Two lanes to the same place. `make release` bumps, validates packaging, commits and tags locally, and `git push --follow-tags` fires release.yml; `make release:ci` does the whole thing in publish.yml. publish.yml pushes its tag with GITHUB_TOKEN, which by design does not trigger other workflows — so release.yml stays dormant for CI-cut releases instead of double-publishing. Both need an NPM_TOKEN secret.