version-bump
Automated semantic versioning and release workflow for Claude Code plugins. Handles version increments across package.json, marketplace.json, plugin.json manifests, build verification, git tagging, GitHub releases, and changelog generation.
Install / Use
npx skills add thedotmack/claude-mem --skill version-bumpInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of version-bump
version-bump scores 84/100 on our quality scale, 78th of 198 Security skills we index (top 40%).
Its SKILL.md is 5.2 KB long, split into 4 sections and no code examples: a solid amount of guidance for an agent.
With 94,599 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated today, so version-bump is actively maintained.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
version-bump compared with similar skills
All 4 of these similar skills score higher than version-bump; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| version-bump (this skill)by thedotmack | 84 | 94.6k | today | SKILL.md |
| Agent-Reachby Panniantong | 100 | 85.3k | 9d ago | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 2d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 2d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 3d ago | SKILL.md |
Frequently asked questions
- How do I install version-bump?
- Run
npx skills add thedotmack/claude-mem --skill version-bump. The install tabs above show the steps for each supported agent. - Which AI agents does version-bump work with?
- It is written for Claude Code, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is version-bump safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is Apache-2.0-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is version-bump still maintained?
- The repository was last updated today, so version-bump is actively maintained.
Skill content
View source on GitHubname: version-bump description: Automated semantic versioning and release workflow for Claude Code plugins. Handles version increments across package.json, marketplace.json, plugin.json manifests, build verification, git tagging, GitHub releases, and changelog generation. NPM publishing is the final human-required handoff because the maintainer raised npm security.
Version Bump & Release Workflow
IMPORTANT: Plan and write detailed release notes before starting.
CRITICAL: Commit EVERYTHING (including build artifacts). At the end of this workflow, NOTHING should be left uncommitted or unpushed. Run git status at the end to verify.
Preparation
-
Analyze: Determine if the change is PATCH (bug fixes), MINOR (features), or MAJOR (breaking).
-
Environment: Identify repository owner/name from
git remote -v. -
Paths — every file that carries the version string:
package.json— the npm/npx-published version (npx claude-mem@X.Y.Zresolves from this)plugin/package.json— bundled plugin runtime deps.claude-plugin/marketplace.json— version insideplugins[0].version.claude-plugin/plugin.json— top-level Claude-plugin manifestplugin/.claude-plugin/plugin.json— bundled Claude-plugin manifest.codex-plugin/plugin.json— Codex-plugin manifestplugin/.codex-plugin/plugin.json— bundled Codex-plugin manifestopenclaw/openclaw.plugin.json— OpenClaw plugin manifest
Verify coverage before editing:
git grep -l "\"version\": \"<OLD>\""should list all eight. If a new manifest has been added since this doc was last updated, update this list.
Workflow
-
Update: Increment the version string in every path above. Do NOT touch
CHANGELOG.md— it's regenerated. -
Verify:
git grep -n "\"version\": \"<NEW>\""— confirm all eight files match.git grep -n "\"version\": \"<OLD>\""— should return zero hits. -
Build and sync:
npm run build-and-syncto regenerate artifacts, sync the local marketplace copy, restart the worker, and clear the queue. Do not use plainnpm run buildfor release validation because it can leave the local marketplace/worker out of sync. -
Commit:
git add -A && git commit -m "chore: bump version to X.Y.Z". -
Tag:
git tag -a vX.Y.Z -m "Version X.Y.Z". -
Push:
git push origin main && git push origin vX.Y.Z. -
GitHub release:
gh release create vX.Y.Z --title "vX.Y.Z" --notes "RELEASE_NOTES". -
Changelog: Regenerate via the project's changelog script:
npm run changelog:generate(Runs
node scripts/generate-changelog.js, which pulls releases from the GitHub API and rewritesCHANGELOG.md.) -
Sync changelog: Commit and push the updated
CHANGELOG.md. -
Pre-handoff audit: Verify the release commit, tag, GitHub release, and changelog are pushed; confirm the release worktree has no pending tracked changes; and ensure its build dependencies are present because
prepublishOnlyrebuilds the package. Ifnpm view claude-mem@X.Y.Z versionalready resolves, skip the handoff and continue with post-publish checks. -
Final human handoff — publish to npm. Do not stop in the middle of the workflow for npm. Finish every agent-owned preparation above first, then make this the final human-required action.
The human maintainer's credentials/2FA are required. The agent MUST NOT run
npm publish(ornp/npm run release:*, which also publish). Give the exact release-worktree path and this command as the only requested action:npm publish # run by the HUMAN — prepublishOnly rebuilds the packageWait for confirmation. Do not ask the human to perform any other release step afterward.
-
Post-publish verification and notification: After confirmation, verify both the exact version and the latest dist-tag:
npm view claude-mem@X.Y.Z version npm view claude-mem versionIf the publish build touched tracked artifacts, run
npm run build-and-sync, review the result, and commit/push any legitimate changes. Then run the Discord notification from~/Scripts/claude-mem/, where the.envwith webhook details lives:cd ~/Scripts/claude-mem/ && npm run discord:notify vX.Y.ZDo this only after npm verification, and even when the release worktree does not have a local
.env. -
Finalize:
git status— working tree must be clean and everything must be pushed. Only automated verification, notification, and cleanup may occur after the final human handoff.
Checklist
- [ ] All eight config files have matching versions
- [ ]
git grepfor old version returns zero hits - [ ]
npm run build-and-syncsucceeded - [ ] Git tag created and pushed
- [ ] GitHub release created with notes
- [ ]
CHANGELOG.mdupdated and pushed - [ ] Pre-handoff audit passed; no agent-owned release preparation remains
- [ ] NPM publishing handed off as the final human-required action (agent does NOT run it)
- [ ] Exact npm version and
latestboth verified after the human publishes - [ ] Discord notification run from
~/Scripts/claude-mem/only after npm verification - [ ]
git statusshows clean tree
Related Skills
Agent-Reach
85.3kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
