# GESF NPM Publish Runbook Publish `@greenarmor/ges` and all workspace packages to npm for the first time. --- ## Prerequisites - [ ] Node >= 22.0.0 installed - [ ] pnpm >= 11.0.0 installed - [ ] npm account with publish rights to the `@greenarmor` org - [ ] `LICENSE` file exists at repo root (MIT) - [ ] All packages build cleanly - [ ] All packages have `"license": "MIT"` - [ ] Git working tree is clean ## Packages (publish order) Publish bottom-up (dependencies first, then dependents): | Order | Package | Type | |-------|---------|------| | 1 | `@greenarmor/ges-core` | library | | 2 | `@greenarmor/ges-compliance-engine` | library | | 3 | `@greenarmor/ges-audit-engine` | library | | 4 | `@greenarmor/ges-policy-engine` | library | | 5 | `@greenarmor/ges-rules-engine` | library | | 6 | `@greenarmor/ges-scoring-engine` | library | | 7 | `@greenarmor/ges-scanner-integration` | library | | 8 | `@greenarmor/ges-doc-generator` | library | | 9 | `@greenarmor/ges-cicd-generator` | library | | 10 | `@greenarmor/ges-report-generator` | library | | 11 | `@greenarmor/ges-mcp-server` | library | | 12 | `@greenarmor/ges` (CLI) | public entry point | --- ## Step 1 — Pre-flight checks ```bash # Ensure clean tree git status # Ensure on master (or release branch) git branch ``` ## Step 2 — Create LICENSE file ```bash cat > LICENSE <<'EOF' MIT License Copyright (c) 2025 Green Armor Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. EOF ``` ## Step 3 — Login to npm ```bash npm login ``` Verify: ```bash npm whoami # Should print your npm username ``` ## Step 4 — Create the `@greenarmor` org (first time only) If the org does not exist yet: ```bash npm org create greenarmor ``` Or create it at [https://www.npmjs.com/org/create](https://www.npmjs.com/org/create). ## Step 5 — Clean and build all packages ```bash # Clean previous builds pnpm run clean # Install dependencies pnpm install # Build all packages pnpm run build # Verify all dist/ directories exist ls packages/*/dist/index.js ``` If any package fails to build, stop and fix before continuing. ## Step 6 — Dry run (verify what will be published) ```bash # Dry run on each package pnpm -r publish --dry-run --access public ``` Review the output carefully: - Confirm only `dist/` is included in the tarballs (the `"files": ["dist"]` field in each package.json) - Confirm version is `0.1.0` - Confirm no unexpected files are bundled ## Step 7 — Publish all packages ### Option A: Single command (recommended) ```bash pnpm -r publish --access public --no-git-checks ``` `--no-git-checks` is needed because `pnpm publish` checks for a clean git tree by default, and workspace inter-dependencies (`workspace:*`) must be rewritten to real versions during publish. ### Option B: Manual (if order matters or for debugging) ```bash # Publish in dependency order cd packages/core && npm publish --access public cd ../compliance-engine && npm publish --access public cd ../audit-engine && npm publish --access public cd ../policy-engine && npm publish --access public cd ../rules-engine && npm publish --access public cd ../scoring-engine && npm publish --access public cd ../scanner-integration && npm publish --access public cd ../doc-generator && npm publish --access public cd ../cicd-generator && npm publish --access public cd ../report-generator && npm publish --access public cd ../mcp-server && npm publish --access public cd ../cli && npm publish --access public ``` ## Step 8 — Verify publication ```bash # Check that all packages are live npm view @greenarmor/ges version npm view @greenarmor/ges-core version npm view @greenarmor/ges-compliance-engine version npm view @greenarmor/ges-audit-engine version npm view @greenarmor/ges-policy-engine version npm view @greenarmor/ges-rules-engine version npm view @greenarmor/ges-scoring-engine version npm view @greenarmor/ges-scanner-integration version npm view @greenarmor/ges-doc-generator version npm view @greenarmor/ges-cicd-generator version npm view @greenarmor/ges-report-generator version npm view @greenarmor/ges-mcp-server version ``` All should return `0.1.0`. ## Step 9 — Smoke test the CLI ```bash # In a fresh directory mkdir /tmp/ges-test && cd /tmp/ges-test npx @greenarmor/ges --version # Should print 0.1.0 npx @greenarmor/ges --help # Should print available commands ``` ### Smoke test the MCP server (standandalone) ```bash # Verify the MCP server bin is accessible via npx npx @greenarmor/ges-mcp-server --help # Should print MCP server info or exit cleanly # Quick protocol test (initialize → tools/list) printf '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"0.1.0"}}}\n{"jsonrpc":"2.0","method":"notifications/initialized"}\n{"jsonrpc":"2.0","id":2,"method":"tools/list"}\n' | npx @greenarmor/ges-mcp-server # Should return JSON-RPC responses with 6 tools ``` ## Step 10 — Commit and tag the release ```bash cd /Users/tata/gesf git add -A git commit -m "release: v0.1.0" git tag v0.1.0 git push origin master --tags ``` --- ## Troubleshooting | Problem | Fix | |---------|-----| | `ENEEDAUTH` | Run `npm login` | | `E403 — scope not found` | Create the `@greenarmor` org on npm first | | `E403 — forbidden` | Your npm account needs publish rights to `@greenarmor` | | `EPUBLISHCONFLICT` | Version already published. Bump version before retrying. | | `workspace:*` in published tarball | pnpm rewrites `workspace:*` to real versions during `pnpm -r publish`. If not rewritten, use `--no-git-checks` and ensure pnpm >= 9. | | Build fails for a package | `cd packages/ && pnpm run build` to see the specific error | | Missing `dist/` in tarball | Confirm `"files": ["dist"]` is in the package's `package.json` | --- ## Future releases (bumping version) ```bash # Bump all packages at once pnpm -r exec npm version patch # or minor, or major # Or bump individually cd packages/cli && npm version minor # Then repeat from Step 5 ```