Skip to content
Back to skills

Release

ASecurity

Prepare, publish, or recover a Voyager release. Use for version bumps and releases, failed store submissions, or Safari release failures.

  • 20,321 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 28, 2026
ai-agentsgit

Security analysis

A100/100

Scanned September 28, 2026

npx -y skills add voyager-crew/voyager --skill release --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Release?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Release
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/voyager-crew-release/badge)](https://www.skillsdirectory.com/skills/voyager-crew-release)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

SKILL.md
---
name: release
description: Prepare, publish, or recover a Voyager release. Use for version bumps and releases, failed store submissions, or Safari release failures.
metadata:
  version: '1.5.0'
---

# Voyager Release

Use repository scripts and `.github/workflows/release.yml` as the source of truth. Normal releases use CI: a release tag builds the browser artifacts, signs and notarizes Safari, creates the GitHub Release, and submits the stores.

## Choose the requested workflow

Read only the reference needed for the current task:

- New release, version bump, or interrupted release preparation: [normal-release.md](references/normal-release.md).
- Failed Chrome or Edge submission, or an urgent Firefox-only hotfix: [store-recovery.md](references/store-recovery.md).
- Safari CI failure or an explicitly requested local recovery artifact: [safari-dmg.md](references/safari-dmg.md).

## Authorization and publication boundaries

The user's request and existing approval define the scope; loading this skill grants no additional permission. Complete authorized preparation and verification, and reuse approval for the same version, destination, and action. A diagnosis or preparation request does not by itself authorize publication.

Before a tag push, store submission, or replacement upload, verify that the concrete action is authorized. Ask only when that authorization is missing or the version, scope, or a possible release blocker needs a user decision; prepare the reviewable result first. Explain any newly discovered change to the approved release.

- A tag push triggers the public GitHub Release, Safari signing/notarization and Sparkle feed, Firefox AMO submission, Chrome Web Store publication, and Edge Add-ons submission.
- Moving a published tag requires explicit authorization for that operation and is allowed only while no release artifacts have been produced. Otherwise recover the affected store or prepare a new version; never silently retag.
- Preserve unrelated changes and stage release paths explicitly. Never bypass hooks with `--no-verify`.
- Keep Safari compatibility bundle IDs and signing requirements intact. Do not run a second local Safari release or upload a second DMG while CI is producing the release.
- Failed required checks block tagging and publication. Fix failures caused by the authorized work and rerun affected checks; ask only when resolving a blocker needs new scope or a risk decision. An accepted unresolved failure remains reported as failed and never bypasses artifact signing, notarization, or privacy requirements.

## Completion

For preparation, report the version, scoped changes, verification results, and remaining publication step. For diagnosis, report the failing stage, evidence, and the concrete recovery path. Do not advance either request into publication automatically.

For publication or recovery, finish the applicable workflow and verify its actual result: GitHub assets/body, Safari notarization/privacy evidence and signed Sparkle feed, and the requested stores' signing/submission outcomes. Distinguish submission success from store availability, and report pending review or failures. A successful GitHub Release alone does not prove every store or Safari succeeded.

Files in this skill

  • SKILL.md3.2 KB
  • agents/openai.yaml203 B
  • references/changelog.md8.7 KB
  • references/normal-release.md9.5 KB
  • references/release-body.md16 KB
  • references/safari-dmg.md8.2 KB
  • references/store-recovery.md3.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…