Skip to content
Back to skills

Codexloop Releasing

ASecurity

release-please, gitflow (develop → main), TestPyPI + PyPI publishing, and the known publish-testpypi gap. Use before cutting a release.

  • 2 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 19, 2026
ai-agentspythonrustbashgit

Security analysis

A100/100

Scanned September 19, 2026

npx -y skills add the-vibey-project/vibey --skill codexloop-releasing --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Codexloop Releasing?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Codexloop Releasing
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/the-vibey-project-codexloop-releasing/badge)](https://www.skillsdirectory.com/skills/the-vibey-project-codexloop-releasing)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: codexloop-releasing
description: release-please, gitflow (develop → main), TestPyPI + PyPI publishing, and the known publish-testpypi gap. Use before cutting a release.
allowed-tools: Read Bash(git *)
---

# codexloop releasing

## Gitflow

```
develop (default branch) → main (releases)
```

1. Feature PRs squash into `develop`.
2. `develop` merge-commits into `main` when ready to release.
3. release-please opens a PR on `main` when it detects conventional
   commits since the last tag.
4. Merging the release PR publishes to PyPI.

## Workflows

- **`ci.yml`**: runs on every push. Tests, linting, type checks, per-layer
  coverage, import-linter, bandit, pip-audit.
- **`publish-testpypi.yml`**: publishes to TestPyPI on every `develop`
  push. **Known gap: no test gate.** This workflow builds and publishes
  without running tests first. It trusts that CI passed.
- **`release-please.yml`**: opens a release PR on `main` when conventional
  commits land. Merging that PR publishes to PyPI (via GitHub Actions +
  PyPI trusted publishing).

## release-please

Configured in `release-please-config.json`:

```json
{
  "packages": {
    ".": {
      "release-type": "python",
      "package-name": "codexloop",
      "changelog-path": "CHANGELOG.md"
    }
  }
}
```

It maintains `CHANGELOG.md` automatically from conventional commits.

## Before merging develop → main

1. All CI gates green on `develop`.
2. TestPyPI publish succeeded (workflow run shows no errors).
3. CHANGELOG.md reflects all user-facing changes since last release.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…