From 4edeb30657e247b48c279df9e475f5215e81dfc8 Mon Sep 17 00:00:00 2001 From: SkillSync Release Automation Date: Fri, 7 Aug 2026 17:44:34 +0800 Subject: [PATCH] fix: align npm package scope with owner --- CHANGELOG.md | 2 +- README.md | 6 +++--- docs/ci.md | 4 ++-- docs/release-readiness-2026-08-05.md | 8 ++++---- package-lock.json | 4 ++-- package.json | 4 ++-- src/cli/commands/ci.ts | 2 +- templates/github/skillsync.yml | 4 ++-- templates/pre-commit/skillsync.yaml | 2 +- tests/cli/ci.test.ts | 8 ++++---- tests/docs/documentation.test.ts | 8 ++++---- 11 files changed, 26 insertions(+), 26 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index d6eac36..946574e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,7 +2,7 @@ ## Unreleased -- Prepared the public npm package as `@chumaniac/skillsync@0.1.0`, updated generated CI +- Prepared the public npm package as `@chumanic/skillsync@0.1.0`, updated generated CI templates to pin the scoped package, and added tag-based OIDC/provenance publication without a long-lived npm token. - Documented the English-only documentation migration by aligning the public workflow diff --git a/README.md b/README.md index eeb7f89..3020209 100644 --- a/README.md +++ b/README.md @@ -90,7 +90,7 @@ The most recent validation ran locally and offline inside the repository: This project is published as a public source repository at [github.com/Chumaniac/skillsync](https://github.com/Chumaniac/skillsync). [`package.json`](./package.json) already includes `repository`, `homepage`, and `bugs` metadata. -The distributable CLI package is `@chumaniac/skillsync`. Scoped public access is declared in +The distributable CLI package is `@chumanic/skillsync`. Scoped public access is declared in `package.json`, while the executable remains available as the `skillsync` command. Tag releases run the full offline validation, inspect the package allowlist, and publish with @@ -118,8 +118,8 @@ After a tagged release is published, install the CLI globally or run a pinned version without a global install: ```bash -npm install --global @chumaniac/skillsync -npx --yes @chumaniac/skillsync@0.1.0 --help +npm install --global @chumanic/skillsync +npx --yes @chumanic/skillsync@0.1.0 --help ``` The executable name is `skillsync` in both cases. diff --git a/docs/ci.md b/docs/ci.md index 227e9a1..a70e214 100644 --- a/docs/ci.md +++ b/docs/ci.md @@ -13,7 +13,7 @@ they can be replaced. The generated GitHub Action grants `contents: read` and uploads SARIF findings; it does not execute Skill scripts. The generated consumer command pins the -published SkillSync package version (`@chumaniac/skillsync@0.1.0` by default); override it +published SkillSync package version (`@chumanic/skillsync@0.1.0` by default); override it with `ci init --package-version ` when upgrading. Because the current repository publishes a scoped public package, the generated consumer template can be used after that package version is available; the repository's own workflow uses @@ -66,7 +66,7 @@ placeholders is intentionally not accepted as production evidence. `.github/workflows/release.yml` runs only for tags matching `v*`. It checks the test suite, type-check, lint, build, and `npm pack --dry-run`, then publishes -`@chumaniac/skillsync` with `npm publish --provenance --access public`. The job +`@chumanic/skillsync` with `npm publish --provenance --access public`. The job uses GitHub OIDC (`id-token: write`) and no long-lived npm token. npm Trusted Publisher configuration is an external prerequisite; a tag is not permission to activate a live runtime capability. diff --git a/docs/release-readiness-2026-08-05.md b/docs/release-readiness-2026-08-05.md index 4128b46..9584947 100644 --- a/docs/release-readiness-2026-08-05.md +++ b/docs/release-readiness-2026-08-05.md @@ -184,19 +184,19 @@ and updated workflow filters. ## M6 npm package release preparation (2026-08-07) The package release track now targets the scoped public package -`@chumaniac/skillsync`. The package metadata, generated consumer templates, and +`@chumanic/skillsync`. The package metadata, generated consumer templates, and tag workflow are aligned. Publication uses GitHub OIDC and npm provenance rather than a long-lived registry token; the npm Trusted Publisher configuration remains an external one-time setup for the package owner. | Review item | Result | | --- | --- | -| Package identity | Prepared | `@chumaniac/skillsync@0.1.0`; the unscoped `skillsync` name is already occupied by another package | +| Package identity | Prepared | `@chumanic/skillsync@0.1.0`; the unscoped `skillsync` name is already occupied by another package | | Public access | Prepared | `private: false` and `publishConfig.access: public` | -| Consumer templates | Pass | GitHub Action and pre-commit templates pin `@chumaniac/skillsync@0.1.0` | +| Consumer templates | Pass | GitHub Action and pre-commit templates pin `@chumanic/skillsync@0.1.0` | | Release workflow | Prepared | Tag validation runs on Node 24, then publishes with OIDC and provenance; no npm token is stored in GitHub | | npm Trusted Publisher | Pending owner setup | Configure user `Chumaniac`, repository `skillsync`, workflow `.github/workflows/release.yml`, and allow `npm publish` | -| First publication | Pending authentication | Requires an authenticated npm account that owns the `@chumaniac` scope | +| First publication | Pending authentication | Requires an authenticated npm account that owns the `@chumanic` scope | This package track does not change the offline-first product boundary. Real network access, provider credentials, Docker/microVM execution, and remote Worker diff --git a/package-lock.json b/package-lock.json index 6f8a87a..e1a7281 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,11 +1,11 @@ { - "name": "@chumaniac/skillsync", + "name": "@chumanic/skillsync", "version": "0.1.0", "lockfileVersion": 3, "requires": true, "packages": { "": { - "name": "@chumaniac/skillsync", + "name": "@chumanic/skillsync", "version": "0.1.0", "license": "MIT", "dependencies": { diff --git a/package.json b/package.json index 3c1f1e7..ec7458d 100644 --- a/package.json +++ b/package.json @@ -1,5 +1,5 @@ { - "name": "@chumaniac/skillsync", + "name": "@chumanic/skillsync", "version": "0.1.0", "private": false, "publishConfig": { @@ -9,7 +9,7 @@ "description": "A provenance, compatibility, and behavior verification layer for Agent Skills.", "repository": { "type": "git", - "url": "https://github.com/Chumaniac/skillsync.git" + "url": "git+https://github.com/Chumaniac/skillsync.git" }, "homepage": "https://github.com/Chumaniac/skillsync#readme", "bugs": { diff --git a/src/cli/commands/ci.ts b/src/cli/commands/ci.ts index a6c179f..d0f6508 100644 --- a/src/cli/commands/ci.ts +++ b/src/cli/commands/ci.ts @@ -24,7 +24,7 @@ export type CiInitResult = { const DEFAULT_PATHS = [".agents/skills", ".claude/skills", ".cursor/skills"]; const DEFAULT_PACKAGE_VERSION = "0.1.0"; -const PUBLISHED_PACKAGE_NAME = "@chumaniac/skillsync"; +const PUBLISHED_PACKAGE_NAME = "@chumanic/skillsync"; function validateNodeVersion(value: string): string { if (!/^\d+(?:\.\d+){0,2}$/.test(value)) { diff --git a/templates/github/skillsync.yml b/templates/github/skillsync.yml index 93cc580..53da643 100644 --- a/templates/github/skillsync.yml +++ b/templates/github/skillsync.yml @@ -17,8 +17,8 @@ jobs: - uses: actions/setup-node@v4 with: node-version: "20" - # Requires the published @chumaniac/skillsync@0.1.0 package. - - run: npx --yes @chumaniac/skillsync@0.1.0 verify --format sarif --path .agents/skills > skillsync.sarif + # Requires the published @chumanic/skillsync@0.1.0 package. + - run: npx --yes @chumanic/skillsync@0.1.0 verify --format sarif --path .agents/skills > skillsync.sarif - uses: github/codeql-action/upload-sarif@v4 if: always() with: diff --git a/templates/pre-commit/skillsync.yaml b/templates/pre-commit/skillsync.yaml index 53abe77..7d4332a 100644 --- a/templates/pre-commit/skillsync.yaml +++ b/templates/pre-commit/skillsync.yaml @@ -3,6 +3,6 @@ repos: hooks: - id: skillsync-verify name: Verify Agent Skills with SkillSync - entry: npx --yes @chumaniac/skillsync@0.1.0 verify --format json --path .claude/skills --path .agents/skills + entry: npx --yes @chumanic/skillsync@0.1.0 verify --format json --path .claude/skills --path .agents/skills language: system pass_filenames: false diff --git a/tests/cli/ci.test.ts b/tests/cli/ci.test.ts index 0c17ff9..081d874 100644 --- a/tests/cli/ci.test.ts +++ b/tests/cli/ci.test.ts @@ -16,8 +16,8 @@ describe("skillsync ci", () => { const content = renderGitHubAction({ nodeVersion: "20", paths: [".agents/skills"], packageVersion: "0.1.0" }); expect(content).toContain("contents: read"); - expect(content).toContain("npx --yes @chumaniac/skillsync@0.1.0 verify --format sarif"); - expect(content).toContain("published @chumaniac/skillsync@0.1.0"); + expect(content).toContain("npx --yes @chumanic/skillsync@0.1.0 verify --format sarif"); + expect(content).toContain("published @chumanic/skillsync@0.1.0"); expect(content).toContain("github/codeql-action/upload-sarif@v4"); expect(content).toContain(".agents/skills/**"); }); @@ -28,7 +28,7 @@ describe("skillsync ci", () => { expect(content).toContain("id: skillsync-verify"); expect(content).toContain(".claude/skills"); expect(content).toContain(".agents/skills"); - expect(content).toContain("npx --yes @chumaniac/skillsync@0.1.0 verify --format json"); + expect(content).toContain("npx --yes @chumanic/skillsync@0.1.0 verify --format json"); }); it("prints a plan without writing, and applies only when requested", async () => { @@ -50,7 +50,7 @@ describe("skillsync ci", () => { apply: true, }); expect(applied.applied).toBe(true); - expect(await readFile(applied.outputPath, "utf8")).toContain("@chumaniac/skillsync@0.1.0 verify --format sarif"); + expect(await readFile(applied.outputPath, "utf8")).toContain("@chumanic/skillsync@0.1.0 verify --format sarif"); await expect( runCiInit({ diff --git a/tests/docs/documentation.test.ts b/tests/docs/documentation.test.ts index 7b3b1a6..4e4882c 100644 --- a/tests/docs/documentation.test.ts +++ b/tests/docs/documentation.test.ts @@ -121,16 +121,16 @@ describe("release documentation", () => { expect(repositoryWorkflow).toContain("SkillSync-Complete-Design.md"); expect(repositoryWorkflow).toContain("Competitive-Research-and-Design-Rationale.md"); expect(repositoryWorkflow).toContain("MVP-Implementation-Plan.md"); - expect(githubTemplate).toContain("@chumaniac/skillsync@0.1.0"); - expect(preCommitTemplate).toContain("@chumaniac/skillsync@0.1.0"); + expect(githubTemplate).toContain("@chumanic/skillsync@0.1.0"); + expect(preCommitTemplate).toContain("@chumanic/skillsync@0.1.0"); expect(review).toContain("runtime-activation-policy.ts"); expect(review).toContain("runtime-deployment-requirements.ts"); - expect(packageJson.name).toBe("@chumaniac/skillsync"); + expect(packageJson.name).toBe("@chumanic/skillsync"); expect(packageJson.private).toBe(false); expect(packageJson.publishConfig).toEqual({ access: "public" }); expect(packageJson.repository).toEqual({ type: "git", - url: "https://github.com/Chumaniac/skillsync.git", + url: "git+https://github.com/Chumaniac/skillsync.git", }); expect(packageJson.homepage).toBe("https://github.com/Chumaniac/skillsync#readme"); expect(packageJson.bugs).toEqual({