Skip to content

release: prepare scoped public npm package - #3

Merged
Chumaniac merged 1 commit into
mainfrom
release/npm-package
Aug 7, 2026
Merged

Chumaniac merged 1 commit into
mainfrom
release/npm-package

Conversation

@Chumaniac

Copy link
Copy Markdown
Owner

What changed

  • Switch the distributable package to @chumaniac/skillsync because the unscoped skillsync name is already occupied.
  • Mark the package public and declare publishConfig.access: public.
  • Update generated GitHub/pre-commit templates to pin the scoped package.
  • Add tag-based npm publication through GitHub OIDC with provenance and no long-lived npm token.
  • Document npm installation, Trusted Publisher setup, and the remaining live-runtime boundaries.

Validation

  • npm run check — 69 test files passed, 1 skipped; 426 tests passed, 1 skipped; type-check, lint, and build passed.
  • npm pack --dry-run — public allowlist inspected successfully.
  • Fresh install from the generated tarball — CLI version and help verified.
  • git diff --check — passed.

Release prerequisite

Before merging a release tag, configure the npm Trusted Publisher for user Chumaniac, repository skillsync, workflow .github/workflows/release.yml, with npm publish allowed. The package remains offline-first; live runtime capabilities are still disabled pending independent security and controlled-environment approval.

@Chumaniac
Chumaniac marked this pull request as ready for review August 7, 2026 09:25
@Chumaniac
Chumaniac merged commit d9983b2 into main Aug 7, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant