release-after-changes

A release rule for publishing a new software version after user-visible features, fixes, or behaviour changes.

In plain words
What is it for?
Use it to update version files, run the required checks, create a release commit and tag, push them to repositories, and verify the published release.
Why use it?
It prevents completed changes from ending up in the code repository without an updated version and release record.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/x0c/corral/release-after-changes
Clone the repo
git clone --depth 1 https://github.com/x0c/corral

Made for: Cursor.

Per session 305 This file is loaded in full into every session.
When invoked 305 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00305 $0.00305
Opus 5 $0.00152 $0.00152
Sonnet 5 $0.00061 $0.00061
Haiku 4.5 $0.00030 $0.00030

Measured yesterday against content hash 6715eb8d7788, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

release-after-changes scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/rules/release-after-changes.mdc · 21 lines

What it actually says

改完即发版

完成任何用户可见的功能、修复或行为改动后,必须发布新版本,不要只提交代码就结束。

流程

  1. 同步 bump:pyproject.tomlCargo.tomlCargo.locksrc/corral/__init__.py(补丁位递增)
  2. 跑验证:完整套件每个版本只跑一次;成功后记戳,推送/收尾若产品代码未改不再整套重跑
  3. 提交:release: vX.Y.Z <简述>
  4. 打 annotated tag:git tag -a vX.Y.Z -m "vX.Y.Z"
  5. 推送:git push github main + tag,以及 origin 同名分支与 tag
  6. gh release create vX.Y.Z --repo x0c/corral --title vX.Y.Z --notes ...
  7. 核对 releases/latesttag_name 等于刚发的版本

细则见 docs/MAINTAINER_GUIDE.md「开源发布」。纯文档/规则整理且无产品行为变化时可不发版;有疑义时默认发版。

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 21 lines · 305 tokens per session scan A 6715eb8d7788

Subscribe to this mod's changes

release-after-changes is a cursor rule published in the GitHub repository x0c/corral (2 stars, last pushed yesterday), licensed MIT. It adds 305 tokens to every session, about $0.0015 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.