Reverse-Skill Release Process: Step-by-Step Guide for Version Management
The reverse-skill release process uses a lightweight Git-tag-driven workflow where version bumps, changelog updates, and bootstrap scripts combine to publish verified tool bundles as GitHub release assets.
The release process for reverse-skill centers on a single source of truth—the VERSION file—and a chain of automated steps that populate GitHub releases with pre-built reverse-engineering tools. This repository (zhaoxuya520/reverse-skill) maintains a deliberately simple pipeline that human developers and AI agents can execute reproducibly.
Overview of the Release Pipeline
The entire workflow spans eight stages, from version incrementing through final verification. Each stage produces observable artifacts: a commit hash, a Git tag, a GitHub release draft, and downloadable ZIP/JAR assets with SHA-256 checksums.
The pipeline's simplicity rests on one architectural decision: pushing a Git tag triggers the GitHub release mechanism, while bootstrap scripts handle asset construction and hash verification.
Step 1: Update the VERSION File
The VERSION file at the repository root stores the canonical version string. This plain-text file follows semantic versioning (e.g., v1.2.0) and serves as the trigger for downstream automation.
echo "v1.2.0" > VERSION
No other configuration files require editing—the bootstrap scripts read this value directly.
Step 2: Edit the CHANGELOG
Release notes live in CHANGELOG.md. Each entry requires a version header and bullet list of changes:
cat <<EOF >> CHANGELOG.md
## v1.2.0 – 2026-08-04
- Added support for `jadx` v1.5.6
- Updated Ghidra-MCP to latest release
- Fixed routing bug in `skills/MASTER-ROUTING.md`
EOF
The changelog format remains human-readable; no parsing tools consume it.
Step 3: Commit and Push to Main
Use conventional commits to maintain clear history:
git add VERSION CHANGELOG.md
git commit -m "feat: bump version to v1.2.0"
git push origin main
The release process for reverse-skill permits direct pushes to main; no protected branch workflow gates the tag creation.
Step 4: Create and Push the Git Tag
The tag name must match the VERSION file contents exactly:
git tag v1.2.0
git push origin v1.2.0
This push triggers GitHub's release creation mechanism, generating a draft release automatically.
Step 5: Build and Upload Release Assets
The bootstrap scripts in skills/scripts/ perform the heavy lifting. The bootstrap-reverse.sh script (and its PowerShell equivalent bootstrap-reverse.ps1) handle three tasks:
- Fetch upstream tool releases using the
install_github_releasehelper - Verify SHA-256 checksums
- Bundle tools into distributable ZIP/JAR archives
The install_github_release function appears at lines 332–340 of skills/scripts/bootstrap-reverse.sh:
bash skills/scripts/bootstrap-reverse.sh
This script downloads tools like jadx and ghidra-mcp, confirms their integrity against known hashes, and stages them for GitHub release attachment.
Step 6: Refresh the Tool Index
After assets publish, update the local tool registry. Two platform-specific commands exist:
- Linux/macOS:
bash skills/scripts/refresh-tool-index.sh - Windows: PowerShell equivalent (unnamed in sources)
The refresh script regenerates skills/tool-index.md from skills/tool-index.md.template, marking newly available tools with ✓ in the github-release-zip and github-release-jar-wrapper columns.
Step 7: Verify the Published Release
Navigate to the generated URL pattern:
https://github.com/zhaoxuya520/reverse-skill/releases/tag/v1.2.0
Confirm:
- All expected ZIP/JAR files attach correctly
- Checksum links resolve
- Release notes reflect
CHANGELOG.mdcontent
Key Files in the Release Process
| File | Purpose |
|---|---|
VERSION |
Single source of truth for version string |
CHANGELOG.md |
Human-readable release history |
skills/scripts/bootstrap-reverse.sh |
Downloads and verifies tool assets; contains install_github_release helper |
skills/scripts/bootstrap-reverse.ps1 |
Windows equivalent of bootstrap script |
skills/scripts/refresh-tool-index.sh |
Regenerates skills/tool-index.md post-release |
skills/tool-index.md.template |
Template defining tool acquisition methods (github-release-zip, github-release-jar-wrapper) |
README.md |
Repository overview and workflow documentation |
README_AI.md |
Release instructions tailored for AI agent pipelines |
Complete Release Command Sequence
# Bump version
echo "v1.2.0" > VERSION
# Update changelog
cat <<EOF >> CHANGELOG.md
## v1.2.0 – 2026-08-04
- Added support for `jadx` v1.5.6
- Updated Ghidra-MCP to latest release
- Fixed routing bug in `skills/MASTER-ROUTING.md`
EOF
# Commit and push
git add VERSION CHANGELOG.md
git commit -m "feat: bump version to v1.2.0"
git push origin main
# Tag release
git tag v1.2.0
git push origin v1.2.0
# Build assets
bash skills/scripts/bootstrap-reverse.sh
# Refresh tool index
bash skills/scripts/refresh-tool-index.sh
Summary
- One file controls versioning: The
VERSIONfile determines the release tag. - Git tags trigger automation: Pushing a tag creates the GitHub release draft.
- Bootstrap scripts ensure integrity:
install_github_releaseinskills/scripts/bootstrap-reverse.shdownloads tools and verifies SHA-256 hashes. - Tool index refreshes automatically: Running
refresh-tool-index.shupdatesskills/tool-index.mdto reflect available releases. - Cross-platform support: Bash and PowerShell scripts cover Linux, macOS, and Windows environments.
Frequently Asked Questions
How does reverse-skill handle version numbering?
The repository uses semantic versioning stored in a plain-text VERSION file at the repository root. The bootstrap scripts and GitHub Actions (if configured) read this file to determine the release tag. No package managers (npm, PyPI, etc.) participate—the workflow remains Git-native.
What security measures protect downloaded tool binaries?
The install_github_release helper function (lines 332–340 of skills/scripts/bootstrap-reverse.sh) verifies SHA-256 checksums for every downloaded ZIP or JAR file. This prevents supply-chain attacks where upstream releases might be compromised. Checksum values are hardcoded or fetched from trusted sources.
Can the release process run unattended or in CI/CD?
Yes. The README_AI.md file contains identical instructions adapted for automated pipelines. The bootstrap scripts require no interactive input; they exit with non-zero status on verification failures, making them suitable for GitHub Actions, GitLab CI, or other automation platforms.
What happens if a tool release is missing or fails verification?
The bootstrap script aborts. The install_github_release function returns a failure code when checksums mismatch or downloads fail, preventing corrupted or incomplete assets from reaching the GitHub release page. Manual intervention is required to update the expected hash or resolve upstream availability.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →