Skip to content

docs(skills): pin the 1.2.1 release in the stash-cli and stash-edge skills - #1029

Merged
auxesis merged 1 commit into
mainfrom
fix/skill-pins-1-2-1
Oct 3, 2026
Merged

auxesis merged 1 commit into
mainfrom
fix/skill-pins-1-2-1

Conversation

@auxesis

@auxesis auxesis commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

This pull request moves three version pins in the agent skills from 1.2.0 to 1.2.1. It makes main pass its tests again.

The release-train test fails on main

stash copies the skills/ directory into its npm tarball, and the build does not rewrite the version literals inside it. So languages/typescript/packages/cli/src/__tests__/release-train.test.ts requires the stash-cli skill to pin the stash version in the tree.

Version Packages pull request #1020 moved stash and @cipherstash/stack to 1.2.1 on 2 October 2026. It left the skill pins at 1.2.0, because no CI ran on that pull request. That missing CI is part 1 of Linear issue CIP-4285. Since then, the test has failed on main, in Tests run 37071819999, and on every pull request based on it.

Three pins move to 1.2.1

  • skills/stash-cli/SKILL.md: the bare-project one-shot, npx --package=stash@1.2.1 stash eql install.
  • skills/stash-edge/SKILL.md: both npm:@cipherstash/stack@1.2.1/wasm-inline specifiers, in the Deno import and in the import map.

These are the same three lines that commit 1fcf7223 changed in #928 for 1.1.1, and that commit 4aaf7dca changed in #938 for 1.2.0.

This change has no changeset, by design

The pins have always moved inside the Version Packages pull request of the release they name, with no changeset of their own. A changeset here would start a stash 1.2.2 release only to correct a pin. That release would then need its own pin change, and the loop would repeat.

The published stash 1.2.1 ships skills that pin 1.2.0. That is acceptable, and the next stash release ships the correct pins.

A follow-up change for CIP-4285 makes the version step move these pins by itself, so that every Version Packages pull request carries them.

Checks

  • release-train.test.ts: 20 tests pass.
  • pnpm test:scripts: 62 files and 1,145 tests pass, with 1 skipped as on main.

Linked issues

This PR is part of #1044. It moved the skill pins that Version Packages PR #1020 missed.

🤖 Generated with Claude Code

https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a

…kills

The skills ship inside the stash tarball and nothing rewrites their
version literals, so release-train.test.ts requires the stash-cli skill
to pin the stash version in the tree. Version Packages #1020 moved stash
and @cipherstash/stack to 1.2.1 and left the pins at 1.2.0, because no
CI ran on it. main has failed that test since.

Move the stash-cli one-shot install and the two stash-edge
@cipherstash/stack specifiers from 1.2.0 to 1.2.1, as #928 (1fcf722)
and #938 (4aaf7dc) did for their releases. No changeset: the pins move
with the release they name, and a changeset here would start a 1.2.2
release only to correct them.

Refs: CIP-4285

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a
@auxesis
auxesis requested a review from a team as a code owner October 3, 2026 00:00
@changeset-bot

changeset-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: bfd21af

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

auxesis added a commit that referenced this pull request Oct 3, 2026
The skills ship inside the stash tarball, and nothing rewrites the
version pins in them. People moved them by hand in each Version Packages
PR: #928 and #938 did, and #1020 did not, because no CI ran on it. main
then failed release-train.test.ts until #1029.

scripts/sync-skill-pins.mjs now runs from the root `version` script,
right after `changeset version`. It rewrites every exact pin of a
release-train package in skills/ to the stable version in the tree, so
each Version Packages PR carries the pins with the versions they name.

The packages are the changesets `fixed` group that holds `stash`, which
a test holds equal to the CLI's RELEASE_TRAIN_MANIFESTS. Run on main's
stale pins, the script makes exactly the change in #1029.

Refs: CIP-4285

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a

@freshtonic freshtonic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. The change is correct and minimal.

I examined these items:

  • At this head, stash and @cipherstash/stack are both at 1.2.1 in languages/typescript/packages/*/package.json. The three changed pins now agree with those versions.
  • No other stash@x.y.z or @cipherstash/stack@x.y.z pin stays in skills/. Thus the skill version pins loop in release-train.test.ts has no other target to fail on.
  • CI on bfd21afd passes, which includes Run Tests on Node 22 and Node 24, Bun, and the Deno WASM E2E tests.

No changeset is correct here. A stash changeset that only moves a pin would start a 1.2.2 release, and that release would need a new pin change. The follow-up for CIP-4285, which makes the version step move these pins, is the correct permanent fix.

@auxesis
auxesis merged commit c4ab67a into main Oct 3, 2026
26 checks passed
@auxesis
auxesis deleted the fix/skill-pins-1-2-1 branch October 3, 2026 00:18
auxesis added a commit that referenced this pull request Oct 3, 2026
The skills ship inside the stash tarball, and nothing rewrites the
version pins in them. People moved them by hand in each Version Packages
PR: #928 and #938 did, and #1020 did not, because no CI ran on it. main
then failed release-train.test.ts until #1029.

scripts/sync-skill-pins.mjs now runs from the root `version` script,
right after `changeset version`. It rewrites every exact pin of a
release-train package in skills/ to the stable version in the tree, so
each Version Packages PR carries the pins with the versions they name.

The packages are the changesets `fixed` group that holds `stash`, which
a test holds equal to the CLI's RELEASE_TRAIN_MANIFESTS. Run on main's
stale pins, the script makes exactly the change in #1029.

Refs: CIP-4285

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants