← get-fableCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to get-fable
Snapshot Sep 30, 2026 · 23:14 UTC · version 1.5.1
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Audit and certify repository merge and release readiness against required quality gates, clean git working trees, and verified distribution artifacts. Use when preparing a release tag, validating release checklist criteria, publishing npm/PyPI packages, or certifying a branch for merge — even if the user does not explicitly say \"fable-release\" (e.g. \"prepare the release\", \"is this ready to merge\", \"ship to production\", \"publish the package\"). Do NOT use when verification is stale, failing, or missing (use fable-verify first).",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 352
},
{
"relative_path": "evals/scenarios.json",
"size_in_bytes": 4253
},
{
"relative_path": "examples/release-readiness-audit.md",
"size_in_bytes": 252
},
{
"relative_path": "references/artifact-and-distribution-verification.md",
"size_in_bytes": 2714
},
{
"relative_path": "references/release-gates.md",
"size_in_bytes": 1534
},
{
"relative_path": "skill.package.json",
"size_in_bytes": 458
},
{
"relative_path": "templates/release-checklist.template.md",
"size_in_bytes": 789
}
],
"name": "fable-release",
"skill_md_contents": "---\nname: fable-release\ndescription: \"Audit and certify repository merge and release readiness against required quality gates, clean git working trees, and verified distribution artifacts. Use when preparing a release tag, validating release checklist criteria, publishing npm/PyPI packages, or certifying a branch for merge — even if the user does not explicitly say \\\"fable-release\\\" (e.g. \\\"prepare the release\\\", \\\"is this ready to merge\\\", \\\"ship to production\\\", \\\"publish the package\\\"). Do NOT use when verification is stale, failing, or missing (use fable-verify first).\"\nversion: 1.3.0\npack: delivery\ninputs:\n - completion_evidence\nrequires:\n - clean_worktree\nproduces:\n - release_readiness\ngates:\n - required_checks_pass\n - no_blocking_findings\nfallback: fable-verify\nmutatesWorkspace: false\nparallelSafe: false\nneural_links:\n precursors:\n - fable-verify\n - fable-review\n - fable-security\n continuations:\n - fable-handoff\n lateral_peers:\n - fable-handoff\n recovery: fable-recover\n---\n\n# Fable Release\n\nProve that the exact commit and artifact users will receive are ready to ship, then distinguish readiness from actual distribution.\n\n## Mission\nA release is an external state transition. Source tests can be perfect while the package omits files, the tag points at another commit, the registry still serves an old version, or a published artifact cannot start in a clean environment.\n\nThis Skill closes that gap by tying release claims to exact version, commit, artifact, workflow, tag, and registry evidence.\n\n## Activate When\n- preparing a branch for merge or a version for release;\n- creating/pushing a version tag;\n- publishing npm/package/plugin artifacts;\n- finalizing a GitHub Release;\n- verifying that a distribution channel actually serves the intended version;\n- assessing whether release evidence is current after last-minute changes.\n\n## Do Not Activate When\n- implementation is still changing (`fable-execute`/`fable-tdd`);\n- functional verification is incomplete (`fable-verify`);\n- blocking review/security findings remain;\n- the user has not authorized an irreversible publish action. Readiness checks may run; publishing itself requires the applicable authorization.\n\n## Release Classification\n\n| Release type | Extra concerns |\n| --- | --- |\n| Merge only | branch/base freshness, required CI, review |\n| Package registry | package contents, clean install, registry verification |\n| Git tag/GitHub Release | tag→SHA binding, notes/assets, draft/prerelease state |\n| Plugin/marketplace | manifest/version parity, submission/approval state |\n| Migration-bearing release | rollout order, backward compatibility, rollback |\n| Security-sensitive release | advisory/secrets/dependency gates, disclosure constraints |\n\n## Protocol\n\n### Stage 1 — Freeze the candidate\nIdentify the exact candidate:\n- version;\n- commit SHA;\n- target branch/tag;\n- distribution channels;\n- required CI/review/security evidence.\n\nAny source/config/package mutation after this point invalidates relevant release evidence and creates a new candidate.\n\n### Stage 2 — Validate version semantics\nCheck:\n- version does not already exist in target registry/tag namespace;\n- SemVer matches actual compatibility impact;\n- all canonical version locations/manifests agree;\n- changelog/release notes describe user-visible changes accurately;\n- prerelease state is intentional.\n\nDo not choose patch/minor/major purely for convenience.\n\n### Stage 3 — Reconfirm fresh quality gates\nVerify required functional/build/review/security evidence belongs to the candidate SHA/mutation generation. If evidence was produced before candidate changes, rerun it.\n\n### Stage 4 — Inspect the artifact boundary\nBuild/dry-run the exact artifact and inspect its manifest/content.\n\nCheck:\n- required entrypoints/assets/manifests are present and non-empty;\n- secrets, temp files, tests/fixtures/internal holdouts are excluded unless intentionally public;\n- generated files are current;\n- executable permissions/exports/bin paths are correct;\n- dependency/runtime constraints are accurate.\n\n### Stage 5 — Clean-environment smoke\nInstall/use the produced artifact outside the source checkout where feasible.\n\nProve at least:\n- install succeeds;\n- primary executable/import resolves;\n- version/help/basic smoke works;\n- documented quick-start path is not accidentally relying on repo-local files.\n\n### Stage 6 — Verify repository release state\nBefore publishing:\n- candidate commit is pushed;\n- required CI on the candidate is green;\n- tag does not exist or already points to exactly the intended SHA;\n- release notes/assets target the same tag/SHA;\n- branch is not known-broken relative to base.\n\n### Stage 7 — Publish only through an authorized secure path\nPrefer configured trusted publishing/OIDC/host automation over introducing long-lived tokens.\n\nDo not print/store credentials or weaken security to make a release pass.\n\nIf authorization or authentication is absent, stop at **READY_NOT_PUBLISHED** with exact remaining action.\n\n### Stage 8 — Verify distribution independently\nAfter publish, query the external destination rather than trusting the publish command.\n\nExamples of proof:\n- registry reports expected version/dist metadata;\n- clean install from registry succeeds;\n- Git tag resolves to candidate SHA;\n- GitHub Release is actually public, not draft;\n- marketplace status reflects submitted/published state.\n\n### Stage 9 — Post-release smoke and handoff\nRun the user-facing install/invocation path from public distribution. Record rollback/deprecation/follow-up issues if observed.\n\n## Release Verdicts\n- **NOT_READY**: required deterministic/review/security/artifact gate fails.\n- **READY_NOT_PUBLISHED**: candidate is sound but publish is unauthorized/unavailable/not requested.\n- **PUBLISHED_UNVERIFIED**: publish command/workflow claims success but external distribution has not been independently confirmed.\n- **RELEASED**: exact candidate is public through intended channels and independently verified.\n\nDo not collapse these states into \"done.\"\n\n## Decision Rules\n- A dirty worktree does not automatically fail if dirt is explicitly unrelated and release artifact is from a clean candidate SHA; however uncommitted release changes do fail readiness.\n- Tag exists at different SHA → hard stop; never move/force a release tag casually.\n- Package version already exists in immutable registry → choose a new valid version, do not overwrite.\n- Dry-run contents differ from intended public surface → fix package configuration before tagging/publishing.\n- Local global install works from repo link but clean tarball/registry install fails → NOT_READY.\n- CI green on older commit → stale release evidence.\n- GitHub Release draft exists → not public release evidence.\n- Publish workflow green but registry not updated yet → PUBLISHED_UNVERIFIED until independently confirmed or known propagation policy is resolved.\n- Marketplace requiring manual approval → report submission state accurately; never claim publication.\n\n## Invariants\n- Release version, commit, tag, artifact, and public metadata refer to one candidate.\n- No credential is committed or logged as release evidence.\n- Irreversible external writes require applicable authorization.\n- Public release claims are externally verified.\n- Last-minute mutation invalidates stale candidate evidence.\n- Release notes do not claim maturity/features unsupported by fresh proof.\n\n## Failure Taxonomy\n### Artifact omission/pollution\nPackage misses runtime file or includes secrets/internal material. Fix boundary, rebuild, resmoke.\n\n### Version drift\nManifests/changelog/CLI/tag disagree. Reconcile before release.\n\n### Candidate drift\nCI/evidence points to older SHA after release commit changed. Rerun gates.\n\n### Tag mismatch\nExisting tag points elsewhere. Stop; investigate rather than force-move.\n\n### Publish/auth failure\nCandidate may remain READY_NOT_PUBLISHED. Diagnose secure auth/workflow without embedding credentials.\n\n### Registry/release mismatch\nPublish reports success but public channel serves wrong/old artifact. Keep PUBLISHED_UNVERIFIED and investigate.\n\n### Clean-install failure\nArtifact depends on repo-local files/dev state. NOT_READY regardless of source tests.\n\n## Anti-Patterns\n- \"tests pass, publish\";\n- tagging before inspecting artifact contents;\n- using source checkout as the only install test;\n- force-moving tags;\n- adding tokens to config/docs to bypass trusted publishing;\n- equating draft release with public release;\n- trusting workflow success without registry/release lookup;\n- updating docs to claim availability before public verification;\n- claiming 100% maturity while changed behavioral evidence is stale.\n\n## Release Attestation\n\n```text\nVersion:\nCandidate SHA:\nTarget channels:\nFresh quality gates:\nArtifact manifest check:\nClean-install smoke:\nTag → SHA:\nGitHub Release state:\nRegistry/marketplace state:\nExternal verification:\nVerdict: NOT_READY | READY_NOT_PUBLISHED | PUBLISHED_UNVERIFIED | RELEASED\nRollback/follow-up:\n```\n\n## Completion Criteria\nThe Skill's work completes when the requested release stage is accurately attested:\n- readiness claims are tied to exact candidate evidence;\n- artifact boundary and clean install are proven where applicable;\n- tag/release/registry states are consistent;\n- public distribution is independently verified before `RELEASED`;\n- missing authorization/external gates are represented as explicit state, never guessed away.\n\n## Progressive Resources\n- Deep guide: `references/artifact-and-distribution-verification.md`\n- Existing release gates: `references/release-gates.md`\n- Example: `examples/release-readiness-audit.md`\n"
}SHA-256 of public snapshot: 6f8dd391ce34258243de7ce0f068a5ceb056d337d19ec3f66cf438587906fb4c