publish-npm-version
Cuts the next minor release of Prisma Next: bumps the root package.json version, propagates it to every workspace package, and opens a PR titled…
npx skills add https://github.com/prisma/prisma-next --skill publish-npm-versionPublish next npm version
Audience
Maintainers of Prisma Next who have permission to push branches and open PRs in the repository. The skill is invoked locally by the maintainer; it does not run as a GitHub Action. Running locally is what makes the resulting PR trigger CI normally — PRs opened by a workflow's GITHUB_TOKEN do not, which defeats the point of cutting a reviewable release.
Background reading
Read docs/oss/versioning.md before running this skill. It covers:
- The source-of-truth model (root
package.jsonversion). - The lockstep guarantee (every workspace package matches the root).
- The dist-tag convention (
latest/dev/beta). - The full release procedure (this skill is step 2 of 3; merging the PR is the publish trigger — there is no separate dispatch step).
- The emergency-patch path (this skill does not handle patches).
This SKILL.md covers only the mechanics of step 2 — opening the bump PR.
Pre-flight
The skill does not require the maintainer to be on main or to have a clean working tree — it does all the work in a fresh worktree off origin/main, so the maintainer's current worktree (typically a feature branch in worktrees/<feature>/) is left undisturbed.
Before invoking this skill, confirm:
- The maintainer can fetch from
origin(git fetch origin mainsucceeds). - You are ready to draft the release notes for this bump. The
draft-release-notesskill (invoked in step 7 below) enumerates the merged PRs since the previous stable tag and surfaces the release-notes-worthy changes — including any breaking changes — so this no longer rests on the maintainer's unaided recollection. If you already know of an in-flight breaking change that must be called out, note it so the authoring step gives it prominence.
If either precondition is unmet, stop and surface the issue. Do not try to auto-resolve.
Procedure
-
Fetch and determine the target version. Run
git fetch origin main, then read the current rootversionfromorigin/mainand compute the next minor:git fetch origin main CURRENT=$(git show origin/main:package.json | node -e 'process.stdout.write(JSON.parse(require("fs").readFileSync(0,"utf8")).version)') NEXT=$(node -e "const [a,b] = process.argv[1].split('.'); process.stdout.write(\`\${a}.\${Number(b)+1}.0\`)" "$CURRENT") echo "$CURRENT → $NEXT"(Patch component is reset to 0 by design — see
docs/oss/versioning.md.) -
Create a fresh worktree off
origin/main. Use the conventionrelease/<version>for both the branch and the sibling worktree path:git worktree add -b "release/$NEXT" "../release-$NEXT" origin/main cd "../release-$NEXT"This is what makes the skill safe to invoke from any worktree: the bump happens against a fresh checkout of
origin/main, not against the maintainer's current branch. The branch name encodes the target version so reviewers can tell at a glance what the PR ships. -
Bump. From the new worktree, run
pnpm bump-minor. The script reads the rootpackage.jsonversionfromgit show HEAD:package.json(in this worktree, HEAD isorigin/main), computes the next minor, and writes it to every workspacepackage.jsonviascripts/set-version.ts.Note:
bump-minorrequiresnode_modulesto resolve its dependencies (e.g.pathe). If the fresh worktree has nonode_modules, runpnpm install --frozen-lockfile --ignore-scriptsfirst. -
Refresh the lockfile. Workspace-internal dependencies in this repo are pinned as
workspace:<version>(notworkspace:*), so the bump changes their specifiers inpnpm-lock.yaml. Run:pnpm install --lockfile-onlyto update
pnpm-lock.yamlin lockstep. Without this step, CI fails withERR_PNPM_OUTDATED_LOCKFILEon the release PR. -
Sanity-check the diff. Confirm:
- Every modified file is either a
package.jsonorpnpm-lock.yaml. - The
package.jsondiffs are exactlyversionfield changes plus internalworkspace:<old> → workspace:<new>specifier bumps (no other fields). - The
pnpm-lock.yamldiff is exactlyspecifier: workspace:<old> → workspace:<new>lines (no resolution churn for external packages).
- Every modified file is either a
-
Commit. Stage
package.jsonfiles andpnpm-lock.yamltogether in a single commit:chore(release): bump to <version>No body is required — the PR description will explain the bump in detail.
-
Draft the release notes. From inside this
release/<version>worktree, run thedraft-release-notesskill for<version>. It enumerates the merged PRs since the previous stablev*tag, triages which are user-facing, categorizes them (breaking changes first), writesdocs/releases/v<version>.md, and prepends a matchingCHANGELOG.mdentry — committing both on the release branch as their own commit. Committing the notes here is what lands them in the bump PR diff, so the PR-modecheck:release-notesgate passes and the maintainer reviews the notes as part of the release PR. -
Push the branch to
origin. -
Open the PR with
gh pr create. Use the title:Bump to version <version>The body should:
- State the previous and new version (
<previous> → <new>). - Link to
docs/oss/versioning.mdfor context. - Point reviewers at the committed
docs/releases/v<version>.md(authored by thedraft-release-notesskill in step 7) as the human-review surface for the release's user-facing changes. - Note that merging this PR ships the release: the resulting push to
maincarries the bumped rootversion, thePublish to npmworkflow detects the change and publishes<new>under dist-taglatest, and a matching GitHub Release is created automatically.
- State the previous and new version (
-
Stop and report the PR URL and the worktree path to the maintainer. The maintainer can
git worktree remove ../release-<version>after the PR merges. Do not merge the PR yourself; the merge is a human gate where someone confirms the release notes are acceptable. (Merging triggers the publish — there is no separate dispatch step.)
Idempotency
pnpm bump-minor is idempotent because it reads the root version from git show HEAD:package.json rather than from the working tree. A maintainer who runs the skill twice without committing in between still ends up with the same target version, not a double-bump. If you find yourself in that situation (working tree dirty with a previous bump), reset and re-run; do not stack bumps.
Out of scope
- Merging the PR. The skill stops at "PR opened" so a human can confirm the release notes. Merging is what triggers the actual publish, but it remains a human gate by design.
- Patch releases. Patches use a different bump shape (
patch+1from a release tag); the manual procedure indocs/oss/versioning.mdapplies. - Pre-release / beta tags. The
betadist-tag is hand-cut via a manualworkflow_dispatchofPublish to npm; this skill always advances to a stable minor.