Agent skill

Dakota Release

by projectbluefin in projectbluefin/dakota

Stable promotion, image signing, digest locking, rollback, and release automation for Dakota.

MITAuto-check passedDevOps & Cloud

Install Dakota Release

skills CLI
$ npx skills add projectbluefin/dakota --skill dakota-release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install projectbluefin/dakota dakota-release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/projectbluefin/dakota.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dakota-release .claude/skills/dakota-release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dakota-release
GitHub stars
180
Token cost
~1.3k tokens
SKILL.md length
568 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Stable promotion, image signing, digest locking, rollback, and release automation for Dakota.

  • Works in 5 steps: Trace Digest Flow: Map the exact… → Verify Cryptographic Policy: Confirm… → Lock Tested SHA: Always pin and verify… → …
  • DevOps & Cloud work in your project
  • SKILL.md covers When to Use, When NOT to Use, Core Process and Invariants, plus 4 more sections
  • Calls just

What it does

Dakota Release is an agent skill from projectbluefin/dakota. Stable promotion, image signing, digest locking, rollback, and release automation for Dakota.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. The repository describes itself as: The buildstream for making Bluefin. The licence is MIT.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/dakota-release”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Trace Digest Flow: Map the exact SHA/digest path from build receipt to the target publication tag.
  2. Verify Cryptographic Policy: Confirm cosign certificate identity and issuer rules match repository policy.
  3. Lock Tested SHA: Always pin and verify the tested source commit SHA; fail closed if upstream advanced during testing.
  4. Verify Variant Coverage: Inspect the actual promotion and rollback workflows independently. rollback-stable.yml currently rolls back only…
  5. Human Gate: Stop and obtain human confirmation before executing any production promotion, signing change, or tag rollback.

What it can do on your machine

Read from SKILL.md and the folder at commit 909f687. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • just

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dakota Release loads about 1.3k tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 568 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from projectbluefin/dakota at commit 909f687, republished under its MIT licence (© projectbluefin). 568 words, ~1,273 tokens.

Download SKILL.mdSave it as .claude/skills/dakota-release/SKILL.md (or your agent's skills folder).
name
dakota-release
description
Stable promotion, image signing, digest locking, rollback, and release automation for Dakota.
metadata.context7-sources
/sigstore/cosign, /bootc-dev/bootc

Dakota Release and Promotion

Release workflows cross a cryptographic and security boundary. Stop for human approval before changing signing identities, token permissions, provenance, or promotion gates.

When to Use

  • Modifying .github/workflows/execute-release.yml or rollback-stable.yml
  • Auditing or updating cosign keyless OIDC signatures or SLSA build provenance attestations
  • Managing image digest pinning, release receipts, or immutable tag promotion
  • Managing the on-demand stable promotion flow or rollback procedures

When NOT to Use

  • Routine CI build or validation workflow updates → load dakota-ci
  • Local container image builds or testing → load dakota-image
  • PR review workflows → load dakota-review

Core Process

  1. Trace Digest Flow: Map the exact SHA/digest path from build receipt to the target publication tag.
  2. Verify Cryptographic Policy: Confirm cosign certificate identity and issuer rules match repository policy.
  3. Lock Tested SHA: Always pin and verify the tested source commit SHA; fail closed if upstream advanced during testing.
  4. Verify Variant Coverage: Inspect the actual promotion and rollback workflows independently. rollback-stable.yml currently rolls back only dakota and dakota-nvidia, plus optional default-image multiarch tags. It does not roll back gaming or nvidia-gaming; recovery of those variants needs a separately reviewed plan, not an assumption of four-variant parity.
  5. Human Gate: Stop and obtain human confirmation before executing any production promotion, signing change, or tag rollback.

Invariants

  • Branch Model: testing is the default branch and integration trunk. sync-next.yml derives next with its stream overlay. Stable candidates are published testing SHAs, not commits from main. Promotion must neither move main nor require it to match the candidate; post-release verification compares image digests directly.
  • Manual Preflight: just release dispatches a remote preflight, not a local simulation or a full signature/variant verification. --apply explicitly enables promotion. sha=<full-40-character-SHA> is a recovery override that bypasses the successful-publish-run lookup; malformed or repeated SHA arguments must fail before dispatch.
  • Rolling Streams: next and btw are rolling development streams; they never promote to :stable.
  • Promotion Gates: Stable promotion intentionally avoids the testsuite e2e gate. It enforces freshness locking, cosign verification, and digest-based copy.
  • Cryptographic Anchoring: Anchor --certificate-identity-regexp with ^...$ and restrict it strictly to the authorized publishing workflow and branch.
  • Digest-Based Promotion: Promotion operates on immutable digests (@sha256:...) or tested source SHAs, never by re-resolving a mutable tag name.
Show full SKILL.md (205 more words)Show less

Common Rationalizations

RationalizationReality
"Adding an e2e test gate to promotion makes stable safer."Promotion occurs hours after build. Re-running e2e adds flakiness and delays security hotfixes. CI owns test gates during build.
"A regex without ^ and $ is good enough for cosign identity."Unanchored regular expressions allow malicious forks or subpaths to forge signatures. Always anchor with ^ and $.
"The rollback workflow covers every published variant."Its current coverage is the default/NVIDIA pair, not the gaming variants. Verify each affected tag before claiming recovery.

Red Flags

  • Pull requests targeting main instead of testing
  • Adding testsuite e2e gates into execute-release.yml
  • Re-resolving mutable tags instead of copying by immutable digest
  • Unanchored --certificate-identity-regexp in cosign verification commands
  • Promoting a new release without human approval

Verification

  • All third-party release actions are pinned to 40-character commit SHAs
  • Certificate identity regex is anchored with ^ and $
  • Digest copy commands use skopeo/cosign without intermediate re-tagging
  • Every affected variant is accounted for; the default/NVIDIA rollback is not reported as recovery of gaming variants
  • No Git branch update gates promotion or post-release verification; stable-digest checks and cleanup remain intact
  • Human approval obtained before any release execution
  • just test-release passes offline; new tests are registered in the CI-facing check-publish-workflow recipe

References

© projectbluefin, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/dakota-release of projectbluefin/dakota.

Open the folder on GitHubat commit 909f687

Compare with similar skills

Dakota Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dakota Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dakota Release this skillprojectbluefin/dakota180—~1.3kAutomated safety check: PassMIT
Monitor CInrwl/nx29k6 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw36k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k8 repos~4.3kAutomated safety check: PassNone
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 6 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    36k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 8 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from projectbluefin/dakota

All 10 skills in this repo
  • Dakota Buildstream

    projectbluefin/dakota

    BuildStream elements, junctions, patches, dependency graphs, and build failures in Dakota.

    180 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Dakota Extensions

    projectbluefin/dakota

    Package, update, and configure GNOME Shell extensions, Quick Settings panels, and schemas in Dakota.

    180 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Dakota Factory

    projectbluefin/dakota

    Maintain task-relevant Dakota guidance: documentation accuracy, official-source verification, and skill auditing.

    180 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Dakota Packaging

    projectbluefin/dakota

    Add, remove, or update native software built from source in Dakota, including Go, Rust, Zig, C/Meson, and binary releases.

    180 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Dakota Ujust

    projectbluefin/dakota

    Author safe end-user ujust recipes in files/just-overrides/default.just, including quoting, gum, JSON, and public-post confirmation.

    180 GitHub stars~1.1k tokensUpdated today
    Auto-check: notes
  • Dakota Image

    projectbluefin/dakota

    OCI layer assembly, boot testing, installer boundaries, VM work, and local OTA verification for Dakota images.

    180 GitHub stars~929 tokensUpdated today
    Auto-check passed

Categories

Questions about Dakota Release

What does Dakota Release do?

Stable promotion, image signing, digest locking, rollback, and release automation for Dakota. Dakota Release is an agent skill from projectbluefin/dakota. Stable promotion, image signing, digest locking, rollback, and release automation for Dakota.

When should I use Dakota Release?

Dakota Release fits situations like: devOps & Cloud work in your project.

How do I install Dakota Release in Claude Code?

Run `npx skills add projectbluefin/dakota --skill dakota-release -a claude-code`. Or copy the skill folder (.agents/skills/dakota-release in projectbluefin/dakota) into .claude/skills/dakota-release in your project. Claude Code loads it when a task matches its description.

How do I install Dakota Release in Codex?

Run `npx skills add projectbluefin/dakota --skill dakota-release -a codex`. Or copy the skill folder (.agents/skills/dakota-release in projectbluefin/dakota) into .agents/skills/dakota-release in your project. Codex loads it when a task matches its description.

Can I use Dakota Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add projectbluefin/dakota --skill dakota-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dakota-release, .gemini/skills/dakota-release, .github/skills/dakota-release and .opencode/skills/dakota-release in your project.

What does Dakota Release need to run?

Going by SKILL.md and its folder, Dakota Release needs the command-line tools its instructions call (just).

Does Dakota Release access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dakota Release safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dakota Release use?

Dakota Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dakota Release use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dakota Release?

Skills that share tags, products or a category with Dakota Release: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 36k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Analyze GitHub Action Logs (withastro/astro, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dakota Release?

projectbluefin (a GitHub organization) maintains it in projectbluefin/dakota, which has 180 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 10, 2026.

Source: projectbluefin/dakota on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.