Skip to content

Stage npm releases for owner approval - #11

Merged
ProgramComputer merged 1 commit into
mainfrom
release/staged-publishing
Sep 29, 2026
Merged

ProgramComputer merged 1 commit into
mainfrom
release/staged-publishing

Conversation

@ProgramComputer

Copy link
Copy Markdown
Owner

Switch the release workflow from direct npm publish to npm stage publish, matching the trusted publisher configured on npmjs.com with npm's recommended staged-only setting.

  • Release (release.yml) still rebuilds and tests the tag, packs one tarball, and runs the package gate. It then stages that exact tarball under next with provenance, and the run summary lists the tested integrity and the owner commands.
  • Verify release (verify-release.yml, new, no publishing permissions) runs after the owner approves the staged version (npm stage approve, 2FA). On Linux and Windows it checks that registry integrity matches the tested tarball and that next points at the version. It then installs fresh from the registry, reruns the MCP transport tests against the installed bin, and checks the provenance attestation and npm audit signatures.
  • RELEASING.md is updated for the approval step.

No package code changes; v1.1.0 still points at 08b189f.

@ProgramComputer
ProgramComputer merged commit 5412669 into main Sep 29, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant