← RiqorCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Riqor
Snapshot Sep 30, 2026 · 23:14 UTC · version 0.2.5+codex.20260809182719
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Use when an AI coding agent prepares, verifies, publishes, or audits an npm and GitHub release of Riqor.",
"included_files": [],
"name": "riqor-release",
"skill_md_contents": "---\nname: riqor-release\ndescription: Use when an AI coding agent prepares, verifies, publishes, or audits an npm and GitHub release of Riqor.\n---\n\n# Riqor Release\n\nPublish only from a clean release commit after the complete gate passes\n\n## Version contract\n\nKeep these values aligned\n\n- root `package.json`\n- `packages/riqor/package.json`\n- `docs/releases/<version>.md`\n- Git tag `v<version>`\n- generated package provenance\n\nPrerelease versions such as `0.2.0-beta.1` must publish to their prerelease npm dist-tag, such as `beta`, and GitHub must mark the Release as prerelease. Do not move `latest` until a stable release is intentional\n\n## Required gate\n\n```bash\nbun install --frozen-lockfile\nbun run riqor:build\nbun test\nbun run plugin:health\nbun run skills:health\nbun run riqor:pack\nbun run riqor:inspect -- packages/riqor/riqor-*.tgz\nbun run riqor:test\nbun run actions:verify\nbun run backlog:check\nbun run release:preflight\n```\n\nReview the final diff and security-sensitive boundaries before tagging\n\n## Publishing\n\nRiqor publishes npm packages only from an authenticated local terminal. GitHub Actions may verify and attach release artifacts, but it must never run `npm publish`, `bun publish`, or receive npm publish credentials\n\nPublish prereleases with `npm publish <tarball> --access public --tag beta` and stable releases with `--tag latest`. Do not enable npm provenance in `publishConfig` for this local-only release path because npm provenance generation requires a supported cloud CI environment\n\nAfter the workflow succeeds, query npm for the published version and dist-tags, download or pack the registry artifact, install it in a clean temporary HOME, and run version, status, doctor, install, and uninstall smoke checks\n\nCompare the registry tarball with the GitHub Release artifact when byte identity is part of the release contract. Do not rewrite existing release tags or historical verification evidence\n"
}SHA-256 of public snapshot: 90c228690c9c723b331b8691eb35353d0b6fe2d663eece9846f863d56d5f00a8