@gapwise/cli is the intended public npm identity. The canonical source is GapwiseHQ/cli. A release is the same version in package.json, the npm registry, the vX.Y.Z Git tag, and GitHub Releases.
- Make changes on a feature branch, run
npm run check, and merge a green PR tomainwithout bypassing protection. - Update
package.jsonwith the intended SemVer version in the PR. Describe user-visible changes in the PR. - Verify
npm pack --dry-runand a clean install of the artifact;npm run checkdoes both. - Check that the npm version is unused before creating the tag.
The tag workflow tests on Node 24, verifies the tag matches package.json and points to a commit on main, publishes via npm Trusted Publishing if the version does not already exist, independently installs the registry package, and creates a GitHub Release. CI also tests Node 22. The workflow never stores a publish token. npm supplies provenance automatically for a public package published from the public GitHub repository through its trusted publisher.
The first release requires an account that can publish under @gapwise; this repository cannot grant npm ownership. The current agent environment has no authenticated npm account. From a clean checkout of merged main, the npm owner should:
npm login
npm whoami
npm run check
npm publish --access publicThe initial 0.2.0 bootstrap was published manually to establish @gapwise/cli on the npm registry. For version 0.2.1 (which normalizes the bin path to bin/gapwise.mjs and verifies clean npx/global execution), from a clean checkout of merged main:
npm login
npm whoami
npm run check
npm publish --access publicIf npm Trusted Publishing has been configured for @gapwise/cli:
- Provider: GitHub Actions
- Organization/user:
GapwiseHQ - Repository:
cli - Workflow filename:
release.yml - Allowed action: direct
npm publish
Then create and push an annotated v0.2.1 tag on the same merged main commit. The workflow checks the existing registry version, verifies its install, and creates the corresponding GitHub Release. Subsequent new versions publish from the tag workflow through OIDC and get npm provenance. Keep the initial manual publish distinct from provenance-bearing OIDC releases; do not claim provenance for manual releases.
If an npm owner authorizes this workspace with an interactive login, the maintainer can complete the publish here and perform the external verification. Never commit auth tokens or .npmrc credentials.