AgentStack
SKILL verified MIT Self-run

Julia Release

skill-louloulibs-claude-skills-julia-release · by LouLouLibs

Use when tagging a Julia package version, updating the loulouJL registry, or computing artifact hashes for Artifacts.toml. Triggers on "tag version", "release", "register", "update registry", "artifact hashes".

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add skill-louloulibs-claude-skills-julia-release

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README — it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-louloulibs-claude-skills-julia-release)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
29d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Julia Release? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Julia Package Release & Registry Update

Tag a version, compute artifact hashes, and register in loulouJL.

Registry Location

/Users/loulou/Dropbox/projects_code/julia_packages/loulouJL/

Each package has: Versions.toml, Deps.toml, Compat.toml, Package.toml

Quick Reference

| Step | Command | |------|---------| | Get tree SHA | git rev-parse vX.Y.Z^{tree} | | Download release artifact | curl -sL -o file.tar.gz "URL" | | SHA256 of tarball | shasum -a 256 file.tar.gz | | Tree hash of extracted artifact | julia -e 'using Pkg; println(bytes2hex(Pkg.GitTools.tree_hash(".")))' |

Release Checklist

1. Version bump (PR required if main is protected)

# Project.toml
version = "X.Y.Z"

2. Tag AFTER all changes are merged

NEVER re-tag a release that has artifacts. Re-tagging causes GitHub to regenerate tarballs with different SHA256 checksums, breaking all artifact downloads.

git tag -a vX.Y.Z -m "vX.Y.Z: description"
git push origin vX.Y.Z

3. Wait for CI + artifact builds

gh run list --limit 5                    # check status
gh run watch  --exit-status      # wait for completion

4. Compute artifact hashes (if package has Artifacts.toml)

# Download each artifact from the release
curl -sL -o artifact.tar.gz "https://github.com/ORG/REPO/releases/download/vX.Y.Z/artifact-PLATFORM.tar.gz"

# SHA256 (goes in Artifacts.toml [[name.download]] sha256)
shasum -a 256 artifact.tar.gz

# Tree hash (goes in Artifacts.toml [[name]] git-tree-sha1)
mkdir extracted && cd extracted
tar -xzf ../artifact.tar.gz
julia -e 'using Pkg; println(bytes2hex(Pkg.GitTools.tree_hash(".")))'

Update Artifacts.toml with computed hashes, commit, push. Do this BEFORE tagging if possible to avoid the re-tag problem.

5. Update loulouJL registry

TREE=$(git rev-parse vX.Y.Z^{tree})

Versions.toml — always update:

["X.Y.Z"]
git-tree-sha1 = "TREE_SHA"

Deps.toml — update only if dependencies changed. Use version ranges:

["X.Y-0"]
SomeDep = "uuid-here"

Ranges must not overlap. "0.6-0" means 0.6 to end of 0.x.

Compat.toml — update only if compat bounds changed:

["0"]
julia = "1.6-*"

Commit and push the registry:

cd /Users/loulou/Dropbox/projects_code/julia_packages/loulouJL
git add LETTER/PackageName/
git commit -m "Register PackageName vX.Y.Z"
git push

6. Verify

using Pkg
Pkg.Registry.update()
Pkg.add("PackageName")  # or Pkg.update("PackageName")

Artifacts.toml Format

[[artifact_name]]
arch = "aarch64"          # or "x86_64"
git-tree-sha1 = "HASH"
os = "macos"              # or "linux"
lazy = true

    [[artifact_name.download]]
    url = "https://github.com/ORG/REPO/releases/download/vX.Y.Z/file.tar.gz"
    sha256 = "HASH"

Common Mistakes

| Mistake | Consequence | Prevention | |---------|-------------|------------| | Re-tag a release with artifacts | SHA256 changes, downloads break | Tag once, after all changes merged | | Tag before artifact hashes committed | Need re-tag (see above) | Compute hashes first, commit, then tag | | Overlapping Deps.toml ranges | Registry resolution errors | "0.5-0.5" then "0.6-0", never "0.5-0" overlapping "0.6-0" | | Forget Pkg.Registry.update() | Old version installed | Always update registry before testing | | Forget Libdl/stdlib in Deps.toml | Package fails to load | Stdlibs with UUIDs still need Deps.toml entries |

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.