ClickUp CLI Release Process
krodak/clickup-cli
Walks through releasing a new version of clickup-cli: pre-release checks, version bump, tagging, CI watch, release notes and the Homebrew update.
Cuts a tagged mecatl release by dispatching the release-PR workflow, merging the bot's pull request and verifying the tag, images, Helm chart, signed archives and Homebrew formula.
$ npx skills add stacklok/mecatl --skill cut-release -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install stacklok/mecatl cut-release --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/stacklok/mecatl.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/cut-release .claude/skills/cut-release && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cut-release" agent skill from https://github.com/stacklok/mecatl/tree/main/.claude/skills/cut-release into .claude/skills/cut-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cut-release", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/stacklok/mecatl/tree/main/.claude/skills/cut-releaseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add stacklok/mecatl --skill cut-release -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install stacklok/mecatl cut-release --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stacklok/mecatl.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/cut-release .agents/skills/cut-release && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cut-release" agent skill from https://github.com/stacklok/mecatl/tree/main/.claude/skills/cut-release into .agents/skills/cut-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cut-release", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add stacklok/mecatl --skill cut-release -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install stacklok/mecatl cut-release --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stacklok/mecatl.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/cut-release .cursor/skills/cut-release && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cut-release" agent skill from https://github.com/stacklok/mecatl/tree/main/.claude/skills/cut-release into .cursor/skills/cut-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cut-release", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/stacklok/mecatl.git --path .claude/skills/cut-release--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add stacklok/mecatl --skill cut-release -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install stacklok/mecatl cut-release --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stacklok/mecatl.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/cut-release .gemini/skills/cut-release && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cut-release" agent skill from https://github.com/stacklok/mecatl/tree/main/.claude/skills/cut-release into .gemini/skills/cut-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cut-release", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install stacklok/mecatl cut-releaseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add stacklok/mecatl --skill cut-release -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/stacklok/mecatl.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/cut-release .github/skills/cut-release && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cut-release" agent skill from https://github.com/stacklok/mecatl/tree/main/.claude/skills/cut-release into .github/skills/cut-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cut-release", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add stacklok/mecatl --skill cut-release -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install stacklok/mecatl cut-release --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stacklok/mecatl.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/cut-release .opencode/skills/cut-release && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cut-release" agent skill from https://github.com/stacklok/mecatl/tree/main/.claude/skills/cut-release into .opencode/skills/cut-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cut-release", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cut-releaseCuts a tagged mecatl release by dispatching the release-PR workflow, merging the bot's pull request and verifying the tag, images, Helm chart, signed archives and Homebrew formula.
A mecatl release is a version tag. Pushing it triggers the release workflow, which publishes signed container images, Helm charts, microVM and Brood Box artifacts, a GitHub Release with darwin and linux CLI archives for amd64 and arm64, checksums, cosign bundles, SBOMs and build provenance, and a formula bump in the public Homebrew tap. No version is baked into the Go code. Nothing pushes to `main` directly: you dispatch a workflow, a bot opens the release PR, a human merges it and a bot tags the merge commit, so the agent never pushes main or creates the tag by hand.
The root `VERSION` file, in bare semver form, is the source of truth and the release PR propagates it to the chart version, app version and default image tag. A published tag is treated as immutable because the Homebrew formula records archive checksums, so a bad release after the tap commit is fixed forward with the next patch version, and re-tagging is allowed only if the run failed before publishing. Release-only inputs are validated before tagging, not with a throwaway tag. The excerpt is cut off in a section about composite action pins.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e731897. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgitbrewgoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENRELEASE_APP_PRIVATE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Mecatl Release Cutting loads about 4k tokens when it runs. Until then it costs about 101 tokens; SKILL.md has 2,050 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from stacklok/mecatl at commit e731897, republished under its Apache-2.0 licence (© stacklok). 2,050 words, ~4,013 tokens.
.claude/skills/cut-release/SKILL.md (or your agent's skills folder).A release is a vX.Y.Z git tag. Pushing that tag triggers .github/workflows/release.yml,
which publishes signed images (mecated, mecatui, mecak8s, execution provider/workload,
Studio, and the Slack-bot example), Helm charts, and versioned microVM and Brood Box
artifacts. It also publishes a GitHub Release carrying darwin/linux x
amd64/arm64 CLI archives, a checksums.txt, cosign bundles, SBOMs, and build
provenance, and pushes a mecatl formula bump to the public stacklok/homebrew-tap
repository. There is no version baked into the Go code — the tag IS the release.
Two consequences of the Homebrew half, before you start:
vX.Y.Z that already produced
a release and a tap commit leaves the tap pointing at checksums that no longer match, which
breaks brew install for everyone. If a release goes wrong after the tap commit lands,
fix forward with the next patch version. Re-tagging is only an option when the run failed
before publishing anything.task release:snapshot && task release:verify only checks CLI archives and
Homebrew packaging; it does not prove the container publishing jobs work.Nothing pushes a commit to main. The release runs through an ordinary pull request:
you dispatch a workflow, a bot opens the PR, a human merges it, and a bot tags the merge
commit. You never run git push origin main, and you never create the tag by hand.
VERSION (repo root, bare semver — 0.0.34, not v0.0.34) is the source of truth
for the release version. The release PR propagates it to the mecak8s chart version,
appVersion, and default image tag. The workflows verify those values directly rather
than maintaining a fixed list of files that a release PR may change.
It did not used to be. mecatequi-reusable.yml referenced its three sibling composite actions
by a hardcoded @vX.Y.Z literal, so every release had to bump those pins in the same tagged
commit or ship version skew. That self-reference — a file naming a tag that does not exist yet —
is why a release needed a commit on main at all. The pins are now $/ self-repository refs,
which resolve to this repo at the exact ref the workflow is running from, so there is nothing
left to bump and skew is impossible rather than merely policed.
Run from the repo root.
Confirm what you're shipping. The release tags whatever is on main when the release PR
merges. Review what has landed since the last tag:
git tag --sort=-v:refname --list 'v*' | head -1 # e.g. v0.0.33
git log <last-tag>..origin/main --onelineConfirm the bump type with the operator before dispatch; patch is the established
release cadence even when the range includes additive changes. Do not infer a
minor bump from commit subjects alone.
Dispatch the release-PR workflow. This is the only step that starts a release:
gh workflow run create-release-pr.yml -f bump_type=patch
gh run watch "$(gh run list --workflow=create-release-pr.yml --limit 1 --json databaseId --jq '.[0].databaseId')"The workflow validates the tracked ARG defaults in
build/execution-provider/Dockerfile and build/execution-workload/Dockerfile
on main: the Go builder, static provider runtime, and Brood Box workload
runtime must have tagged digest pins available for Linux amd64 and arm64;
it also builds both images without publishing. The tag workflow repeats the
pin and availability validation on the merged commit before tagging. Renovate
updates the pins through its native Dockerfile manager; no image repository
variables are required.
If validation fails, fix the tracked pins through review (or retry a transient
registry failure); do not bypass the check. The publishing job validates the
tagged checkout again. The workflow bumps
VERSION, the mecak8s chart version and app version, and the chart's default
image tag. It opens Release vX.Y.Z from branch release/vX.Y.Z, then asserts that the
required values are synchronized. If that verification step fails, do not merge the PR;
close it, delete the branch, and read the job log.
Review the release PR like any other PR and confirm that all changes belong to the release update:
gh pr list --head "release/vX.Y.Z" --json number,url,files
gh pr diff <number>Wait for CI to go green. The PR is opened by the release GitHub App, so it triggers checks normally.
Squash-merge it. A human does this — it is the approval gate, and it is the only way
VERSION changes on main:
gh pr merge <number> --squashThe tagging workflow does not read the commit subject — it asks GitHub which PR produced
the commit and requires a merged, bot-opened PR from branch release/vX.Y.Z with matching
version values. The squash title and the number of updated files do not affect the tag gate.
Watch the tag get created. Merging fires create-release-tag.yml, which re-verifies the
commit and pushes the annotated tag. That push fires release.yml on its own — the tag is
pushed by a GitHub App installation token precisely so the cascade happens, where a
GITHUB_TOKEN-pushed tag would trigger nothing:
gh run watch "$(gh run list --workflow=create-release-tag.yml --limit 1 --json databaseId --jq '.[0].databaseId')"
git fetch --tags && git tag --sort=-v:refname --list 'v*' | head -1Confirm the release run started, then wait for every publishing job. A
successful CLI archive or one green image is not a complete release. In
particular, check the mecated, execution provider/workload, Brood Box
resolution, microVM, chart, and CLI/Homebrew jobs before reporting success:
gh run list --workflow=release.yml --limit 3
gh run watch "$(gh run list --workflow=release.yml --limit 1 --json databaseId --jq '.[0].databaseId')"Verify the GitHub Release carries every artifact. It must not be a draft, and it must
have four archives plus a checksum file, with a cosign bundle and an SBOM alongside each.
Also require brood-base-index.json, brood-platforms.json, and the
microvm-default-*.json completion assets for each platform. Missing assets
mean the release is incomplete even if the CLI archives are available:
gh release view vX.Y.Z --json isDraft,assets --jq '{draft: .isDraft, assets: [.assets[].name]}'Then prove one archive is actually usable rather than trusting the asset list. Use the
repo-local .scratch/ dir, never /tmp (AGENTS.md):
mkdir -p .scratch/release-vX.Y.Z
gh release download vX.Y.Z -p 'checksums.txt' -p '*darwin_arm64*' -D .scratch/release-vX.Y.Z
(cd .scratch/release-vX.Y.Z \
&& shasum -a 256 -c checksums.txt --ignore-missing \
&& tar -xzf mecatl_*_darwin_arm64.tar.gz \
&& ./mecatui --version && ./mecated --version)Both --version lines must print the tag you just cut. A dev+<revision> output means the
release build lost its BUILD_ID linker stamp — a release bug, not a cosmetic one, because
the public install docs claim a released binary reports its tag.
If the run died between "release created" and "assets uploaded" it leaves a DRAFT, which
a lookup by tag does not return, so a naive re-run fails trying to create the release again.
Recover with gh release delete vX.Y.Z --cleanup-tag=false --yes, then re-dispatch.
Verify the Homebrew tap got the formula bump:
gh api repos/stacklok/homebrew-tap/commits --jq '.[0].commit.message'
gh api repos/stacklok/homebrew-tap/contents/Formula/mecatl.rb --jq '.content' \
| base64 -d | grep -E 'version|url|sha256' | headThe top commit must name the version you just cut, and the formula's url and sha256
values must match the release assets from step 7.
While stacklok/mecatl is private, brew install stacklok/tap/mecatl fails even after a
correct tap commit: Homebrew's downloader does not authenticate, so it cannot fetch a release
archive from a private repository. The tap commit landing is the whole verification until the
repository goes public; this is known and accepted. Once it is public, run the real
end-to-end check once:
brew update && brew install stacklok/tap/mecatl && mecatui --versionThe vX.Y.Z release above is the root repo / mecated image release. The importable
core, github.com/stacklok/mecatl/engine, is its own Go module (ADR 0036) with its own
tag grammar engine/vX.Y.Z (distinct from the root tags). It carries a public-API
compatibility contract (engine/COMPATIBILITY.md, ADR 0037).
engine/vX.Y.Z tag is engine/v0.0.1 — a deliberate "earliest, no stability
promise" initial cut (the lowest pre-v1 patch, signalling zero stability commitment for the very
first published surface). Cutting it is a deliberate maintainer decision (deferred per ADR 0037) —
do NOT cut it as part of a routine root release unless asked. The grammar is engine/vX.Y.Z,
distinct from the root vX.Y.Z tags; the two version lines are independent. SUBSEQUENT bumps
follow engine/COMPATIBILITY.md (pre-v1: minor = additive, patch = fixes).Run from the repo root.
Pick the engine version. First cut = engine/v0.0.1 (a deliberate "earliest, no stability
promise" initial cut); thereafter increment per semver, classified per engine/COMPATIBILITY.md
(pre-v1: Added = minor, Changed/Removed = minor too; patch = fixes). The latest engine tag (none
yet on the first cut):
git tag --sort=-v:refname --list 'engine/v*' | head -1Pre-flight. Confirm engine/CHANGELOG.md has an [Unreleased] entry covering everything
since the last engine tag (on the first cut that is the whole initial surface — the existing
[Unreleased] baseline section). Then run the advisory gorelease check:
task api:release-checkOn the FIRST cut this is a no-op / uninformative: gorelease can only classify the surface
against a prior engine/vX.Y.Z base tag, and none exists yet — so it has nothing to compare
to. That is expected. The authoritative guard is the api-compat gate (task api:check), which
already guarantees the committed engine/api/*.txt snapshots match the surface being tagged.
Create the annotated tag with a concise summary:
git tag -a engine/vX.Y.Z -m "engine/vX.Y.Z — <one-line summary>"Push the tag:
git push origin engine/vX.Y.ZThis line is deliberately still manual. An engine tag adds no commit to main and carries
no pin bump, so it never needed the release-PR flow the root vX.Y.Z line uses — pushing the
tag is the whole release.
IMPORTANT — an engine tag fires NO image build, NO GitHub Release, and NO Homebrew formula bump. release.yml triggers on v* (the root tag
glob), which does not match engine/v*, so cutting an engine tag runs none of the ko build /
cosign / SBOM / SLSA pipeline. It only publishes the module version, making it resolvable for
go get github.com/stacklok/mecatl/engine@engine/vX.Y.Z consumers (ADR 0036/0037). There is no pin
bump and no release.yml run to confirm — the push of the tag is the whole release.
gh run list line is not proof that
brew install works.stacklok/homebrew-tap. The formula is generated from the tag by the
release workflow and carries a DO NOT EDIT header. A manual edit is overwritten by the next
release and desynchronizes the checksums in the meantime.main, and never create a root vX.Y.Z tag by hand. Both are the
workflows' job. A hand-pushed version bump skips code review, and a hand-created tag can point
at a commit whose release metadata the gate rejects. If VERSION is edited on main outside a
release PR, create-release-tag.yml refuses to tag it rather than cutting a release from it.
release.yml's guard job additionally refuses to publish anything from a tag that is
not an ancestor of main, so a tag cut on a branch builds nothing. (This applies to the ROOT
v* line only — the engine/v* tags below are still cut by hand, deliberately: they carry
no pin bump and add no commit to main.)git tag -a), matching prior releases — they carry a tagger + message.
create-release-tag.yml does this; the tagger is github-actions[bot].@vX.Y.Z examples in
user-docs/building/deployment/mecatequi.md are illustrative and do NOT gate the release. The
release flow deliberately leaves them alone.create-release-pr.yml verifies
the bump before the PR can merge, and create-release-tag.yml tags only the merge commit. It
means someone tagged by hand or the chart metadata drifted from VERSION. Fix forward with a
patch.create-release-tag.yml makes one decision from the tag's state and
the commit's provenance, so it is quiet when there is nothing to do (the tag already points
here, or VERSION names an already-released tag this commit did not produce) and loud only
when a tag should have been created and something is wrong. release.yml re-signs
idempotently via its workflow_dispatch tag input.release GitHub
Environment (vars.RELEASE_APP_CLIENT_ID, secrets.RELEASE_APP_PRIVATE_KEY), whose
deployment-branch policy must be restricted to main. The App needs exactly two repository
permissions — Contents: write and Pull requests: write. It does NOT need Workflows: write,
because a release no longer edits anything under .github/workflows/. Repo-level secrets would let anyone
with push access dispatch a modified workflow from a branch and mint the App credential.release/v* PR is open, the next dispatch refuses and names
it — merge or close it first. Once none is open, leftover release/v* branches from failed
runs are deleted automatically before the new PR is cut.© stacklok, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/cut-release of stacklok/mecatl.
Open the folder on GitHubat commit e731897
Mecatl Release Cutting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Mecatl Release Cutting this skillstacklok/mecatl | 218 | — | ~4k | Automated safety check: Pass | Apache-2.0 | |
| ClickUp CLI Release Processkrodak/clickup-cli | 120 | — | ~906 | Automated safety check: Warn | MIT | |
| OpenWork Release Processdifferent-ai/openwork | 24k | — | ~2.3k | Automated safety check: Pass | Custom licence | |
| ccLoad Release Publishercaidaoli/ccLoad | 417 | — | ~887 | Automated safety check: Pass | MIT | |
| AnyDrag Release RoutineXueshiQiao/AnyDrag | 227 | — | ~2.6k | Automated safety check: Pass | GPL-3.0 | |
| Kt Search Releasejillesvangurp/kt-search | 155 | — | ~1.2k | Automated safety check: Pass | MIT |
krodak/clickup-cli
Walks through releasing a new version of clickup-cli: pre-release checks, version bump, tagging, CI watch, release notes and the Homebrew update.
different-ai/openwork
Cuts an OpenWork desktop release through a tag-driven GitHub Actions workflow that makes no commits, with pre-tag checks on open fix PRs and verification afterward.
caidaoli/ccLoad
Publishes a ccLoad Beta or explicit stable release through a version-tag workflow, including commit, push, CI wait, GitHub Release and container image checks.
XueshiQiao/AnyDrag
Runs the full AnyDrag release process end to end, from cumulative bilingual release notes through version bumping to watching CI and the Homebrew cask update.
jillesvangurp/kt-search
A skill your agent uses when the user wants to cut, publish, tag, or create a GitHub release for kt-search, especially when the task includes version bumping, validating that commits are pushed…
computerlovetech/agr
Release process for the agr package. An agent skill from computerlovetech/agr.
stacklok/mecatl
Interviews you about provider, cost, openness and image needs, then designs the models section of a mecatl settings file with aliases, slots and router categories.
stacklok/mecatl
Runs mecatl's offline benchmark and scenario harness to measure, profile with pprof, optimize and prove a performance win with benchstat, then adds a regression benchmark.
stacklok/mecatl
Designs, validates and writes the learning section of a mecatl settings file, covering mode, sensitivity, reflection budgets and validated or evaluated activation.
stacklok/mecatl
Guides reading mecatl's perf MCP data to find why a running harness is slow, leaking goroutines or growing in memory, using cheap reads before any CPU capture.
stacklok/mecatl
Rebuilds the mecak8s image into the local mecatl-dev Kind cluster and builds mecatui, so you can try in-progress mecatl changes against a real Kubernetes deployment.
stacklok/mecatl
Review completed non-trivial code across four independent axes: Spec, Standards, Test adequacy, and installed Domain specialists.
Categories
Cuts a tagged mecatl release by dispatching the release-PR workflow, merging the bot's pull request and verifying the tag, images, Helm chart, signed archives and Homebrew formula. A mecatl release is a version tag. Pushing it triggers the release workflow, which publishes signed container images, Helm charts, microVM and Brood Box artifacts, a GitHub Release with darwin and linux CLI archives for amd64 and arm64, checksums, cosign bundles, SBOMs and build provenance, and a formula bump in the public Homebrew tap.
Mecatl Release Cutting fits situations like: cutting or shipping a new mecatl release; verifying the tag, images and Homebrew bump after a release run; deciding how to recover from a release that failed after publishing.
Run `npx skills add stacklok/mecatl --skill cut-release -a claude-code`. Or copy the skill folder (.claude/skills/cut-release in stacklok/mecatl) into .claude/skills/cut-release in your project. Claude Code loads it when a task matches its description.
Run `npx skills add stacklok/mecatl --skill cut-release -a codex`. Or copy the skill folder (.claude/skills/cut-release in stacklok/mecatl) into .agents/skills/cut-release in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add stacklok/mecatl --skill cut-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cut-release, .gemini/skills/cut-release, .github/skills/cut-release and .opencode/skills/cut-release in your project.
Going by SKILL.md and its folder, Mecatl Release Cutting needs the command-line tools its instructions call (gh, git, brew and go) and credentials named GITHUB_TOKEN and RELEASE_APP_PRIVATE_KEY. Our summary lists: The mecatl repository and its release workflows; GitHub access to dispatch workflows and merge pull requests.
SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Mecatl Release Cutting is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Mecatl Release Cutting: ClickUp CLI Release Process (krodak/clickup-cli, 120 stars), OpenWork Release Process (different-ai/openwork, 24k stars), ccLoad Release Publisher (caidaoli/ccLoad, 417 stars) and AnyDrag Release Routine (XueshiQiao/AnyDrag, 227 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
stacklok (a GitHub organization) maintains it in stacklok/mecatl, which has 218 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 6, 2026.
Source: stacklok/mecatl on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.