Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

## Unreleased

- Prepared the public npm package as `@chumaniac/skillsync@0.1.0`, updated generated CI
- Prepared the public npm package as `@chumanic/skillsync@0.1.0`, updated generated CI
templates to pin the scoped package, and added tag-based OIDC/provenance publication
without a long-lived npm token.
- Documented the English-only documentation migration by aligning the public workflow
Expand Down
6 changes: 3 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -90,7 +90,7 @@ The most recent validation ran locally and offline inside the repository:

This project is published as a public source repository at [github.com/Chumaniac/skillsync](https://github.com/Chumaniac/skillsync). [`package.json`](./package.json) already includes `repository`, `homepage`, and `bugs` metadata.

The distributable CLI package is `@chumaniac/skillsync`. Scoped public access is declared in
The distributable CLI package is `@chumanic/skillsync`. Scoped public access is declared in
`package.json`, while the executable remains available as the `skillsync` command.

Tag releases run the full offline validation, inspect the package allowlist, and publish with
Expand Down Expand Up @@ -118,8 +118,8 @@ After a tagged release is published, install the CLI globally or run a pinned
version without a global install:

```bash
npm install --global @chumaniac/skillsync
npx --yes @chumaniac/skillsync@0.1.0 --help
npm install --global @chumanic/skillsync
npx --yes @chumanic/skillsync@0.1.0 --help
```

The executable name is `skillsync` in both cases.
Expand Down
4 changes: 2 additions & 2 deletions docs/ci.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ they can be replaced.

The generated GitHub Action grants `contents: read` and uploads SARIF findings;
it does not execute Skill scripts. The generated consumer command pins the
published SkillSync package version (`@chumaniac/skillsync@0.1.0` by default); override it
published SkillSync package version (`@chumanic/skillsync@0.1.0` by default); override it
with `ci init --package-version <version>` when upgrading. Because the current
repository publishes a scoped public package, the generated consumer template can
be used after that package version is available; the repository's own workflow uses
Expand Down Expand Up @@ -66,7 +66,7 @@ placeholders is intentionally not accepted as production evidence.

`.github/workflows/release.yml` runs only for tags matching `v*`. It checks the
test suite, type-check, lint, build, and `npm pack --dry-run`, then publishes
`@chumaniac/skillsync` with `npm publish --provenance --access public`. The job
`@chumanic/skillsync` with `npm publish --provenance --access public`. The job
uses GitHub OIDC (`id-token: write`) and no long-lived npm token. npm Trusted
Publisher configuration is an external prerequisite; a tag is not permission
to activate a live runtime capability.
Expand Down
8 changes: 4 additions & 4 deletions docs/release-readiness-2026-08-05.md
Original file line number Diff line number Diff line change
Expand Up @@ -184,19 +184,19 @@ and updated workflow filters.
## M6 npm package release preparation (2026-08-07)

The package release track now targets the scoped public package
`@chumaniac/skillsync`. The package metadata, generated consumer templates, and
`@chumanic/skillsync`. The package metadata, generated consumer templates, and
tag workflow are aligned. Publication uses GitHub OIDC and npm provenance rather
than a long-lived registry token; the npm Trusted Publisher configuration remains
an external one-time setup for the package owner.

| Review item | Result |
| --- | --- |
| Package identity | Prepared | `@chumaniac/skillsync@0.1.0`; the unscoped `skillsync` name is already occupied by another package |
| Package identity | Prepared | `@chumanic/skillsync@0.1.0`; the unscoped `skillsync` name is already occupied by another package |
| Public access | Prepared | `private: false` and `publishConfig.access: public` |
| Consumer templates | Pass | GitHub Action and pre-commit templates pin `@chumaniac/skillsync@0.1.0` |
| Consumer templates | Pass | GitHub Action and pre-commit templates pin `@chumanic/skillsync@0.1.0` |
| Release workflow | Prepared | Tag validation runs on Node 24, then publishes with OIDC and provenance; no npm token is stored in GitHub |
| npm Trusted Publisher | Pending owner setup | Configure user `Chumaniac`, repository `skillsync`, workflow `.github/workflows/release.yml`, and allow `npm publish` |
| First publication | Pending authentication | Requires an authenticated npm account that owns the `@chumaniac` scope |
| First publication | Pending authentication | Requires an authenticated npm account that owns the `@chumanic` scope |

This package track does not change the offline-first product boundary. Real
network access, provider credentials, Docker/microVM execution, and remote Worker
Expand Down
4 changes: 2 additions & 2 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions package.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"name": "@chumaniac/skillsync",
"name": "@chumanic/skillsync",
"version": "0.1.0",
"private": false,
"publishConfig": {
Expand All @@ -9,7 +9,7 @@
"description": "A provenance, compatibility, and behavior verification layer for Agent Skills.",
"repository": {
"type": "git",
"url": "https://github.com/Chumaniac/skillsync.git"
"url": "git+https://github.com/Chumaniac/skillsync.git"
},
"homepage": "https://github.com/Chumaniac/skillsync#readme",
"bugs": {
Expand Down
2 changes: 1 addition & 1 deletion src/cli/commands/ci.ts
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ export type CiInitResult = {

const DEFAULT_PATHS = [".agents/skills", ".claude/skills", ".cursor/skills"];
const DEFAULT_PACKAGE_VERSION = "0.1.0";
const PUBLISHED_PACKAGE_NAME = "@chumaniac/skillsync";
const PUBLISHED_PACKAGE_NAME = "@chumanic/skillsync";

function validateNodeVersion(value: string): string {
if (!/^\d+(?:\.\d+){0,2}$/.test(value)) {
Expand Down
4 changes: 2 additions & 2 deletions templates/github/skillsync.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,8 @@ jobs:
- uses: actions/setup-node@v4
with:
node-version: "20"
# Requires the published @chumaniac/skillsync@0.1.0 package.
- run: npx --yes @chumaniac/skillsync@0.1.0 verify --format sarif --path .agents/skills > skillsync.sarif
# Requires the published @chumanic/skillsync@0.1.0 package.
- run: npx --yes @chumanic/skillsync@0.1.0 verify --format sarif --path .agents/skills > skillsync.sarif
- uses: github/codeql-action/upload-sarif@v4
if: always()
with:
Expand Down
2 changes: 1 addition & 1 deletion templates/pre-commit/skillsync.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,6 @@ repos:
hooks:
- id: skillsync-verify
name: Verify Agent Skills with SkillSync
entry: npx --yes @chumaniac/skillsync@0.1.0 verify --format json --path .claude/skills --path .agents/skills
entry: npx --yes @chumanic/skillsync@0.1.0 verify --format json --path .claude/skills --path .agents/skills
language: system
pass_filenames: false
8 changes: 4 additions & 4 deletions tests/cli/ci.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,8 @@ describe("skillsync ci", () => {
const content = renderGitHubAction({ nodeVersion: "20", paths: [".agents/skills"], packageVersion: "0.1.0" });

expect(content).toContain("contents: read");
expect(content).toContain("npx --yes @chumaniac/skillsync@0.1.0 verify --format sarif");
expect(content).toContain("published @chumaniac/skillsync@0.1.0");
expect(content).toContain("npx --yes @chumanic/skillsync@0.1.0 verify --format sarif");
expect(content).toContain("published @chumanic/skillsync@0.1.0");
expect(content).toContain("github/codeql-action/upload-sarif@v4");
expect(content).toContain(".agents/skills/**");
});
Expand All @@ -28,7 +28,7 @@ describe("skillsync ci", () => {
expect(content).toContain("id: skillsync-verify");
expect(content).toContain(".claude/skills");
expect(content).toContain(".agents/skills");
expect(content).toContain("npx --yes @chumaniac/skillsync@0.1.0 verify --format json");
expect(content).toContain("npx --yes @chumanic/skillsync@0.1.0 verify --format json");
});

it("prints a plan without writing, and applies only when requested", async () => {
Expand All @@ -50,7 +50,7 @@ describe("skillsync ci", () => {
apply: true,
});
expect(applied.applied).toBe(true);
expect(await readFile(applied.outputPath, "utf8")).toContain("@chumaniac/skillsync@0.1.0 verify --format sarif");
expect(await readFile(applied.outputPath, "utf8")).toContain("@chumanic/skillsync@0.1.0 verify --format sarif");

await expect(
runCiInit({
Expand Down
8 changes: 4 additions & 4 deletions tests/docs/documentation.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -121,16 +121,16 @@ describe("release documentation", () => {
expect(repositoryWorkflow).toContain("SkillSync-Complete-Design.md");
expect(repositoryWorkflow).toContain("Competitive-Research-and-Design-Rationale.md");
expect(repositoryWorkflow).toContain("MVP-Implementation-Plan.md");
expect(githubTemplate).toContain("@chumaniac/skillsync@0.1.0");
expect(preCommitTemplate).toContain("@chumaniac/skillsync@0.1.0");
expect(githubTemplate).toContain("@chumanic/skillsync@0.1.0");
expect(preCommitTemplate).toContain("@chumanic/skillsync@0.1.0");
expect(review).toContain("runtime-activation-policy.ts");
expect(review).toContain("runtime-deployment-requirements.ts");
expect(packageJson.name).toBe("@chumaniac/skillsync");
expect(packageJson.name).toBe("@chumanic/skillsync");
expect(packageJson.private).toBe(false);
expect(packageJson.publishConfig).toEqual({ access: "public" });
expect(packageJson.repository).toEqual({
type: "git",
url: "https://github.com/Chumaniac/skillsync.git",
url: "git+https://github.com/Chumaniac/skillsync.git",
});
expect(packageJson.homepage).toBe("https://github.com/Chumaniac/skillsync#readme");
expect(packageJson.bugs).toEqual({
Expand Down
Loading