-
Notifications
You must be signed in to change notification settings - Fork 9
Releases and Publishing
The canonical package is published on npm:
pi update npm:pi-meta-oauthEach release is also mirrored to GitHub Packages as @blockedpath/pi-meta-oauth and receives a GitHub Release with generated notes.
The repository's publish.yml workflow starts when a v* tag is pushed. It:
- Runs TypeScript checking and tests.
- Verifies that the tag matches the version in
package.json. - Publishes
pi-meta-oauthto npm using trusted publishing and provenance. - Publishes
@blockedpath/pi-meta-oauthto GitHub Packages using the repository-scopedGITHUB_TOKEN. - Creates the GitHub Release after both registries succeed.
The registry checks compare the published package's Git commit with the tagged commit, allowing a partially completed workflow to be safely re-run.
Start from a clean main branch after the intended changes have passed CI:
npm version patch -m "chore(release): v%s"
git push origin main --follow-tagsUse minor or major instead of patch when appropriate.
The npm package must trust:
- GitHub owner:
BlockedPath - Repository:
pi-meta-oauth - Workflow filename:
publish.yml - Environment: blank
- Allowed action:
npm publish
GitHub Packages creates new npm packages with private visibility by default. An administrator can open the package's settings and change its visibility to Public. GitHub warns that a public package cannot later be made private.