Skip to content
Back to skills

Release

ASecurity

Versioning and CHANGELOG: SemVer mapped from Conventional Commits, Keep a Changelog format, tagging, pre-release gates. Use when cutting a version: bumping, writing the CHANGELOG entry, or tagging.

  • 24 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 3, 2026
ai-agentsbashgitsecurity

Security analysis

A100/100

Scanned October 3, 2026

npx -y skills add crewforth/crewforth --skill release --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Release?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Release
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/crewforth-release/badge)](https://www.skillsdirectory.com/skills/crewforth-release)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: release
description: |
  Versioning and CHANGELOG: SemVer mapped from Conventional Commits, Keep a Changelog format, tagging,
  pre-release gates.
  Use when cutting a version: bumping, writing the CHANGELOG entry, or tagging.
---

# Release & CHANGELOG

<!-- routing-eval reads the next line; why it sits in the body: AGENT_TEMPLATE.md -->
Trigger phrases: "release", "cut a release", "changelog", "version bump", "bump the version", "new version", "tag", "semver"

## SemVer mapping (derive from Conventional Commits)
- `fix:` → **PATCH** (x.y.Z)
- `feat:` → **MINOR** (x.Y.0)
- `BREAKING CHANGE:` / `feat!:` → **MAJOR** (X.0.0)

## CHANGELOG (Keep a Changelog)
Headings: **Added · Changed · Fixed · Removed · Security · Deprecated**.
Every version is dated; the `Unreleased` section can be auto-populated from commits.

## Pre-release gates (all must pass)
- [ ] Tests green + `sonarqube-check` PASSED
- [ ] `dependency-audit` clean (0 HIGH/CRITICAL)
- [ ] CHANGELOG up to date
- [ ] Version number conforms to SemVer
- [ ] **The release commit is a diff too (§4.6).** A `chore(release)` bump, a CHANGELOG-only edit and a docs-site
      version touch each stage a diff, and §4.6 exempts nothing by size — `crew-review-agent` runs over them like
      any other. A version that disagrees with the tag, a CHANGELOG entry naming the wrong one, a generated
      manifest edited by hand: that is what this review is for, and all three have shipped before.
- [ ] **Every distribution channel has a documented way to GET this version.** Publishing and reaching users are
      different events. A channel whose consumers pin at install time — an editor extension, a plugin, a vendored
      copy — leaves them on the version they installed until they ask for a new one, so a security fix ships and
      does not arrive. For each channel name the upgrade command in the README, and say plainly where it is not
      automatic.

## Tagging
```bash
git tag -a vX.Y.Z -m "vX.Y.Z"    # asks for approval (§4.4); push on explicit request (§4.5)
```

## DoD
- Correct SemVer bump; complete CHANGELOG; tag + rollback plan ready.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…