deepchat-release — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited deepchat-release (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Follow the repository-specific DeepChat release process. Prepare release metadata on dev, keep CHANGELOG.md concise, and publish through the documented fast-forward flow instead of merge commits on main.
Inspect git state before changing anything:
release/<version> exists locally or on origin.v<version> exists locally or on origin.If a local or remote tag already exists on the wrong commit, stop and ask before replacing it.
Pick the mode that matches the user's request and current git state:
prepare metadataUpdate package.json, CHANGELOG.md, and the release notes commit on dev.
cut release branchCreate release/<version> from the release-ready commit on dev and push it.
update existing release branchUse this when the release branch already exists but metadata changed afterward. Commit on dev, move release/<version> to the new dev commit, and force-push only the disposable release branch.
publishUse this only after the release PR is approved. Fast-forward main, create the version tag on the same commit, push the tag, and then delete the temporary release branch.
Use references/release-checklist.md for exact commands.
When preparing a release on dev:
package.json to the target version.CHANGELOG.md section at the top.For v1.0.1 and later, format changelog entries in this order:
## vX.Y.Z (YYYY-MM-DD)
- English bullet
- English bullet
- 中文条目
- 中文条目Use the current local date in YYYY-MM-DD form. Preserve older changelog sections unless the user explicitly asks to rewrite them.
After editing release metadata, run these repo-required commands:
pnpm run formatpnpm run i18npnpm run lintPrefer running pnpm run typecheck before cutting the release branch. Run tests when the user asks, when the release touches behavior beyond metadata, or when risk is unclear. Report pre-existing failures separately from the release metadata work.
dev as the integration branch.release/<version> as disposable and identical to a commit already on dev.main.pnpm run release:ff -- release/<version> --tag v<version> to publish after approval.Read ../../../docs/release-flow.md when you need the full repository policy or if the checklist and repo docs ever diverge.
When the user says something like "the release branch already exists but the tag is not created yet" or "I fixed the changelog after cutting the release branch":
dev.dev.release/<version> to HEAD.release/<version> with --force-with-lease.main.v1.0.1 and 2026-04-02.Activate this skill for requests like:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.