npx skills add ...
npx skills add cloudflare/sandbox-sdk --skill changesets
npx skills add cloudflare/sandbox-sdk --skill changesets
Use when creating a changeset, preparing a release, or bumping versions. Covers which packages to reference, how to write user-facing changeset descriptions, the release automation flow, and the npm/Docker version sync requirement. (project)
This repository uses changesets to create Version Packages PRs and maintain changelog/version files. Stable and prerelease artifact publishing are handled by the release orchestrator. Create a changeset whenever your change affects published packages.
A changeset should be created when there is a change that is observable to a consumer of the
@cloudflare/sandbox package. This includes:
Create a new file in .changeset/ (e.g. .changeset/your-feature-name.md):
Only reference @cloudflare/sandbox. Never list @repo/shared or @repo/sandbox-container — those are internal workspace packages and must not be versioned independently. Changes to them flow through the public package. Pre-commit hooks and CI enforce this.
Use patch for almost everything. The SDK is in beta:
patch — all normal changes (features, fixes, refactors)minor — breaking changes onlymajor — neverImportant: Changeset files should only reference @cloudflare/sandbox, never @repo/shared or @repo/sandbox-container. These internal packages should not be versioned independently - changes to them flow through the public package. Pre-commit hooks and CI will validate this rule.
Important: Write for end users. Changeset descriptions appear in GitHub releases - they're user-facing documentation, not internal notes.
Releases run via .github/workflows/release.yml. There is no manual publishing step.
Docker image version MUST match the npm package version. This is enforced via ARG SANDBOX_VERSION in packages/sandbox/Dockerfile. Don't try to release them out of band.
packages/sandbox/src/version.tslinux/amd64 only, matching Cloudflare's production runtime (ARM Macs use Rosetta/QEMU locally, preserving dev/prod parity)registry.cloudflare.com/library/sandbox:{version} (with -python, -opencode, -musl variants). Any authenticated Cloudflare customer can pull from the library/ namespace without our account ID..changeset/ is descriptive (fix-stream-encoding.md, not patch.md)@cloudflare/sandbox is listedpatch (or minor for breaking changes)