PluginBench
Skill
Review
Audit score 70

version-bump

thedotmack/claude-mem

Automated semantic versioning and release workflow for Claude Code plugins with multi-manifest sync and GitHub integration.

What is version-bump?

Automates the complete release pipeline for Claude Code plugins, including version bumps across eight configuration files, build verification, git tagging, GitHub releases, and changelog generation. Use this when you're ready to publish a new version and need to ensure all manifests, tags, and release artifacts stay in sync.

  • Increments semantic versions (PATCH/MINOR/MAJOR) across package.json, marketplace.json, plugin.json, and Codex/OpenClaw manifests
  • Verifies version consistency across all eight tracked files before proceeding
  • Runs build-and-sync to regenerate artifacts and validate the release
  • Creates annotated git tags and pushes commits, tags, and GitHub releases
  • Regenerates CHANGELOG.md from GitHub release history
  • Provides pre-handoff audit checklist to catch missing steps before npm publish

How to install version-bump

npx skills add https://github.com/thedotmack/claude-mem --skill version-bump
Prerequisites
  • Git repository with remotes configured (git remote -v must show owner/name)
  • npm installed and authenticated for the target registry
  • GitHub CLI (gh) installed and authenticated
  • Node.js and npm scripts (build-and-sync, changelog:generate) configured in package.json
  • Release notes prepared before starting the workflow
Claude Code
Cursor
Windsurf
Cline

How to use version-bump

  1. 1.Determine the version bump type (PATCH for fixes, MINOR for features, MAJOR for breaking changes)
  2. 2.Update the version string in all eight files: package.json, plugin/package.json, .claude-plugin/marketplace.json, .claude-plugin/plugin.json, plugin/.claude-plugin/plugin.json, .codex-plugin/plugin.json, plugin/.codex-plugin/plugin.json, and openclaw/openclaw.plugin.json
  3. 3.Verify consistency by running git grep -n "\"version\": \"<NEW>\"" and confirming zero hits for the old version
  4. 4.Run npm run build-and-sync to regenerate artifacts and validate the build
  5. 5.Commit all changes with git add -A && git commit -m "chore: bump version to X.Y.Z"
  6. 6.Create and push the git tag: git tag -a vX.Y.Z -m "Version X.Y.Z" && git push origin main && git push origin vX.Y.Z
  7. 7.Create the GitHub release: gh release create vX.Y.Z --title "vX.Y.Z" --notes "RELEASE_NOTES"
  8. 8.Run npm run changelog:generate to regenerate CHANGELOG.md from GitHub releases

Use cases

Good for
  • Publishing a bug-fix release (PATCH) with automated version bumps across all plugin manifests
  • Releasing a new feature (MINOR) while ensuring marketplace.json and plugin.json stay synchronized
  • Coordinating a breaking-change release (MAJOR) with git tags, GitHub releases, and changelog updates
  • Validating that all eight configuration files match before handing off to npm publish
  • Regenerating release notes and changelogs from GitHub API after publishing
Who it's for
  • Plugin maintainers releasing Claude Code or Codex plugins
  • Teams managing multi-manifest projects with synchronized versioning
  • Developers who want to automate semantic versioning workflows while keeping npm publish as a manual security gate

version-bump FAQ

Why is npm publish a manual human-required step?

The maintainer raised npm security concerns, so publishing requires human credentials and 2FA. The agent completes all preparation (versioning, tagging, GitHub release, changelog) but stops before npm publish to enforce this security boundary.

What do I do if git grep finds the old version after updating?

You missed one or more of the eight files. Re-run git grep -n "\"version\": \"<OLD>\"" to find all occurrences, update them, and re-verify before proceeding to the build step.

Why must I run npm run build-and-sync instead of plain npm run build?

build-and-sync regenerates artifacts, syncs the local marketplace copy, restarts the worker, and clears the queue. Plain build can leave the marketplace and worker out of sync, causing release validation to fail.

What if npm view claude-mem@X.Y.Z version doesn't resolve after the human publishes?

The npm publish may have failed or not yet propagated. Ask the human to confirm the publish succeeded and check npm logs. If it did succeed, wait a few minutes for npm's CDN to sync and re-check.

Can I skip the Discord notification?

Only if the project does not use Discord notifications. The notification script lives in ~/Scripts/claude-mem/ and requires a .env with webhook details. Run it only after npm verification confirms the version is live.

Full instructions (SKILL.md)

Source of truth, from thedotmack/claude-mem.


name: version-bump description: Automated semantic versioning and release workflow for Claude Code plugins. Handles version increments across package.json, marketplace.json, plugin.json manifests, build verification, git tagging, GitHub releases, and changelog generation. NPM publishing is the final human-required handoff because the maintainer raised npm security.

Version Bump & Release Workflow

IMPORTANT: Plan and write detailed release notes before starting.

CRITICAL: Commit EVERYTHING (including build artifacts). At the end of this workflow, NOTHING should be left uncommitted or unpushed. Run git status at the end to verify.

Preparation

  1. Analyze: Determine if the change is PATCH (bug fixes), MINOR (features), or MAJOR (breaking).

  2. Environment: Identify repository owner/name from git remote -v.

  3. Paths — every file that carries the version string:

    • package.json — the npm/npx-published version (npx claude-mem@X.Y.Z resolves from this)
    • plugin/package.json — bundled plugin runtime deps
    • .claude-plugin/marketplace.json — version inside plugins[0].version
    • .claude-plugin/plugin.json — top-level Claude-plugin manifest
    • plugin/.claude-plugin/plugin.json — bundled Claude-plugin manifest
    • .codex-plugin/plugin.json — Codex-plugin manifest
    • plugin/.codex-plugin/plugin.json — bundled Codex-plugin manifest
    • openclaw/openclaw.plugin.json — OpenClaw plugin manifest

    Verify coverage before editing: git grep -l "\"version\": \"<OLD>\"" should list all eight. If a new manifest has been added since this doc was last updated, update this list.

Workflow

  1. Update: Increment the version string in every path above. Do NOT touch CHANGELOG.md — it's regenerated.

  2. Verify: git grep -n "\"version\": \"<NEW>\"" — confirm all eight files match. git grep -n "\"version\": \"<OLD>\"" — should return zero hits.

  3. Build and sync: npm run build-and-sync to regenerate artifacts, sync the local marketplace copy, restart the worker, and clear the queue. Do not use plain npm run build for release validation because it can leave the local marketplace/worker out of sync.

  4. Commit: git add -A && git commit -m "chore: bump version to X.Y.Z".

  5. Tag: git tag -a vX.Y.Z -m "Version X.Y.Z".

  6. Push: git push origin main && git push origin vX.Y.Z.

  7. GitHub release: gh release create vX.Y.Z --title "vX.Y.Z" --notes "RELEASE_NOTES".

  8. Changelog: Regenerate via the project's changelog script:

    npm run changelog:generate
    

    (Runs node scripts/generate-changelog.js, which pulls releases from the GitHub API and rewrites CHANGELOG.md.)

  9. Sync changelog: Commit and push the updated CHANGELOG.md.

  10. Pre-handoff audit: Verify the release commit, tag, GitHub release, and changelog are pushed; confirm the release worktree has no pending tracked changes; and ensure its build dependencies are present because prepublishOnly rebuilds the package. If npm view claude-mem@X.Y.Z version already resolves, skip the handoff and continue with post-publish checks.

  11. Final human handoff — publish to npm. Do not stop in the middle of the workflow for npm. Finish every agent-owned preparation above first, then make this the final human-required action.

    The human maintainer's credentials/2FA are required. The agent MUST NOT run npm publish (or np / npm run release:*, which also publish). Give the exact release-worktree path and this command as the only requested action:

    npm publish   # run by the HUMAN — prepublishOnly rebuilds the package
    

    Wait for confirmation. Do not ask the human to perform any other release step afterward.

  12. Post-publish verification and notification: After confirmation, verify both the exact version and the latest dist-tag:

    npm view claude-mem@X.Y.Z version
    npm view claude-mem version
    

    If the publish build touched tracked artifacts, run npm run build-and-sync, review the result, and commit/push any legitimate changes. Then run the Discord notification from ~/Scripts/claude-mem/, where the .env with webhook details lives:

    cd ~/Scripts/claude-mem/ && npm run discord:notify vX.Y.Z
    

    Do this only after npm verification, and even when the release worktree does not have a local .env.

  13. Finalize: git status — working tree must be clean and everything must be pushed. Only automated verification, notification, and cleanup may occur after the final human handoff.

Checklist

  • All eight config files have matching versions
  • git grep for old version returns zero hits
  • npm run build-and-sync succeeded
  • Git tag created and pushed
  • GitHub release created with notes
  • CHANGELOG.md updated and pushed
  • Pre-handoff audit passed; no agent-owned release preparation remains
  • NPM publishing handed off as the final human-required action (agent does NOT run it)
  • Exact npm version and latest both verified after the human publishes
  • Discord notification run from ~/Scripts/claude-mem/ only after npm verification
  • git status shows clean tree