Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@

## Unreleased

- Prepared the public npm package as `@chumanic/skillsync@0.1.0`, updated generated CI
templates to pin the scoped package, and added tag-based OIDC/provenance publication
without a long-lived npm token.
- Published and smoke-tested the public npm package `@chumanic/skillsync@0.1.0`; a clean
consumer install, `skillsync --help`, and the package audit passed. Future tag releases
use the configured OIDC/provenance workflow without a long-lived npm token.
- Documented the English-only documentation migration by aligning the public workflow
filters with `MVP-Implementation-Plan.md`, `SkillSync-Complete-Design.md`, and
`Competitive-Research-and-Design-Rationale.md`; historical versions remain available
Expand Down
13 changes: 7 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -93,10 +93,11 @@ This project is published as a public source repository at [github.com/Chumaniac
The distributable CLI package is `@chumanic/skillsync`. Scoped public access is declared in
`package.json`, while the executable remains available as the `skillsync` command.

Tag releases run the full offline validation, inspect the package allowlist, and publish with
GitHub OIDC and npm provenance. The release workflow does not store or use a long-lived npm
token. The package's npm Trusted Publisher must be configured for `Chumaniac/skillsync` and
`.github/workflows/release.yml` before a tag can publish successfully.
The initial `0.1.0` package is published on npm. Future tag releases run the full offline
validation, inspect the package allowlist, and publish with GitHub OIDC and npm provenance.
The release workflow does not store or use a long-lived npm token. The package's npm Trusted
Publisher must be configured for `Chumaniac/skillsync` and `.github/workflows/release.yml`
before a tag can publish a future version successfully.

### Report privacy boundary

Expand All @@ -114,8 +115,8 @@ This option controls only whether local paths are preserved. It does not change

## Install from npm

After a tagged release is published, install the CLI globally or run a pinned
version without a global install:
The initial public package release is available on npm. Install the CLI globally or run a
pinned version without a global install:

```bash
npm install --global @chumanic/skillsync
Expand Down
20 changes: 20 additions & 0 deletions docs/release-readiness-2026-08-05.md
Original file line number Diff line number Diff line change
Expand Up @@ -202,3 +202,23 @@ This package track does not change the offline-first product boundary. Real
network access, provider credentials, Docker/microVM execution, and remote Worker
execution remain disabled pending the independent security and controlled-runtime
gates above.

## M7 npm publication closeout (2026-08-08)

The initial public package release is now available as
`@chumanic/skillsync@0.1.0`. The package was published interactively after the
release checks passed and was verified from a clean consumer directory.

| Review item | Result |
| --- | --- |
| Public registry metadata | Pass | Anonymous registry lookup resolves version `0.1.0` with the `latest` tag |
| Clean consumer install | Pass | `npm install --ignore-scripts @chumanic/skillsync@0.1.0` completed successfully |
| CLI smoke test | Pass | The installed `skillsync --help` command rendered the public command list |
| Package audit | Pass | The clean install reported zero vulnerabilities |
| npm Trusted Publisher | Pending owner setup | Configure user `Chumaniac`, repository `skillsync`, workflow `release.yml`, and allow `npm publish` |
| Future tag publication | Pending owner setup | The GitHub OIDC/provenance workflow is ready, but the npm Trusted Publisher must be configured before publishing a future tag |

This closeout confirms public distribution and local consumer usability. It does
not approve live network access, provider credentials, Docker/microVM execution,
or remote Worker execution; those remain separate security and controlled-runtime
gates.
Loading