Skip to content

Releases and Publishing

justin edited this page Aug 7, 2026 · 1 revision

Releases and Publishing

User updates

The canonical package is published on npm:

pi update npm:pi-meta-oauth

Each release is also mirrored to GitHub Packages as @blockedpath/pi-meta-oauth and receives a GitHub Release with generated notes.

Automated release flow

The repository's publish.yml workflow starts when a v* tag is pushed. It:

  1. Runs TypeScript checking and tests.
  2. Verifies that the tag matches the version in package.json.
  3. Publishes pi-meta-oauth to npm using trusted publishing and provenance.
  4. Publishes @blockedpath/pi-meta-oauth to GitHub Packages using the repository-scoped GITHUB_TOKEN.
  5. Creates the GitHub Release after both registries succeed.

The registry checks compare the published package's Git commit with the tagged commit, allowing a partially completed workflow to be safely re-run.

Maintainer release command

Start from a clean main branch after the intended changes have passed CI:

npm version patch -m "chore(release): v%s"
git push origin main --follow-tags

Use minor or major instead of patch when appropriate.

npm trusted publisher

The npm package must trust:

  • GitHub owner: BlockedPath
  • Repository: pi-meta-oauth
  • Workflow filename: publish.yml
  • Environment: blank
  • Allowed action: npm publish

GitHub Packages visibility

GitHub Packages creates new npm packages with private visibility by default. An administrator can open the package's settings and change its visibility to Public. GitHub warns that a public package cannot later be made private.

Clone this wiki locally