Communitygithub.com

lguidolin/conventional-commits-and-releases

Use when committing, writing a commit message, opening a PR that will be squash-merged, or configuring automated versioning/changelogs. Keywords — conventional commits, release-please, semver, feat/fix/chore, breaking change, changelog.

¿Qué es conventional-commits-and-releases?

conventional-commits-and-releases is a Claude Code agent skill that use when committing, writing a commit message, opening a PR that will be squash-merged, or configuring automated versioning/changelogs. Keywords — conventional commits, release-please, semver, feat/fix/chore, breaking change, changelog.

Compatible conClaude Code~Codex CLI~Cursor
npx skills add https://github.com/lguidolin/agent-skills/tree/main/skills/conventional-commits-and-releases

Preguntar en tu IA favorita

Abre un nuevo chat con esta habilidad de agente ya precargada.

Documentación

Conventional Commits and Releases

Overview

Commit messages are a machine-read interface, not just prose. Automated versioning and changelog generation parse them; a malformed message produces a wrong public version or a broken release. Discipline in the small (one well-formed message) yields correctness in the large (accurate changelog, correct version bump) for free.

The Format

<type>(<scope>): <description>

TypeEffect / use
featNew feature — minor bump
fixBug fix — patch bump
docsDocumentation only
choreMaintenance, deps, config
refactorBehavior-preserving code change
testTests only
ci / buildPipeline / build-system changes
  • Imperative mood: "add X", not "added X" or "adds X".
  • Breaking changes: feat!: or a BREAKING CHANGE: footer — triggers a major bump.
  • Scope optional but encouraged: feat(auth):, fix(db):.

Load-Bearing Details

  • The type↔version link means a mistyped feat vs fix ships a wrong version. Pick the type deliberately: "add" = new feature, "update" = enhancement to existing, "fix" = bug.
  • Squash-merge: the PR title becomes the commit that ships. It must itself be a valid Conventional Commit, or the release is wrong.
  • Human-authored voice. No AI/assistant attribution, no Co-authored-by trailers, no generated-by footers. Commits read as a human wrote them.

Common Rationalizations

ExcuseReality
"The message doesn't really matter"It drives the changelog and the version number. It matters mechanically.
"chore is close enough for this feature"chore won't bump the version; users won't get your feature in a release. Use the right type.
"I'll fix the PR title later"On squash-merge the title is final at merge. Fix it before.
"A Co-authored-by trailer is harmless"Project rule forbids AI attribution. No exceptions.

Red Flags — STOP

  • A commit message with no type prefix
  • Using chore/docs for something that adds or fixes user-facing behavior
  • A squash PR title that isn't a valid conventional commit
  • Any AI attribution or Co-authored-by line

Enforcement:

  • PR title — validated in CI, blocking (amannn/action-semantic-pull-request). On squash-merge the title is the commit that ships, so this is the gate that matters.
  • AI attribution — a blocking No AI Attribution job rejects Co-authored-by trailers naming Claude/Anthropic and Generated with [Claude…] footers, in both the branch commits and the PR body (the body becomes the squash commit body). Human Co-authored-by trailers are unaffected.
  • Branch commit bodies — deliberately unlinted. Squash-merge discards them, so they never reach the changelog. If you move to merge commits, add commitlint.

Known gap: if a commit is authored by an agent account, GitHub composes a Co-authored-by trailer at squash time — after the PR check has run. The gate above cannot see it. Don't commit as an agent identity.

Full rationale: Article III of the constitution, bundled at engineering-constitution/references/engineering-constitution.md.

Individual skills in this repo

This repo contains 18 individual skills — each has its own dedicated page.

lguidolin/change-hygiene-and-code-craft

Use when writing or refactoring code, structuring a commit or PR, or deciding whether to abstract duplication. Symptoms — mixing reorg with logic changes, a PR doing several things at once, a file growing large, the second copy of similar code, or unsure whether to DRY something up.

lguidolin/cloud-delivery-aks

Use when deploying to Kubernetes or Azure Kubernetes Service (AKS), configuring cloud secrets, setting up progressive rollout/canary, per-PR ephemeral environments, or k8s health probes. Keywords — Kubernetes, AKS, Key Vault, Argo Rollouts, Flagger, canary, blue-green, liveness, readiness, PodDisruptionBudget, HPA, rollback, GHCR.

lguidolin/commit-history-rewrite

Use when an existing repository has messy commit history that needs to conform to conventional commits before adopting release-please, or when intermediate WIP/fixup/merge commits need to be cleaned up.

lguidolin/defense-in-depth-security

Use when handling untrusted input, secrets, authentication/authorization, or dependencies — or threat-modeling a new surface. Keywords — STRIDE, threat model, least privilege, secrets management, supply chain, dependency scanning, input validation, audit log, defense in depth.

lguidolin/designing-before-building

Use when starting a feature, fixing a non-trivial bug, or about to write implementation code — before any code exists. Symptoms you need this: "this is simple, I'll just code it", reaching for the editor before a design is approved, or an idea that hasn't been turned into a spec and plan.

lguidolin/engineering-constitution

Use when starting work in a project that follows the engineering constitution, orienting to its rules, or deciding which engineering practice applies to a task — spec writing, commits, testing, security, deploys, database, or UI work.

lguidolin/graphql-contract-testing

Use when writing a GraphQL query/mutation that the UI and a test will share, or building route/schema contract or smoke tests. Symptoms — copying a query into a test, a test asserting on query text, schema change that didn't break the UI build, or RLS/permission drift. Keywords — graphql-codegen, typed document, contract test, route smoke test.

lguidolin/init-repo-CI

Use when setting up a new repository with conventional commits, release-please, and CI automation, or when retrofitting an existing repository that lacks automated versioning and PR validation workflows.

lguidolin/interface-craft-and-accessibility

Use when building or styling UI — components, layouts, forms, design tokens — or making accessibility decisions. Keywords — a11y, WCAG, keyboard navigation, focus state, contrast, design system, minimalist UI, component reuse, ARIA, semantic HTML.

lguidolin/merge-gates-and-automation

Use when setting up or changing CI, pre-push hooks, or a task runner, or deciding what must pass before merge. Symptoms — tempted to put authoritative checks only in a local hook, skip CI, bypass with --no-verify, or unsure what gates a merge vs. runs locally.

lguidolin/observability-and-slos

Use when adding logging, metrics, tracing, health checks, SLOs, or alerting — or when building a service surface that needs to be operable and debuggable. Keywords — structured logs, OpenTelemetry, correlation id, RED metrics, liveness, readiness, SLI, SLO, error budget, alerting.

lguidolin/performance-and-scale

Use when working on hot paths, list endpoints, pagination, data-access in loops, or public interfaces/schemas. Symptoms — unbounded queries, N+1 access, no latency budget, optimizing without measuring, or changing an interface many consumers depend on. Keywords — pagination, N+1, Hyrum's Law, performance budget, bundle size.

lguidolin/postgres-postgraphile-rls-and-sql

Use when writing PostgreSQL, PostGraphile config, Row-Level Security policies, SQL schema files, or working on the Browser→App→PostGraphile→Postgres data path. Keywords — RLS, SECURITY DEFINER, search_path, pgSettings, grants, roles, GraphQL depth limit, query cost, statement_timeout, SQL file organization.

lguidolin/recording-decisions

Use when a design or architecture decision has been made and needs to be captured — writing a decision record or ADR, updating a decision index, noting a deferred idea, or superseding a past decision. Keywords — ADR, decision record, rationale, rejected alternatives, dependency index.

lguidolin/resilience-and-deploy-safety

Use when planning a deploy, designing a rollback, or responding to an incident or writing a postmortem. Keywords — deploy safety, rollback, immutable artifact, progressive delivery, canary, blast radius, incident response, blameless postmortem, error budget.

lguidolin/ship-it

Use when the user wants to ship work — push, PR, archive decision records, merge, and clean up. Handles the full lifecycle from committing final changes through post-merge cleanup including converting specs/plans to compact decision records.

lguidolin/tests-as-a-control

Use when writing or modifying tests, when a test breaks during a refactor, or when testing permission/role rules. Symptoms — tempted to edit a test to make it pass, testing only the happy path, a deny-test that started passing, flaky tests, or unsure what to assert.

lguidolin/zero-downtime-migrations

Use when changing a database schema where data must survive the change — adding/removing/renaming columns, constraints, indexes, or backfilling. Symptoms — a destructive migration bundled with a code deploy, a NOT NULL column with a backfill, a table-locking UPDATE, or a rename. Keywords — expand/contract, parallel change, backfill, NOT VALID, CREATE INDEX CONCURRENTLY, graphile-migrate.

Skills relacionados