Skip to content

v0.7.0 — hotfix-flow skill (roadmap complete)

Choose a tag to compare

@PeterGuy326 PeterGuy326 released this 10 May 15:05
· 12 commits to main since this release

[0.7.0] - 2026-05-10

hotfix-flow skill shipped — the last 🚧 in the roadmap. The Git-host-workflow family is now complete: issue-triage → pr-review → changelog-bot → release-sop, with hotfix-flow as the emergency entry. hotfix-flow carries the same hard-gate philosophy plus two non-negotiables: cherry-pick only the fix (no "while we're here" extras), and forward-merge the hotfix back to main (and every intermediate release/* branch) — no merge-back, not done. Agent-agnostic markdown contract; Git-host-agnostic (GitHub / GitLab / Gitea).

Added

  • skills/hotfix-flow/SKILL.md — generic hotfix-flow SOP — drives a hotfix for a released version that can't wait for the next release. Eight gated steps: Step 0 should-we-hotfix gate (regression/S1/security in a released version + release train too slow + locate the affected version, the base = the release tag or release/* branch, the fix commit, the linked issue-triage'd issue), Step 1 the fix lands on main first via a normal PR (so main never regresses) — exceptions for "main already moved past it" and "bug only exists on the released branch", Step 2 branch the hotfix off the release point (git switch -c hotfix/vX.Y.(Z+1) vX.Y.Z, not off main), Step 3 cherry-pick only the fix commit(s) — no unrelated commits, no "while we're here" cleanups, big conflict ⇒ stop (not a clean hotfix), Step 4 a CHANGELOG entry under a new ## [X.Y.(Z+1)] - YYYY-MM-DD dated section on the hotfix branch (the one case an entry goes into a dated section on a non-main branch — drafted via changelog-bot), Step 5 the simplified hotfix review (pr-review's hotfix gates only: CI green + regression test + CHANGELOG entry + correct base + pr-review Step 6 security-trigger judgement not skipped), Step 6 tag the patch release and hand to release-sop entering at its Step 5 (tag → push → GitHub Release whose notes name the affected versions → post-release smoke → DOD), Step 7 forward-merge the hotfix back to main (and through every intermediate release/* branch in order) — via a PR if main is protected; until this lands the hotfix is not done; verified with git branch --contains <fix-sha> showing main + main's CHANGELOG having [X.Y.(Z+1)], Step 8 DOD closeout. Includes an edge-case runbook (could-just-wait, fix-not-on-main, big cherry-pick conflict, tag-off-main repo, multi-release-branch repo, security hotfix via SECURITY.md, protected main, forgotten forward-merge, "slip in one more change", hotfix-on-a-hotfix) and eight red lines (branch off the release point not main; cherry-pick only the fix; fix must be on main too; must forward-merge back; hotfix still needs a CHANGELOG entry + regression test; security hotfix runs through SECURITY.md; tag is the only release trigger; no extra commits in the hotfix). Composition: triggered by S1/security issues from issue-triage; uses pr-review's hotfix gates; uses changelog-bot for the entry; hands off to release-sop for the release closeout. Agent-agnostic; Git-host-agnostic.
  • README.md — hotfix-flow promoted from 🚧 planned to ✅ shipped; the roadmap is now complete — Skills table row rewritten with the 8-stage summary; the "planned skills" note replaced with "all five skills are shipped — the Git-host-workflow family is complete"; quickstart gains a hotfix-flow curl one-liner; Usage section gains a hotfix-flow trigger table; repo-layout tree updated for skills/hotfix-flow/SKILL.md and examples/hotfix-flow-demo.md; Background section reworded ("the other planned skills" → "the other four skills"). install.sh unchanged — it auto-discovers any skills/<name>/SKILL.md.
  • examples/hotfix-flow-demo.md — worked hotfix-flow transcript — the 8 steps run end-to-end on a hypothetical S1 regression in dws 0.4.0 (panic on a redirecting URL) in a tag-off-main repo: Step 0 the should-we-hotfix decision, Step 1 the fix landing on main via PR #171, Step 2 branching hotfix/v0.4.1 off tag v0.4.0, Step 3 cherry-picking only the fix commit (with the "big conflict ⇒ stop" note), Step 4 the [0.4.1] dated CHANGELOG section on the hotfix branch, Step 5 the simplified review with the security-trigger judgement explicitly run, Step 6 tagging v0.4.1 and handing to release-sop, Step 7 the forward-merge-back-to-main PR with the git branch --contains verification, Step 8 the DOD closeout. Closes with the security-hotfix-via-SECURITY.md, the "don't slip in --retry" cherry-pick-only, and the skipped-forward-merge contrasts.