Publish this plugin to npm - a production release, a pre-release, or an experimental build from a branch.

MITAuto-check passedDevelopment

Install Cut A Release

skills CLI
$ npx skills add strapi-community/plugin-rest-cache --skill cut-a-release -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install strapi-community/plugin-rest-cache cut-a-release --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/strapi-community/plugin-rest-cache.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/cut-a-release .claude/skills/cut-a-release && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cut-a-release
GitHub stars
155
Token cost
~2.2k tokens
SKILL.md length
1,253 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Publish this plugin to npm - a production release, a pre-release, or an experimental build from a branch.

  • Works in 5 steps: Merge work to main using conventional… → Review that PR. The version comes from… → Merge it. release-please tags and… → …
  • Shipping a release
  • SKILL.md covers The pieces, Production release, Pre-release and Moving off a prerelease version, plus 5 more sections
  • Calls npm and pnpm; needs GITHUB_TOKEN

What it does

Cut A Release is an agent skill from strapi-community/plugin-rest-cache. Publish this plugin to npm - a production release, a pre-release, or an experimental build from a branch. Use when preparing or shipping a release, updating the changelog, or debugging the publish workflow.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Changelog and release notes. It works with npm. The repository describes itself as: Speed-up HTTP requests with LRU cache. The licence is MIT.

When your agent uses it

  • Shipping a release
  • Updating the changelog
  • Debugging the publish workflow

Example prompts

  • “/cut-a-release”

Requirements

  • Node.js
  • A credential in GITHUB_TOKEN

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Merge work to main using conventional commits. release-please keeps a
  2. Review that PR. The version comes from the commit types since the last
  3. Merge it. release-please tags and creates draft Releases.
  4. Go to Releases, review, press Publish release.
  5. publish.yml starts and waits on the npm-latest environment. A maintainer

What it can do on your machine

Read from SKILL.md and the folder at commit af0e7d8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cut A Release loads about 2.2k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 1,253 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from strapi-community/plugin-rest-cache at commit af0e7d8, republished under its MIT licence (© strapi-community). 1,253 words, ~2,204 tokens.

Download SKILL.mdSave it as .claude/skills/cut-a-release/SKILL.md (or your agent's skills folder).
name
cut-a-release
description
Publish this plugin to npm - a production release, a pre-release, or an experimental build from a branch. Use when preparing or shipping a release, updating the changelog, or debugging the publish workflow.

Cutting a release

Publishing is always manual. There is no trigger that publishes on merge, and there must never be one. Two humans gates stand in front of npm: pressing "Publish release" on a draft, and approving the deployment environment.

The pieces

release-please.ymlWatches main, maintains one rolling release PR, and creates draft GitHub Releases. Publishes nothing.
publish.ymlThe only thing that talks to npm. Never fires on merge.
release-please-config.jsonChangelog sections, package list, draft: true.
.release-please-manifest.jsonCurrent version per package. release-please owns this; do not hand-edit.

Production release

  1. Merge work to main using conventional commits. release-please keeps a chore: release X.Y.Z PR up to date, with the changelog grouped by change type.
  2. Review that PR. The version comes from the commit types since the last release — feat gives a minor, fix a patch, ! or a BREAKING CHANGE: footer a major. If the proposed version is wrong, the commit messages are wrong; fix them rather than editing the version.
  3. Merge it. release-please tags and creates draft Releases.
  4. Go to Releases, review, press Publish release.
  5. publish.yml starts and waits on the npm-latest environment. A maintainer approves. It packs and publishes to the latest tag.

The draft step is not ceremony: a Release created by GITHUB_TOKEN does not trigger other workflows, so an auto-published one would silently never reach npm.

Pre-release

release-please only ever proposes stable versions. A beta is not something it produces, and there is deliberately no prerelease mode in its config - that made every ordinary release a beta and left the repository unable to reach a stable version without a Release-As: override.

So a beta is a manual dispatch. Run the publish workflow from the Actions tab, with the branch selector on main:

  • mode: next
  • version: the exact version, e.g. 5.2.0-beta.0
  • target_branch: the branch to build, defaults to main

It stamps that version across all three packages, builds, and publishes to the next dist-tag through the npm-prerelease environment. Users install it with npm install @strapi-community/plugin-rest-cache@next.

version must carry a prerelease suffix. scripts/stamp-version.mjs refuses a stable version, so no dispatch can put one on npm - stable versions come only from release-please and the version already committed to package.json.

Nothing is tagged and no GitHub Release is created: a dispatched beta is a build of a branch, not a point in the release history. The run summary records the commit.

If a GitHub Release is marked as a pre-release and published, that also routes to next - publish.yml reads github.event.release.prerelease. That path publishes the version release-please committed, and never stamps over it.

Moving off a prerelease version

If the last release was a prerelease, release-please will not graduate on its own. The default versioning strategy keeps the suffix, so 5.1.0-beta plus a fix: becomes 5.1.1-beta, not 5.1.0.

Land a commit on main whose message carries the version as a footer:

chore: graduate to a stable release

Release-As: 5.1.0

It applies to that one release and leaves nothing behind in the config.

Note where the footer has to be. GitHub builds a squash commit from the pull request title and body only when the branch has more than one commit; with a single commit it uses that commit's own message. A footer written in the pull request description is silently dropped in that case, and the next release comes out as another prerelease.

Experimental build from a pull request

The easy path. Add the publish-experimental label to a pull request. It publishes 0.0.0-experimental.<pr head sha> to the experimental dist-tag and comments on the PR with the exact install command.

The workflow then removes the label again, including when the publish failed. The label is a one-shot request, not a mode: to cut another build after pushing more commits, add it back. It deliberately no longer fires on synchronize, which used to republish silently on every push for as long as the label happened to still be attached.

Same-repo pull requests only; a fork PR never reaches the publish job.

Experimental build from a branch

When there is no pull request, or you want a specific branch.

Run the publish workflow from the Actions tab:

  • keep the branch selector on main — this matters, see below;
  • mode: experimental;
  • target_branch: the branch to build.

It publishes 0.0.0-experimental.<sha> to the experimental dist-tag. Install by exact version, not by tag — the tag is clobbered by the next experimental build:

bash
npm install @strapi-community/plugin-rest-cache@0.0.0-experimental.<sha>
Show full SKILL.md (535 more words)Show less
Why the branch selector must stay on main, and why the PR trigger is pull_request_target

npm trusted publishing is not branch-scoped. It checks the repository, the workflow filename and the environment, and discards the ref. Since workflow_dispatch runs the workflow file from the branch you pick, choosing a feature branch would hand that branch's own YAML a publish-capable token — and npm publish defaults to --tag latest.

The label trigger has the same problem in a different shape: plain pull_request would run the PR branch's copy of the workflow, with publish credentials in scope. That is what Strapi's own experimental workflow does, and it is a real accepted risk on their side. This one uses pull_request_target, which runs the workflow file as it exists on the default branch, so neither the environment gate nor the version assertion can be edited by the branch being published.

The usual pull_request_target trap - checking out untrusted code in a job holding secrets - does not apply here, because the build job holds neither secrets nor an id-token.

So the workflow takes the branch as an input instead. The build job checks it out but has no id-token and no environment; the publish job runs from main's YAML and asserts the version matches 0.0.0-experimental.<40 hex> before publishing. Both halves are needed: without the assertion, a poisoned build could stamp 5.99.0, which every ^5.0.0 range would resolve regardless of dist-tag.

Things that will break a release

Everything publishing lives in publish.yml and must stay there. npm validates the workflow filename and allows only one trusted-publisher config per package, so a second publishing workflow file would fail authentication.

Never npm publish from a package directory. npm does not understand the workspace: protocol and would publish workspace:* literally, producing a manifest nobody can install. The workflow runs pnpm pack first and publishes the tarball. The plugin depends on the memory provider this way, so this affects the primary package.

The build must run before packing, and in order. The providers typecheck against the plugin's emitted declarations, so pnpm run build builds the plugin first, then the providers. files is ["dist"] — an unbuilt package publishes an empty directory.

Node 24 or newer in the publish job. Trusted publishing needs npm ≥ 11.5.1 and no Node 22 release ships one.

If a publish fails

  • Waiting for approval — expected. Someone with reviewer rights approves the deployment.
  • 401/403 from npm — the trusted publisher config on npmjs.com does not match this workflow's filename or environment name. Both are exact, case-sensitive strings.
  • ERESOLVE installing an experimental build — the internal peer ranges were not rewritten. scripts/stamp-experimental-version.mjs pins them to the exact experimental version because a ^5.x peer cannot satisfy 0.0.0-*.
  • Version assertion failed — the build produced a version that does not match the mode. Treat this as a real signal, not a check to relax.

Never

  • Add a trigger that publishes on a push to a branch, or on a merge. The labelled-PR trigger is deliberate and only ever produces 0.0.0-experimental builds; nothing may reach the latest tag without a human pressing publish.
  • Change the PR trigger from pull_request_target to pull_request.
  • Give the build job id-token: write, an environment, or any secret.
  • Remove the version-shape assertion.
  • Add a second workflow file that publishes.

© strapi-community, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/cut-a-release of strapi-community/plugin-rest-cache.

Open the folder on GitHubat commit af0e7d8

Compare with similar skills

Cut A Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cut A Release compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cut A Release this skillstrapi-community/plugin-rest-cache155—~2.2kAutomated safety check: PassMIT
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Hunk Release Workflowmodem-dev/hunk9.6k—~3.8kAutomated safety check: PassMIT
Version ReleaseNG-ZORRO/ng-zorro-antd9.2k—~3.1kAutomated safety check: PassMIT
AionUi Version BumpiOfficeAI/AionUi33k—~2.1kAutomated safety check: PassApache-2.0

Similar skills

  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Hunk Release Workflow

    modem-dev/hunk

    Maintainer workflow for preparing, publishing, verifying and curating Hunk releases, with confirmation gates before tags, publishes and public edits.

    9.6k GitHub stars~3.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Version Release

    NG-ZORRO/ng-zorro-antd

    NG-ZORRO/ng-zorro-antd repository release workflow. An agent skill from NG-ZORRO/ng-zorro-antd.

    9.2k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed
  • AionUi Version Bump

    iOfficeAI/AionUi

    Automates an AionUi release: checks the latest AionCore release and its artifacts, updates package.json, writes the changelog, opens a PR and tags the release.

    33k GitHub stars~2.1k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Release Round

    ethereumjs/ethereumjs-monorepo

    Runs a coordinated EthereumJS npm release round in six human-gated phases — intent and readiness, CHANGELOG, version bump, publish (human executes), post-publish verification, and announcements.

    2.8k GitHub stars~2k tokensUpdated 20 days ago
    DevelopmentAuto-check passed

More from strapi-community/plugin-rest-cache

  • Add A Provider

    strapi-community/plugin-rest-cache

    Add a new cache provider package to this repository, or modify an existing one.

    155 GitHub stars~960 tokensUpdated 11 days ago
    Auto-check passed
  • Configure REST Cache

    strapi-community/plugin-rest-cache

    Choose and write a Strapi REST Cache configuration for a specific use case.

    155 GitHub stars~1.1k tokensUpdated 11 days ago
    Auto-check passed
  • Diagnose REST Cache

    strapi-community/plugin-rest-cache

    Diagnose why Strapi REST Cache is not caching, is serving stale content, or is caching the wrong thing.

    155 GitHub stars~1.2k tokensUpdated 11 days ago
    Auto-check passed
  • Verify A Change

    strapi-community/plugin-rest-cache

    Verify a change to this plugin before opening a PR. An agent skill from strapi-community/plugin-rest-cache.

    155 GitHub stars~779 tokensUpdated 11 days ago
    Auto-check passed

Works with

Categories

Questions about Cut A Release

What does Cut A Release do?

Publish this plugin to npm - a production release, a pre-release, or an experimental build from a branch. Cut A Release is an agent skill from strapi-community/plugin-rest-cache. Publish this plugin to npm - a production release, a pre-release, or an experimental build from a branch.

When should I use Cut A Release?

Cut A Release fits situations like: shipping a release; updating the changelog; debugging the publish workflow.

How do I install Cut A Release in Claude Code?

Run `npx skills add strapi-community/plugin-rest-cache --skill cut-a-release -a claude-code`. Or copy the skill folder (.claude/skills/cut-a-release in strapi-community/plugin-rest-cache) into .claude/skills/cut-a-release in your project. Claude Code loads it when a task matches its description.

How do I install Cut A Release in Codex?

Run `npx skills add strapi-community/plugin-rest-cache --skill cut-a-release -a codex`. Or copy the skill folder (.claude/skills/cut-a-release in strapi-community/plugin-rest-cache) into .agents/skills/cut-a-release in your project. Codex loads it when a task matches its description.

Can I use Cut A Release in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add strapi-community/plugin-rest-cache --skill cut-a-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cut-a-release, .gemini/skills/cut-a-release, .github/skills/cut-a-release and .opencode/skills/cut-a-release in your project.

What does Cut A Release need to run?

Going by SKILL.md and its folder, Cut A Release needs the command-line tools its instructions call (npm and pnpm) and credentials named GITHUB_TOKEN. Our summary lists: Node.js; A credential in GITHUB_TOKEN.

Does Cut A Release access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cut A Release safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cut A Release use?

Cut A Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cut A Release use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cut A Release?

Skills that share tags, products or a category with Cut A Release: Cutting A Release (TriliumNext/Trilium, 38k stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars), Hunk Release Workflow (modem-dev/hunk, 9.6k stars) and Version Release (NG-ZORRO/ng-zorro-antd, 9.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cut A Release?

strapi-community (a GitHub organization) maintains it in strapi-community/plugin-rest-cache, which has 155 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 28, 2026.

Source: strapi-community/plugin-rest-cache on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.