Agent skill

CI Release Governance

by rodri-oliveira-dev in rodri-oliveira-dev/Dapper-FluentMap

A skill your agent uses to review or adjust Dapper-FluentMap GitHub Actions, packaging, NuGet publishing, versioning, release, rollback, recovery, provenance, and automation security.

MITAuto-check passedDevOps & Cloud

Install CI Release Governance

skills CLI
$ npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill ci-release-governance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rodri-oliveira-dev/Dapper-FluentMap ci-release-governance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rodri-oliveira-dev/Dapper-FluentMap.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ci-release-governance .claude/skills/ci-release-governance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ci-release-governance
GitHub stars
453
Token cost
~1.8k tokens
SKILL.md length
786 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses to review or adjust Dapper-FluentMap GitHub Actions, packaging, NuGet publishing, versioning, release, rollback, recovery, provenance, and automation security.

  • Works in 10 steps: Read root AGENTS.md, existing workflows,… → Identify triggers, branch guards,… → Preserve the real package set unless the… → …
  • Adjust Dapper-FluentMap GitHub Actions
  • Calls dotnet and rg; needs SONAR_TOKEN
  • NuGet publishing

What it does

CI Release Governance is an agent skill from rodri-oliveira-dev/Dapper-FluentMap. Use this skill to review or adjust Dapper-FluentMap GitHub Actions, packaging, NuGet publishing, versioning, release, rollback, recovery, provenance, and automation security. Do not use for production code changes without pipeline impact.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD. It works with GitHub Actions and GitHub. The repository describes itself as: Fluent mapping for Dapper, with conventions, immutable object materialization, analyzers, source generators, DI integration, and Dommel support. The licence is MIT.

When your agent uses it

  • Adjust Dapper-FluentMap GitHub Actions
  • NuGet publishing
  • Automation security
  • Production code changes without pipeline impact

Example prompts

  • “/ci-release-governance”

Requirements

  • A credential in SONAR_TOKEN

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Read root AGENTS.md, existing workflows, and relevant eng scripts.
  2. Identify triggers, branch guards, permissions, credentials, version sources, artifacts, commands, package IDs, and rollback/recovery paths.
  3. Preserve the real package set unless the task explicitly changes it
  4. Preserve one effective release version source per flow. Directory.Build.props defines FluentMapPackageVersionPrefix; release passes the…
  5. Preserve validation order: restore, audit when applicable, build, test, pack, validate artifacts, smoke test when relevant, then…
  6. Preserve minimum required permissions; avoid broad write permissions.
  7. Keep secrets out of files and logs. Prefer the existing OIDC/Trusted Publishing pattern for NuGet.org unless explicit requirements justify…
  8. Ensure failure before package publication prevents later release announcement. Ensure partial release failure has an explicit rollback or…
  9. Update documentation only for behavior that really exists after the change.
  10. Review the diff for import-source assumptions, wrong branch names, incorrect package identities, fixed old versions, nonexistent scripts…

What it can do on your machine

Read from SKILL.md and the folder at commit 4f5a39f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dotnet
    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SONAR_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

CI Release Governance loads about 1.8k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 786 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rodri-oliveira-dev/Dapper-FluentMap at commit 4f5a39f, republished under its MIT licence (© rodri-oliveira-dev). 786 words, ~1,831 tokens.

Download SKILL.mdSave it as .claude/skills/ci-release-governance/SKILL.md (or your agent's skills folder).
name
ci-release-governance
description
Use this skill to review or adjust Dapper-FluentMap GitHub Actions, packaging, NuGet publishing, versioning, release, rollback, recovery, provenance, and automation security. Do not use for production code changes without pipeline impact.
license
MIT

Purpose

Guide CI/CD, packaging, versioning, release, and recovery changes according to the automation that actually exists in Dapper-FluentMap.

Primary Rule

Inspect .github/workflows/ and relevant eng/** scripts before assuming any automation. Do not document or depend on workflows, scripts, package sets, branches, or publishing behavior that are not present in the current tree.

Current Automation Facts

  • The development and release branch is main.
  • ci.yml runs on pushes to main, pull requests, and manual dispatch.
  • release.yml is manual (workflow_dispatch) and rejects releases not started from main.
  • release.yml validates a SemVer input without v, rejects versions below major 3, checks existing tags, checks NuGet availability for all published package IDs, builds/tests/packs, validates artifacts, runs consumer smoke tests, creates a tag, publishes to NuGet.org and GitHub Packages, creates/updates a GitHub Release, and runs rollback on partial failure.
  • release.yml and release-recovery-missing-nuget.yml share the release concurrency group with cancel-in-progress: false; normal release and recovery wait for each other and never cancel an in-flight release mutation.
  • release-recovery-missing-nuget.yml reconciles future partial release state by first resolving an operator-selected release source. Branch mode uses source_type=branch, source_ref=main, and an explicit SemVer version; tag mode uses source_type=tag, source_ref=v<SemVer>, and derives both version and validated commit by peeling the tag to a commit. The workflow then checks out the resolved commit into a separate source directory, prefers the original release-package artifact from an explicit original_release_run_id, falls back to a validated deterministic rebuild when that artifact is unavailable, validates package identities and dependency contracts from the validated source, recovers missing NuGet.org and GitHub Packages identities with content comparison for existing primary packages, accepts or restores the release tag only when it points to the resolved commit, creates/updates the GitHub Release with exact governed metadata and artifact set, writes recovery attestation metadata bound to the resolved commit, re-attests recovered artifacts, and produces a final reconciliation summary.
  • NuGet.org primary package recovery verifies Flat Container convergence and compares content before accepting existing packages. Symbol packages are submitted separately with NuGet.org V3 tooling; NuGet.org does not expose a public .snupkg content-comparison endpoint, so recovery documents that limitation instead of claiming independent symbol-byte verification.
  • sonar-quality-issues.yml syncs high-impact Sonar findings to GitHub issues when SONAR_CI_ENABLED and SONAR_TOKEN are configured.
  • Package validation scripts live under eng/: validate-slnx-equivalence.ps1, validate-package-metadata.ps1, validate-release-artifacts.ps1, run-sonar-tests.ps1, rollback-release.ps1, and consumer smoke scripts.

When To Use

  • Changes to .github/workflows/** or eng/** automation.
  • Restore/build/test/coverage/pack/publish changes in CI.
  • Versioning, SemVer, tag, artifact, Source Link/provenance, package metadata, or package count changes.
  • NuGet.org, GitHub Packages, OIDC, NuGet/login, permissions, environments, concurrency, credentials, rollback, or recovery work.
  • Documentation changes that describe CI, packaging, release, or recovery behavior.

When Not To Use

  • Functional source changes with no pipeline impact: use dotnet-library-change.
  • Pure behavior-preserving code refactoring: use dotnet-refactoring-engineer.
  • Ordinary tests with no CI or package behavior change.
  • Running a publication/release operation without explicit user request.
Show full SKILL.md (327 more words)Show less

Process

  1. Read root AGENTS.md, existing workflows, and relevant eng scripts.
  2. Identify triggers, branch guards, permissions, credentials, version sources, artifacts, commands, package IDs, and rollback/recovery paths.
  3. Preserve the real package set unless the task explicitly changes it:
    • Dapper.FluentMap
    • Dapper.FluentMap.Dommel
    • FluentMap.DependencyInjection
    • FluentMap.Analyzers
    • FluentMap.Generators
  4. Preserve one effective release version source per flow. Directory.Build.props defines FluentMapPackageVersionPrefix; release passes the requested version through MSBuild Version.
  5. Preserve validation order: restore, audit when applicable, build, test, pack, validate artifacts, smoke test when relevant, then tag/publish/release.
  6. Preserve minimum required permissions; avoid broad write permissions.
  7. Keep secrets out of files and logs. Prefer the existing OIDC/Trusted Publishing pattern for NuGet.org unless explicit requirements justify a different approach.
  8. Ensure failure before package publication prevents later release announcement. Ensure partial release failure has an explicit rollback or recovery story.
  9. Update documentation only for behavior that really exists after the change.
  10. Review the diff for import-source assumptions, wrong branch names, incorrect package identities, fixed old versions, nonexistent scripts, or one-package assumptions.

Validation

For workflow-only changes, use the cheapest reliable checks first:

bash
rg --files .github/workflows eng

For package/release pipeline changes, validate with the actual repository commands:

bash
dotnet restore ./Dapper.FluentMap.slnx
dotnet build ./Dapper.FluentMap.slnx --configuration Release --no-restore
dotnet test ./Dapper.FluentMap.slnx --configuration Release --no-build
dotnet pack ./Dapper.FluentMap.slnx --configuration Release --no-build --output ./artifacts/packages
./eng/validate-package-metadata.ps1 -PackageDirectory './artifacts/packages'

Use ./eng/validate-release-artifacts.ps1 and ./eng/consumer-smoke/run-consumer-smoke.ps1 when release artifacts or consumer package behavior are in scope.

Restrictions

  • Do not run dotnet nuget push, create tags, create GitHub Releases, trigger release workflows, or publish external artifacts unless explicitly requested.
  • Do not replace temporary OIDC-based publishing with persistent API keys without explicit scope and security review.
  • Do not remove restore/build/test/pack/package validation to reduce CI time without a documented replacement.
  • Do not change package IDs, package count checks, version guards, artifact manifests, checksums, provenance, or rollback behavior incidentally.
  • Do not assume administrative settings such as environments, repository variables, rulesets, trusted publishing policies, or secrets exist beyond what workflows reference.

Quality Bar

A good automation change matches the current repository, uses minimum permissions, keeps versioning and package identity explicit, validates before publication, preserves provenance and recovery paths, fails diagnostically, and documents only real capabilities.

© rodri-oliveira-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/ci-release-governance of rodri-oliveira-dev/Dapper-FluentMap.

Open the folder on GitHubat commit 4f5a39f

Compare with similar skills

CI Release Governance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CI Release Governance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CI Release Governance this skillrodri-oliveira-dev/Dapper-FluentMap453—~1.8kAutomated safety check: PassMIT
Nushellccusage/ccusage19k—~938Automated safety check: PassCustom licence
Make GitHub Actions Workflowdotnet/efcore15k—~2.1kAutomated safety check: PassMIT
AI News RadarLearnPrompt/ai-news-radar1.8k—~2.5kAutomated safety check: NotesMIT
Clawsweeperopenclaw/openclaw392k—~3kAutomated safety check: PassMIT
ONNX Runtime CI Managementmicrosoft/onnxruntime22k—~4.1kAutomated safety check: PassMIT

Similar skills

  • Nushell

    ccusage/ccusage

    Guides ccusage Nushell scripts. An agent skill from ccusage/ccusage.

    19k GitHub stars~938 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Official

    Create GitHub Actions workflows for CI, automation, or PR management.

    15k GitHub stars~2.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AI News Radar

    LearnPrompt/ai-news-radar

    A skill your agent uses when working on AI News Radar, 24 小时 AI 更新雷达, AI 更新雷达, 伯乐Skill, or Scout Skill: finding high-signal AI/tech sources, adding RSS/OPML/GitHub feeds, checking source health…

    1.8k GitHub stars~2.5k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Clawsweeper

    openclaw/openclaw

    A skill your agent uses for all ClawSweeper work: OpenClaw issue/PR sweep reports, repair jobs, cloud fix PRs, @clawsweeper maintainer mention commands, trusted ClawSweeper-reviewed…

    392k GitHub stars~3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • ONNX Runtime CI Management

    microsoft/onnxruntime

    Official

    Triggers, re-runs and unblocks the CI checks on an ONNX Runtime pull request, after diagnosing whether a failure is transient or needs a code change.

    22k GitHub stars~4.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • CI Watchdog

    latitude-dev/latitude-llm

    Continuously monitor GitHub PR CI checks and automatically fix failures until all checks pass.

    4.7k GitHub stars~1.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from rodri-oliveira-dev/Dapper-FluentMap

All 11 skills in this repo
  • Directory Build Organization

    rodri-oliveira-dev/Dapper-FluentMap

    Guide for organizing MSBuild infrastructure with Directory.Build.props, Directory.Build.targets, Directory.Packages.props when present, and related repository build files.

    453 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Microbenchmarking

    rodri-oliveira-dev/Dapper-FluentMap

    Activate when BenchmarkDotNet is involved or when a .NET performance question requires controlled microbenchmark measurement.

    453 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Nuget Trusted Publishing

    rodri-oliveira-dev/Dapper-FluentMap

    Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions.

    453 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Test Gap Analysis

    rodri-oliveira-dev/Dapper-FluentMap

    Pseudo-mutation analysis for behavioral blind spots: determine whether existing tests would catch meaningful caller-visible production changes, identify survivors or untested outcomes, and…

    453 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Authoring GitHub Workflows

    rodri-oliveira-dev/Dapper-FluentMap

    Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run.

    453 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Binlog Failure Analysis

    rodri-oliveira-dev/Dapper-FluentMap

    Analyze MSBuild binary logs to diagnose build failures. An agent skill from rodri-oliveira-dev/Dapper-FluentMap.

    453 GitHub stars~750 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about CI Release Governance

What does CI Release Governance do?

A skill your agent uses to review or adjust Dapper-FluentMap GitHub Actions, packaging, NuGet publishing, versioning, release, rollback, recovery, provenance, and automation security. CI Release Governance is an agent skill from rodri-oliveira-dev/Dapper-FluentMap. Use this skill to review or adjust Dapper-FluentMap GitHub Actions, packaging, NuGet publishing, versioning, release, rollback, recovery, provenance, and automation security.

When should I use CI Release Governance?

CI Release Governance fits situations like: adjust Dapper-FluentMap GitHub Actions; nuGet publishing; automation security; production code changes without pipeline impact.

How do I install CI Release Governance in Claude Code?

Run `npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill ci-release-governance -a claude-code`. Or copy the skill folder (.agents/skills/ci-release-governance in rodri-oliveira-dev/Dapper-FluentMap) into .claude/skills/ci-release-governance in your project. Claude Code loads it when a task matches its description.

How do I install CI Release Governance in Codex?

Run `npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill ci-release-governance -a codex`. Or copy the skill folder (.agents/skills/ci-release-governance in rodri-oliveira-dev/Dapper-FluentMap) into .agents/skills/ci-release-governance in your project. Codex loads it when a task matches its description.

Can I use CI Release Governance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill ci-release-governance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ci-release-governance, .gemini/skills/ci-release-governance, .github/skills/ci-release-governance and .opencode/skills/ci-release-governance in your project.

What does CI Release Governance need to run?

Going by SKILL.md and its folder, CI Release Governance needs the command-line tools its instructions call (dotnet and rg) and credentials named SONAR_TOKEN. Our summary lists: A credential in SONAR_TOKEN.

Does CI Release Governance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is CI Release Governance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does CI Release Governance use?

CI Release Governance is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does CI Release Governance use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to CI Release Governance?

Skills that share tags, products or a category with CI Release Governance: Nushell (ccusage/ccusage, 19k stars), Make GitHub Actions Workflow (dotnet/efcore, 15k stars), AI News Radar (LearnPrompt/ai-news-radar, 1.8k stars) and Clawsweeper (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CI Release Governance?

rodri-oliveira-dev (a GitHub user) maintains it in rodri-oliveira-dev/Dapper-FluentMap, which has 453 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 8, 2026.

Source: rodri-oliveira-dev/Dapper-FluentMap on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.