repairs publication for an already-signed existing tag only and does not bypass the normal-release signing checks.

Desktop signing is automatic. Complete macOS/Windows signing and notarization secrets produce signed artifacts; missing or incomplete signing inputs produce unsigned desktop artifacts and the GitHub release notes get an unsigned-artifact warning. desktop_validation_only=true builds artifacts from the current workflow ref for maintainer inspection and skips the release PR, tag, GitHub release, npm publish, Homebrew update, Scoop update, and public container tags.

Runtime resolution

The published npm shim (apps/cli/bin/native-shim.js) locates its bundled runtime via:

  1. KANDEV_BUNDLE_DIR env var (set by Homebrew wrapper, used by tests).
  2. Installed @kdlbs/runtime-{platform} npm package via require.resolve().
  3. The Homebrew/manual install path execs bin/kandev directly. (--runtime-version is rejected by the native launcher.)

Runtime helper binary checklist

When adding, renaming, or removing bundled helper binaries such as agentctl-<goos>-<goarch>, update every packaging surface in the same PR:

  • backend build targets and scripts
  • Docker/runtime image copy steps
  • .github/workflows/release.yml bundle, macOS signing, and notarization loops
  • scripts/release/prepare-desktop-runtime.sh
  • scripts/release/verify-desktop-runtime.sh
  • scripts/release/remote-helper-assets.mjs
  • apps/backend/internal/agent/runtime/lifecycle/remote_helper_manifest.go and the cache resolver
  • scripts/release-desktop.test.sh
  • apps/desktop/AGENTS.md runtime resource list

Verify with the helper build plus release-runtime tests, for example:

bash
make -C apps/backend build-agentctl-remote
bash scripts/release-desktop.test.sh

© kdlbs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/release of kdlbs/kandev.

Open the folder on GitHubat commit b734113

Compare with similar skills

Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Release this skillkdlbs/kandev909—~2.6kAutomated safety check: PassAGPL-3.0
Dev Releasealecs5am/ralphy136—~757Automated safety check: PassApache-2.0
ClickUp CLI Release Processkrodak/clickup-cli121—~906Automated safety check: WarnMIT
Kanvibe Release Deployrookedsysc/kanvibe143—~12kAutomated safety check: NotesAGPL-3.0
Release Flowromankurnovskii/BrewMate301—~976Automated safety check: PassMIT
Deploykangraemin/claude-inspector131—~739Automated safety check: NotesMIT

Similar skills

  • Dev Release

    alecs5am/ralphy

    Cut a Ralphy CLI release across GitHub Releases, Homebrew, and npm.

    136 GitHub stars~757 tokensUpdated 15 days ago
    DevelopmentAuto-check passed
  • ClickUp CLI Release Process

    krodak/clickup-cli

    Walks through releasing a new version of clickup-cli: pre-release checks, version bump, tagging, CI watch, release notes and the Homebrew update.

    121 GitHub stars~906 tokensUpdated yesterday
    DevOps & CloudAuto-check: warnings
  • Kanvibe Release Deploy

    rookedsysc/kanvibe

    A skill your agent uses whenever releasing or deploying KanVibe desktop from a clean, up-to-date dev checkout: ask only for the target version and release-note approval, then let the AI update…

    143 GitHub stars~12k tokensUpdated today
    DevelopmentAuto-check: notes
  • Release Flow

    romankurnovskii/BrewMate

    Automate the full application release flow for BrewMate, including committing local changes, bumping version, waiting for GitHub Actions release build, and pushing the in-repo cask update…

    301 GitHub stars~976 tokensUpdated 10 days ago
    DevOps & CloudAuto-check passed
  • Deploy

    kangraemin/claude-inspector

    Claude Inspector macOS 배포 스킬. An agent skill from kangraemin/claude-inspector.

    131 GitHub stars~739 tokensUpdated today
    AI & LLM EngineeringAuto-check: notes
  • Project Pull Request

    swimmwatch/cloakbrowser-mcp

    Create, update, prepare, or review a cloakbrowser-mcp GitHub Pull Request only when the user explicitly requests PR work.

    161 GitHub stars~1k tokensUpdated 6 days ago
    DevelopmentAuto-check passed

More from kdlbs/kandev

All 45 skills in this repo
  • PR Walkthrough

    kdlbs/kandev

    Generate a single-file HTML walkthrough that explains a PR's purpose, user impact, interface changes, compatibility risks, and implementation.

    909 GitHub stars~6.2k tokensUpdated today
    Auto-check passed
  • Debug

    kdlbs/kandev

    Diagnose Kandev bugs, running-instance issues, UI/browser failures, and runtime behavior.

    909 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Improve Kandev's AI harness from session learnings or explicit requests.

    909 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Diagram Design

    kdlbs/kandev

    Create branded architecture, IT current-state, flowchart, sequence, state machine, ER/data model, timeline, swimlane, quadrant, radar/spider, polar chart (polar/radial lollipop), loop/flywheel…

    909 GitHub starsUsed in 1 repo~8k tokens
    Auto-check passed
  • TDD

    kdlbs/kandev

    Implement changes using Test-Driven Development (Red-Green-Refactor).

    909 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Verify

    kdlbs/kandev

    Run a broad local verification audit only when the user explicitly requests it or PR/CI remediation requires it.

    909 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Questions about Release

What does Release do?

Kandev release and version-channel conventions — unified Stable SemVer plus deterministic npm-only Nightlies. Release is an agent skill from kdlbs/kandev. Kandev release and version-channel conventions — unified Stable SemVer plus deterministic npm-only Nightlies.

When should I use Release?

Release fits situations like: cutting a release; changing channels; debugging artifacts; answering version-channel questions.

How do I install Release in Claude Code?

Run `npx skills add kdlbs/kandev --skill release -a claude-code`. Or copy the skill folder (.agents/skills/release in kdlbs/kandev) into .claude/skills/release in your project. Claude Code loads it when a task matches its description.

How do I install Release in Codex?

Run `npx skills add kdlbs/kandev --skill release -a codex`. Or copy the skill folder (.agents/skills/release in kdlbs/kandev) into .agents/skills/release in your project. Codex loads it when a task matches its description.

Can I use Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kdlbs/kandev --skill release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/release, .gemini/skills/release, .github/skills/release and .opencode/skills/release in your project.

What does Release need to run?

Going by SKILL.md and its folder, Release needs the command-line tools its instructions call (bash, node, python3, make and gh) and credentials named GITHUB_TOKEN, RELEASE_PR_BYPASS_TOKEN and RELEASE_GPG_PRIVATE_KEY. Our summary lists: Python 3; Docker; A credential in GITHUB_TOKEN; A credential in RELEASE_PR_BYPASS_TOKEN.

Does Release access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Release safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Release use?

Release is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Release use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Release?

Skills that share tags, products or a category with Release: Dev Release (alecs5am/ralphy, 136 stars), ClickUp CLI Release Process (krodak/clickup-cli, 121 stars), Kanvibe Release Deploy (rookedsysc/kanvibe, 143 stars) and Release Flow (romankurnovskii/BrewMate, 301 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Release?

kdlbs (a GitHub organization) maintains it in kdlbs/kandev, which has 909 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 8, 2026.

Source: kdlbs/kandev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.