Repository navigation
v0.7.0 — hotfix-flow skill (roadmap complete)
[0.7.0] - 2026-05-10
hotfix-flow skill shipped — the last 🚧 in the roadmap. The Git-host-workflow family is now complete: issue-triage → pr-review → changelog-bot → release-sop, with hotfix-flow as the emergency entry. hotfix-flow carries the same hard-gate philosophy plus two non-negotiables: cherry-pick only the fix (no "while we're here" extras), and forward-merge the hotfix back to main (and every intermediate release/* branch) — no merge-back, not done. Agent-agnostic markdown contract; Git-host-agnostic (GitHub / GitLab / Gitea).
Added
skills/hotfix-flow/SKILL.md— generic hotfix-flow SOP — drives a hotfix for a released version that can't wait for the next release. Eight gated steps: Step 0 should-we-hotfix gate (regression/S1/security in a released version + release train too slow + locate the affected version, the base = the release tag orrelease/*branch, the fix commit, the linkedissue-triage'd issue), Step 1 the fix lands onmainfirst via a normal PR (somainnever regresses) — exceptions for "main already moved past it" and "bug only exists on the released branch", Step 2 branch the hotfix off the release point (git switch -c hotfix/vX.Y.(Z+1) vX.Y.Z, not offmain), Step 3 cherry-pick only the fix commit(s) — no unrelated commits, no "while we're here" cleanups, big conflict ⇒ stop (not a clean hotfix), Step 4 a CHANGELOG entry under a new## [X.Y.(Z+1)] - YYYY-MM-DDdated section on the hotfix branch (the one case an entry goes into a dated section on a non-mainbranch — drafted viachangelog-bot), Step 5 the simplified hotfix review (pr-review's hotfix gates only: CI green + regression test + CHANGELOG entry + correct base +pr-reviewStep 6 security-trigger judgement not skipped), Step 6 tag the patch release and hand torelease-sopentering at its Step 5 (tag → push → GitHub Release whose notes name the affected versions → post-release smoke → DOD), Step 7 forward-merge the hotfix back tomain(and through every intermediaterelease/*branch in order) — via a PR ifmainis protected; until this lands the hotfix is not done; verified withgit branch --contains <fix-sha>showingmain+main's CHANGELOG having[X.Y.(Z+1)], Step 8 DOD closeout. Includes an edge-case runbook (could-just-wait, fix-not-on-main, big cherry-pick conflict, tag-off-main repo, multi-release-branch repo, security hotfix viaSECURITY.md, protectedmain, forgotten forward-merge, "slip in one more change", hotfix-on-a-hotfix) and eight red lines (branch off the release point notmain; cherry-pick only the fix; fix must be onmaintoo; must forward-merge back; hotfix still needs a CHANGELOG entry + regression test; security hotfix runs throughSECURITY.md; tag is the only release trigger; no extra commits in the hotfix). Composition: triggered byS1/securityissues fromissue-triage; usespr-review's hotfix gates; useschangelog-botfor the entry; hands off torelease-sopfor the release closeout. Agent-agnostic; Git-host-agnostic.README.md—hotfix-flowpromoted from 🚧 planned to ✅ shipped; the roadmap is now complete — Skills table row rewritten with the 8-stage summary; the "planned skills" note replaced with "all five skills are shipped — the Git-host-workflow family is complete"; quickstart gains ahotfix-flowcurl one-liner; Usage section gains ahotfix-flowtrigger table; repo-layout tree updated forskills/hotfix-flow/SKILL.mdandexamples/hotfix-flow-demo.md; Background section reworded ("the other planned skills" → "the other four skills").install.shunchanged — it auto-discovers anyskills/<name>/SKILL.md.examples/hotfix-flow-demo.md— workedhotfix-flowtranscript — the 8 steps run end-to-end on a hypotheticalS1regression indws 0.4.0(panic on a redirecting URL) in a tag-off-mainrepo: Step 0 the should-we-hotfix decision, Step 1 the fix landing onmainvia PR #171, Step 2 branchinghotfix/v0.4.1off tagv0.4.0, Step 3 cherry-picking only the fix commit (with the "big conflict ⇒ stop" note), Step 4 the[0.4.1]dated CHANGELOG section on the hotfix branch, Step 5 the simplified review with the security-trigger judgement explicitly run, Step 6 taggingv0.4.1and handing torelease-sop, Step 7 the forward-merge-back-to-mainPR with thegit branch --containsverification, Step 8 the DOD closeout. Closes with the security-hotfix-via-SECURITY.md, the "don't slip in--retry" cherry-pick-only, and the skipped-forward-merge contrasts.