diff --git a/CHANGELOG.md b/CHANGELOG.md index 946574e..08ce8d8 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,9 +2,9 @@ ## Unreleased -- Prepared the public npm package as `@chumanic/skillsync@0.1.0`, updated generated CI - templates to pin the scoped package, and added tag-based OIDC/provenance publication - without a long-lived npm token. +- Published and smoke-tested the public npm package `@chumanic/skillsync@0.1.0`; a clean + consumer install, `skillsync --help`, and the package audit passed. Future tag releases + use the configured OIDC/provenance workflow without a long-lived npm token. - Documented the English-only documentation migration by aligning the public workflow filters with `MVP-Implementation-Plan.md`, `SkillSync-Complete-Design.md`, and `Competitive-Research-and-Design-Rationale.md`; historical versions remain available diff --git a/README.md b/README.md index 3020209..431da63 100644 --- a/README.md +++ b/README.md @@ -93,10 +93,11 @@ This project is published as a public source repository at [github.com/Chumaniac The distributable CLI package is `@chumanic/skillsync`. Scoped public access is declared in `package.json`, while the executable remains available as the `skillsync` command. -Tag releases run the full offline validation, inspect the package allowlist, and publish with -GitHub OIDC and npm provenance. The release workflow does not store or use a long-lived npm -token. The package's npm Trusted Publisher must be configured for `Chumaniac/skillsync` and -`.github/workflows/release.yml` before a tag can publish successfully. +The initial `0.1.0` package is published on npm. Future tag releases run the full offline +validation, inspect the package allowlist, and publish with GitHub OIDC and npm provenance. +The release workflow does not store or use a long-lived npm token. The package's npm Trusted +Publisher must be configured for `Chumaniac/skillsync` and `.github/workflows/release.yml` +before a tag can publish a future version successfully. ### Report privacy boundary @@ -114,8 +115,8 @@ This option controls only whether local paths are preserved. It does not change ## Install from npm -After a tagged release is published, install the CLI globally or run a pinned -version without a global install: +The initial public package release is available on npm. Install the CLI globally or run a +pinned version without a global install: ```bash npm install --global @chumanic/skillsync diff --git a/docs/release-readiness-2026-08-05.md b/docs/release-readiness-2026-08-05.md index 9584947..ec765fa 100644 --- a/docs/release-readiness-2026-08-05.md +++ b/docs/release-readiness-2026-08-05.md @@ -202,3 +202,23 @@ This package track does not change the offline-first product boundary. Real network access, provider credentials, Docker/microVM execution, and remote Worker execution remain disabled pending the independent security and controlled-runtime gates above. + +## M7 npm publication closeout (2026-08-08) + +The initial public package release is now available as +`@chumanic/skillsync@0.1.0`. The package was published interactively after the +release checks passed and was verified from a clean consumer directory. + +| Review item | Result | +| --- | --- | +| Public registry metadata | Pass | Anonymous registry lookup resolves version `0.1.0` with the `latest` tag | +| Clean consumer install | Pass | `npm install --ignore-scripts @chumanic/skillsync@0.1.0` completed successfully | +| CLI smoke test | Pass | The installed `skillsync --help` command rendered the public command list | +| Package audit | Pass | The clean install reported zero vulnerabilities | +| npm Trusted Publisher | Pending owner setup | Configure user `Chumaniac`, repository `skillsync`, workflow `release.yml`, and allow `npm publish` | +| Future tag publication | Pending owner setup | The GitHub OIDC/provenance workflow is ready, but the npm Trusted Publisher must be configured before publishing a future tag | + +This closeout confirms public distribution and local consumer usability. It does +not approve live network access, provider credentials, Docker/microVM execution, +or remote Worker execution; those remain separate security and controlled-runtime +gates.