Skip to content

Add safe one-time npm first-publication workflow - #8

Merged
DelshadH merged 1 commit into
mainfrom
codex/npm-first-publication-bootstrap
Jul 27, 2026
Merged

Add safe one-time npm first-publication workflow#8
DelshadH merged 1 commit into
mainfrom
codex/npm-first-publication-bootstrap

Conversation

@DelshadH

Copy link
Copy Markdown
Owner

Summary

  • publish the genuine reviewed 0.1.0-alpha.1 packages once from protected GitHub-hosted CI
  • verify exact artifacts, registry absence, provenance, and non-rerunnable incident handling
  • revoke the one-time token on every authenticated exit path and prohibit placeholders

Verification

  • clean token-free run: 154 tests, package smoke, examples, demo + recording, real upgrades, corpus, performance, security, release preparation
  • actionlint v1.7.12
  • immutable tarball SHA-256 verification and four registry E404 checks

No tag, GitHub release, npm token, or registry publication is created by this PR.

@DelshadH

Copy link
Copy Markdown
Owner Author

Exact-head token-free evidence for \

@DelshadH

Copy link
Copy Markdown
Owner Author

Independent exact-SHA release review: PASS for \

@DelshadH
DelshadH merged commit 198f19a into main Jul 27, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant