Skip to content

runbook publish npm

greenarmor edited this page Jul 2, 2026 · 1 revision

GESF NPM Publish Runbook

Publish @greenarmor/ges and all workspace packages to npm for the first time.


Prerequisites

  • Node >= 22.0.0 installed
  • pnpm >= 11.0.0 installed
  • npm account with publish rights to the @greenarmor org
  • LICENSE file exists at repo root (MIT)
  • All packages build cleanly
  • All packages have "license": "MIT"
  • Git working tree is clean

Packages (publish order)

Publish bottom-up (dependencies first, then dependents):

Order Package Type
1 @greenarmor/ges-core library
2 @greenarmor/ges-compliance-engine library
3 @greenarmor/ges-audit-engine library
4 @greenarmor/ges-policy-engine library
5 @greenarmor/ges-rules-engine library
6 @greenarmor/ges-scoring-engine library
7 @greenarmor/ges-scanner-integration library
8 @greenarmor/ges-doc-generator library
9 @greenarmor/ges-cicd-generator library
10 @greenarmor/ges-report-generator library
11 @greenarmor/ges-mcp-server library
12 @greenarmor/ges (CLI) public entry point

Step 1 — Pre-flight checks

# Ensure clean tree
git status

# Ensure on master (or release branch)
git branch

Step 2 — Create LICENSE file

cat > LICENSE <<'EOF'
MIT License

Copyright (c) 2025 Green Armor

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
EOF

Step 3 — Login to npm

npm login

Verify:

npm whoami
# Should print your npm username

Step 4 — Create the @greenarmor org (first time only)

If the org does not exist yet:

npm org create greenarmor

Or create it at https://www.npmjs.com/org/create.

Step 5 — Clean and build all packages

# Clean previous builds
pnpm run clean

# Install dependencies
pnpm install

# Build all packages
pnpm run build

# Verify all dist/ directories exist
ls packages/*/dist/index.js

If any package fails to build, stop and fix before continuing.

Step 6 — Dry run (verify what will be published)

# Dry run on each package
pnpm -r publish --dry-run --access public

Review the output carefully:

  • Confirm only dist/ is included in the tarballs (the "files": ["dist"] field in each package.json)
  • Confirm version is 0.1.0
  • Confirm no unexpected files are bundled

Step 7 — Publish all packages

Option A: Single command (recommended)

pnpm -r publish --access public --no-git-checks

--no-git-checks is needed because pnpm publish checks for a clean git tree by default, and workspace inter-dependencies (workspace:*) must be rewritten to real versions during publish.

Option B: Manual (if order matters or for debugging)

# Publish in dependency order
cd packages/core && npm publish --access public
cd ../compliance-engine && npm publish --access public
cd ../audit-engine && npm publish --access public
cd ../policy-engine && npm publish --access public
cd ../rules-engine && npm publish --access public
cd ../scoring-engine && npm publish --access public
cd ../scanner-integration && npm publish --access public
cd ../doc-generator && npm publish --access public
cd ../cicd-generator && npm publish --access public
cd ../report-generator && npm publish --access public
cd ../mcp-server && npm publish --access public
cd ../cli && npm publish --access public

Step 8 — Verify publication

# Check that all packages are live
npm view @greenarmor/ges version
npm view @greenarmor/ges-core version
npm view @greenarmor/ges-compliance-engine version
npm view @greenarmor/ges-audit-engine version
npm view @greenarmor/ges-policy-engine version
npm view @greenarmor/ges-rules-engine version
npm view @greenarmor/ges-scoring-engine version
npm view @greenarmor/ges-scanner-integration version
npm view @greenarmor/ges-doc-generator version
npm view @greenarmor/ges-cicd-generator version
npm view @greenarmor/ges-report-generator version
npm view @greenarmor/ges-mcp-server version

All should return 0.1.0.

Step 9 — Smoke test the CLI

# In a fresh directory
mkdir /tmp/ges-test && cd /tmp/ges-test

npx @greenarmor/ges --version
# Should print 0.1.0

npx @greenarmor/ges --help
# Should print available commands

Smoke test the MCP server (standandalone)

# Verify the MCP server bin is accessible via npx
npx @greenarmor/ges-mcp-server --help
# Should print MCP server info or exit cleanly

# Quick protocol test (initialize → tools/list)
printf '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"0.1.0"}}}\n{"jsonrpc":"2.0","method":"notifications/initialized"}\n{"jsonrpc":"2.0","id":2,"method":"tools/list"}\n' | npx @greenarmor/ges-mcp-server
# Should return JSON-RPC responses with 6 tools

Step 10 — Commit and tag the release

cd /Users/tata/gesf

git add -A
git commit -m "release: v0.1.0"
git tag v0.1.0
git push origin master --tags

Troubleshooting

Problem Fix
ENEEDAUTH Run npm login
E403 — scope not found Create the @greenarmor org on npm first
E403 — forbidden Your npm account needs publish rights to @greenarmor
EPUBLISHCONFLICT Version already published. Bump version before retrying.
workspace:* in published tarball pnpm rewrites workspace:* to real versions during pnpm -r publish. If not rewritten, use --no-git-checks and ensure pnpm >= 9.
Build fails for a package cd packages/<pkg> && pnpm run build to see the specific error
Missing dist/ in tarball Confirm "files": ["dist"] is in the package's package.json

Future releases (bumping version)

# Bump all packages at once
pnpm -r exec npm version patch   # or minor, or major

# Or bump individually
cd packages/cli && npm version minor

# Then repeat from Step 5

Clone this wiki locally