Skip to content

Conversation

@CybotTM
Copy link
Member

@CybotTM CybotTM commented Feb 7, 2026

Summary

  • Pin all GitHub Actions to SHA for supply chain security
  • Add step-security/harden-runner (v2.14.2)
  • Update actions/checkout to v6.0.2
  • Update softprops/action-gh-release to v2.5.0
  • Split into separate skill and plugin release packages
  • Produce both .zip and .tar.gz formats

Asset naming

Package Contents
*-skill-v*.zip/.tar.gz Skill only (SKILL.md, references, scripts, templates)
*-plugin-v*.zip/.tar.gz Full plugin (skill + .claude-plugin manifest, hooks, scripts)

Test plan

  • Verify workflow YAML is valid
  • Tag a release and confirm correct assets are produced

- Pin all actions to SHA (harden-runner v2.14.2, checkout v6.0.2, gh-release v2.5.0)
- Add step-security/harden-runner for supply chain security
- Split into separate skill and plugin release assets
- Produce both zip and tar.gz formats
@gemini-code-assist
Copy link

Note

Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported.

@CybotTM CybotTM merged commit 70327a6 into main Feb 7, 2026
3 checks passed
@CybotTM CybotTM deleted the chore/standardize-release-workflow branch February 7, 2026 17:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant