Verdaccio Pull Request Workflow
verdaccio/verdaccio
Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.
Run a release end to end, autonomous by default: version bump everywhere, changelog, docs, landing page, tag, push, GitHub release, PyPI/npm.
$ npx skills add luongnv89/skills --skill ship -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install luongnv89/skills ship --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ship .claude/skills/ship && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ship" agent skill from https://github.com/luongnv89/skills/tree/main/skills/ship into .claude/skills/ship/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ship", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/luongnv89/skills/tree/main/skills/shipType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add luongnv89/skills --skill ship -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install luongnv89/skills ship --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/ship .agents/skills/ship && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ship" agent skill from https://github.com/luongnv89/skills/tree/main/skills/ship into .agents/skills/ship/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ship", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add luongnv89/skills --skill ship -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install luongnv89/skills ship --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/ship .cursor/skills/ship && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ship" agent skill from https://github.com/luongnv89/skills/tree/main/skills/ship into .cursor/skills/ship/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ship", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/luongnv89/skills.git --path skills/ship--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add luongnv89/skills --skill ship -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install luongnv89/skills ship --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/ship .gemini/skills/ship && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ship" agent skill from https://github.com/luongnv89/skills/tree/main/skills/ship into .gemini/skills/ship/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ship", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install luongnv89/skills shipInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add luongnv89/skills --skill ship -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/ship .github/skills/ship && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ship" agent skill from https://github.com/luongnv89/skills/tree/main/skills/ship into .github/skills/ship/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ship", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add luongnv89/skills --skill ship -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install luongnv89/skills ship --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/luongnv89/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/ship .opencode/skills/ship && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ship" agent skill from https://github.com/luongnv89/skills/tree/main/skills/ship into .opencode/skills/ship/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ship", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
shipRun a release end to end, autonomous by default: version bump everywhere, changelog, docs, landing page, tag, push, GitHub release, PyPI/npm.
Ship is an agent skill from luongnv89/skills. Run a release end to end, autonomous by default: version bump everywhere, changelog, docs, landing page, tag, push, GitHub release, PyPI/npm. Use to ship, cut, or tag a release. Don't use for routine commits, pull requests, or marketplace publishing.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 17 other files, including reference files (for example `agents/changelog-generator.md`, `agents/docs-updater.md` and `agents/landing-page-updater.md`).
It sits in Development, covering Landing pages, Changelog and release notes and Pull requests. It works with GitHub and npm. The repository describes itself as: Supercharge your AI agents/bots with reusable skills. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit b5ef695. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ship loads about 3.3k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 64 tokens; SKILL.md has 1,615 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from luongnv89/skills at commit b5ef695, republished under its MIT licence (© luongnv89). 1,615 words, ~3,342 tokens.
.claude/skills/ship/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.Release a project end to end: the version in every place it appears, the developer changelog and end-user notes, the README, docs, and landing page, then build, tag, push, GitHub release, and PyPI/npm publish.
/ship [X.Y.Z | major | minor | patch] [--auto | --no-auto]PARTIAL, or stop with BLOCKED.--no-auto) asks the user to confirm the version, the file changes, the build, the push, the GitHub release, and each publish. "Ask me before each step" selects it too.X.Y.Z releases that version; major|minor|patch sets the bump.Read references/auto-mode.md before Step 1: outcome table, hard stops, version rules.
Scope. A mode removes confirmations; it never widens the request. Only /ship or an explicit request to ship, cut, tag, or publish a release runs Steps 6-9. "What changed?" or "draft release notes" runs Step 2 and the changelog-generator only, and changes no file. "Bump the version" or "update the docs/landing page for the release" runs Steps 1-5 and leaves the changes uncommitted.
Before creating, updating, or deleting files, sync the current branch with the remote. If the working tree is not clean, run git stash push -u -m "pre-sync" first and git stash pop after:
branch="$(git rev-parse --abbrev-ref HEAD)"
git fetch origin && git pull --rebase origin "$branch"If a rebase or stash conflict occurs, stop with BLOCKED — sync conflict and list the files under Decision (interactive mode: ask the user). If origin is missing, follow the origin missing row in references/auto-mode.md.
Print the mode, the version argument, and the scope.
Full release only: run git status --porcelain. If it prints anything: auto mode stops with BLOCKED — uncommitted changes and lists the files; interactive mode asks whether to stash (pop after the final report), commit, or abort. Never discard work.
Full release only: check that the current branch is the default branch: git symbolic-ref --short refs/remotes/origin/HEAD prints origin/<default>; if that ref is missing, read the HEAD branch: line of git remote show origin. If the branches differ, follow the Not on the default branch row in references/auto-mode.md.
Full release only: run git describe --exact-match --tags HEAD. Resume that release only when no version argument was given, or an explicit version equals the tag's release version. A different version or major|minor|patch continues through the sync and normal version selection. For resume, follow references/resume.md: skip version preparation, but rebuild and verify artifacts before any unfinished local upload.
Run the Repo Sync above.
Check for a release tool or a monorepo:
ls -d .releaserc* .changeset .versionrc* lerna.json release.config.* pnpm-workspace.yaml 2>/dev/null
grep -qs '^\[workspace\]' Cargo.toml && echo "cargo workspace"
grep -E '"(release|semantic-release|release-it|@changesets/cli|standard-version|workspaces)"[[:space:]]*:' package.json 2>/dev/nullThe package.json grep matches a scripts.release entry, a release-tool dependency, or workspaces, never "version". On a match, follow the Release tool detected or Monorepo row in references/auto-mode.md.
last_tag="$(git describe --tags --abbrev=0 2>/dev/null)"
range="${last_tag:+$last_tag..}HEAD"
git log "$range" --oneline --no-merges -n 300
git log "$range" --format=%B --no-merges | grep -E '^BREAKING[ -]CHANGE:'OLD_VERSION is last_tag without its prefix; the new tag keeps that prefix (v when there are no tags). Choose NEW_VERSION by the first rule that applies:
last_tag exists and the log is empty → BLOCKED — nothing to release.references/auto-mode.md → Version rules matches → use its outcome.BREAKING: or !: subject or a BREAKING CHANGE: footer, MINOR for feat:, else PATCH.Stop with BLOCKED before any file changes if the tag for NEW_VERSION exists locally or on origin, or if a registry the project publishes to already has NEW_VERSION (references/publishing.md → Decide per registry). Print "N features, M fixes, K breaking since vOLD → vNEW (rule: <rule>)". Interactive mode asks the user to confirm or override; auto mode continues.
Subagents read in isolated context so the main agent's context window stays small. Spawn inputs, file ownership, and the workspace: references/orchestration.md. Without the Agent tool, run each agent file inline in the same order.
version-bumper and changelog-generator.docs-updater and landing-page-updater, both reading version-changes.json and user-notes.md.The landing-page-updater owns the files that render the landing site and reports four items, each updated, current, or not on page with evidence: version (stale older values too), changelog for end users (plain language, no hashes, PR numbers, or authors), feature list, and documentation. It never adds a section the page lacks. With no landing page it reports "No landing page — skipped."
Interactive mode shows the consolidated summary and waits for confirmation.
Spawn release-reviewer. Auto mode always runs it; it replaces the human check. On NEEDS_FIX, apply each issue's suggestion to the workspace proposals and review once more. Still NEEDS_FIX → BLOCKED — release review failed, with no project file written. Without the Agent tool, run the reviewer's checklist inline and note under Uncertainty that the review was not independent.
Apply in the order in references/orchestration.md → Apply changes. Then, unless this is a first release, sweep for the old version:
git grep -n -I -F "$OLD_VERSION" -- . ':(exclude,glob)**/CHANGELOG*' ':(exclude,glob)**/CHANGES*' ':(exclude,glob)**/HISTORY*' ':(exclude,glob)**/NEWS*'Run the same sweep for each drifted current value in version_sources. Use one class per hit: missed (the project's own version: fix it and re-run the sweep), historical, dependency, or fixture. The step passes when no hit is missed and every version_sources file reads NEW_VERSION; otherwise stop with BLOCKED — version not updated in <file>. Record the class counts under Evidence.
[ -f package.json ] && grep -q '"build"' package.json && echo "npm run build"
[ -f Makefile ] && grep -q '^build:' Makefile && echo "make build"
[ -f Cargo.toml ] && echo "cargo build --release"
[ -f pyproject.toml ] && grep -q '^\[build-system\]' pyproject.toml && echo "python -m build"Interactive mode asks first; auto mode runs it. A failed build stops the run: BLOCKED — build failed. No build step → skip and say so.
Step 1 guaranteed a clean start, so every tracked change belongs to the release, including regenerated lockfiles:
git add -u
git add <each file Step 5 created, such as a new CHANGELOG.md>
git commit -m "chore(release): vX.Y.Z"
git tag -a vX.Y.Z -m "Release vX.Y.Z"
git status --porcelain --untracked-files=no # must print nothingIf a hook rejects the commit, stop: BLOCKED — commit hook failed; never use --no-verify. Interactive mode asks "Push <branch> and tag vX.Y.Z to origin?"; a decline ends with PARTIAL — tag vX.Y.Z created locally, not pushed. Auto mode pushes:
git push origin <branch> && git push origin vX.Y.Z
git ls-remote --tags origin "refs/tags/vX.Y.Z"A rejected push stops with BLOCKED — push rejected; never force-push. If git ls-remote prints nothing, stop, skip Steps 8-9: BLOCKED — tag vX.Y.Z not on origin (recovery: references/final-report.md).
If gh auth status fails or the remote is not GitHub, skip with PARTIAL and put the command under Decision. If a workflow creates releases on tag push, verify with gh release view vX.Y.Z instead (references/publishing.md). Interactive mode asks first.
gh release create vX.Y.Z --title "vX.Y.Z" --notes-file "$WORKSPACE/changelog-generator/release-notes.md" --latestA pre-release (a - suffix, or a PEP 440 a, b, rc, or .dev suffix) uses --prerelease instead of --latest; a version below the highest existing tag uses --latest=false. Append artifact paths if any exist.
Follow references/publishing.md, using the per-registry decision made in Step 2. Auto mode publishes only where the package already exists for this repository, or to a registry the request names; a missing credential or an npm one-time-password prompt skips that registry with PARTIAL; a CI-owned publish is verified, not repeated.
Every run, including one that stops early, ends with: Result: (COMPLETE, PARTIAL — <reason>, or BLOCKED — <reason>), Mode:, Evidence: (checks that ran, plus each auto decision and its reason), Uncertainty: (not verified), and Decision: (pending user action, or "No approval needed"). Then the post-release checklist. Status rules, an example report for each status, and the checklist: references/final-report.md.
PARTIAL — no remote.references/resume.md, which recovers the notes and registry decisions, rebuilds for unfinished local uploads, and finishes only the steps not yet done.BLOCKED and list the recovery commands (delete the tag locally and on origin, revert the commit) under Decision; the user confirms and runs them. A version published to PyPI or npm cannot be reused; the fix is a new version.references/auto-mode.md and appears under Evidencemissed hit## Unreleased section is promoted, not duplicatedgit ls-remote; the GitHub release exists when gh is availablereferences/final-report.md: result findable first, facts separated from assumptions, claims traceable to evidence, next decision named. Without reviewer feedback, human understanding stays unconfirmedAfter each step, print a status report (√ pass, × fail, a Criteria line, Result: PASS | FAIL | PARTIAL). Templates: references/step-reports.md.
references/auto-mode.md: gate outcomes in both modes, hard stops, version rulesreferences/orchestration.md: workspace, two-wave spawn inputs, file ownership, apply orderreferences/step-reports.md: step report templatesreferences/publishing.md: per-registry decision, CI-owned publishing, PyPI / npm commandsreferences/resume.md: finishing a release that stopped after its tag was createdreferences/final-report.md: status rules, examples, reader checks, post-release checklistagents/: version-bumper, changelog-generator, docs-updater, landing-page-updater, release-reviewer© luongnv89, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 13 other files (references) in skills/ship of luongnv89/skills.
Open the folder on GitHubat commit b5ef695
Ship next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ship this skillluongnv89/skills | 131 | — | ~3.3k | Automated safety check: Pass | MIT | |
| Verdaccio Pull Request Workflowverdaccio/verdaccio | 18k | — | ~1.9k | Automated safety check: Pass | MIT | |
| ZCF Release AutomationUfoMiao/zcf | 6.1k | — | ~3.4k | Automated safety check: Pass | MIT | |
| Prisma Release PRprisma/orm | 48k | — | ~4k | Automated safety check: Pass | Apache-2.0 | |
| Nylas Nodejs Releasenylas/nylas-nodejs | 180 | — | ~1.6k | Automated safety check: Warn | MIT | |
| Dev Releasealecs5am/ralphy | 138 | — | ~757 | Automated safety check: Pass | Apache-2.0 |
verdaccio/verdaccio
Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.
UfoMiao/zcf
Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.
prisma/orm
Helps a Prisma 8 maintainer cut the next release by bumping the version across every workspace package, opening the release PR and preparing the docs PR.
nylas/nylas-nodejs
Prepares nylas-nodejs SDK releases on a versioned release branch with CHANGELOG updates, version bump, git tag, and PR body.
alecs5am/ralphy
Cut a Ralphy CLI release across GitHub Releases, Homebrew, and npm.
arietan/lite-edit
Publish a new LiteEdit release to GitHub — commit code, bump version, write changelog, create GitHub release, and update the landing page.
luongnv89/skills
Review UI usability using Steve Krug's principles and produce a scannable report.
luongnv89/skills
Manage AI agent fleets in Herdr: tile root + sub-agents in one tab, start/prompt/wait/read/monitor via the herdr agent CLI, steer any pane; help lists every operation.
luongnv89/skills
Optimize Ollama configuration for the current machine's hardware.
luongnv89/skills
Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
luongnv89/skills
Audit and optimize websites for technical SEO, content SEO, and AI bot accessibility.
luongnv89/skills
Generate sprint-based development tasks from a PRD. An agent skill from luongnv89/skills.
Categories
Run a release end to end, autonomous by default: version bump everywhere, changelog, docs, landing page, tag, push, GitHub release, PyPI/npm. Ship is an agent skill from luongnv89/skills. Run a release end to end, autonomous by default: version bump everywhere, changelog, docs, landing page, tag, push, GitHub release, PyPI/npm.
Ship fits situations like: routine commits; marketplace publishing.
Run `npx skills add luongnv89/skills --skill ship -a claude-code`. Or copy the skill folder (skills/ship in luongnv89/skills) into .claude/skills/ship in your project. Claude Code loads it when a task matches its description.
Run `npx skills add luongnv89/skills --skill ship -a codex`. Or copy the skill folder (skills/ship in luongnv89/skills) into .agents/skills/ship in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add luongnv89/skills --skill ship -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ship, .gemini/skills/ship, .github/skills/ship and .opencode/skills/ship in your project.
Going by SKILL.md and its folder, Ship needs the command-line tools its instructions call (git and gh). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Ship is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Ship: Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars), ZCF Release Automation (UfoMiao/zcf, 6.1k stars), Prisma Release PR (prisma/orm, 48k stars) and Nylas Nodejs Release (nylas/nylas-nodejs, 180 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
luongnv89 (a GitHub user) maintains it in luongnv89/skills, which has 131 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on October 9, 2026.
Source: luongnv89/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.