| name | taxmate-release-closeout |
| description | Execute TaxMate Australia repo PR closeout, local validation, and release delivery. Use when fixing or merging TaxMate Australia GitHub PRs, handling review comments, encoding repeated review lessons into validation checks/tests, running Gitleaks gates, merging Release Please PRs, verifying published tags/releases, or cleaning TaxMate worktrees/branches after release. |
TaxMate Release Closeout
Use this only for the nijanthan-dev/taxmate-australia repo. Prefer gh for GitHub. Recheck live state before acting; memories are hints, not truth.
Preflight
- Confirm repo, remote, current branch, and worktree state.
- If work starts from
main, create a fresh fix/, feat/, or chore/ branch or worktree from current origin/main.
- Recheck issue/PR head SHA, mergeability, and unresolved review threads.
- Confirm the full local workflow and secret scans passed for the current head.
- If GitHub auth lacks scope, report the missing scope and stop. Do not run
gh auth refresh unless asked in the current turn.
Fix PR Review Comments
- Patch all current-head review comments, not only the easiest one.
- If feedback repeats or points to a contract class, update
scripts/taxmate_review_guardrails.py and focused tests before the one-off code fix.
- Audit the same failure pattern across flat, nested, itemized, generated, and rendered paths before re-requesting independent review.
- For generated skill/doc output, patch
scripts/skillgen.py or the source file first; do not hand-edit generated skills/*/SKILL.md unless the generator owns no path.
- Run focused tests for the touched area, then the repo's relevant validation path.
- Reply to each review thread with the fix and resolve it.
- Push and recheck the current head and review threads.
Validation Gates
Run the strongest relevant local checks before merge. Common TaxMate checks include:
./scripts/taxmate validate
./scripts/check-publication-ready.sh
gitleaks dir . --redact
Also run secret scans on history and the PR diff before merge. If a secret reached remote Git, stop and remove it from branch history before merge.
For ATO fetch/runtime changes, preserve curl --disable -L ordering and verify status, final URL, and body handling through tests.
For release/version changes, inspect .release-please-manifest.json, .codex-plugin/plugin.json, skill.json, plugin.lock.json, CHANGELOG.md, and Release Please config as applicable.
Merge And Release
- Squash-merge the fix PR only after local validation and secret-scan gates pass.
- Verify issue closure and updated
main state.
- Wait for Release Please to open the next release PR when the fix should ship.
- Inspect release PR version bumps and changelog, then run the local validation required for the changed files.
- Merge the release PR with squash merge.
- Verify tag, GitHub release, and version artifacts.
- Fast-forward local
main if safe.
- Clean merged temp branches/worktrees only after verifying no user changes would be lost. Preserve unrelated untracked paths.
Stop Conditions
Stop and report plainly when:
- Missing GitHub scope blocks required action.
- Full local validation is absent for the current head.
- Any Gitleaks gate finds a real secret.
- Release Please fails because required repo secret/config is missing.
- Cleanup would delete user work or an active worktree.