Repository navigation
Define the canonical npm package identity and align metadata #3
Description
Activity
This was generated by AI during triage.
Agent Brief
Category: enhancement
Summary: Move mdcode's canonical public npm identity to@gcmdev/mdcodeand align all package metadata and public documentation.Current behavior:
The published package ismdcode-tsat version0.0.4. Package metadata and public examples use inconsistent identities, includingmdcode-ts,mdcode, and@gcm/mdcode. The intended@gcmdev/mdcodepackage does not yet exist on npm, though the maintainer controls that scope.Desired behavior:
@gcmdev/mdcodebecomes the single canonical public package identity. All public install instructions, package metadata, repository references, badges, and import examples consistently use it. Existingmdcode-tsconsumers receive a documented migration path.Key interfaces:
- Published package manifest — package name, repository, homepage, exports, CLI binary, package files, and discoverability metadata must describe the canonical package.
- Public installation and import examples — use
@gcmdev/mdcodeand the documentedmdcodeCLI consistently. - Existing
mdcode-tspublication — determine and carry out the maintainer-approved deprecation/redirect strategy.
Acceptance criteria:
-
@gcmdev/mdcodeis reserved/published by the maintainer and exposes the documented CLI and library entry points. - Public metadata, README instructions, badges/links, keywords, and imports consistently name
@gcmdev/mdcode. - A clean install using the documented command provides the
mdcodeCLI. - The current
mdcode-tspackage has an explicit, documented migration/deprecation treatment. - Package contents include the correct README and distributable entry points.
Out of scope:
- Renaming the GitHub repository unless independently decided.
- New CLI features or changes to mdcode behavior.
- Claiming the npm scope, publishing packages, or setting npm deprecation metadata without the maintainer's authenticated account and final authorization.
Why this needs a human:
The maintainer must use the controlled@gcmdevnpm scope and make the irreversible publication/deprecation decisions. An agent can prepare and verify the repository changes but cannot complete those account-level actions.- addedenhancementNew feature or requestNew feature or requestready-for-humanRequires human implementation or external-account decisionsRequires human implementation or external-account decisions
on Aug 8, 2026 Plan
Canonical identity:
@gcmdev/mdcode. The CLI binary staysmdcode.Decisions
mdcode-ts:npm deprecateplus a migration note in the README. No shim release.packages/usage: depends on and imports the real name@gcmdev/mdcode(nomdcodealias).- First publish: the maintainer publishes
0.1.0by hand. CI does every release after that.
Current state (checked 2026-10-03)
- npm has
mdcode-ts@0.0.4(binmdcode).@gcmdev/mdcodedoes not exist yet. - The manifest's exports (
.,./cli), bin (mdcode → dist/main.js) andfiles: [dist, README.md]are already correct.npm pack --dry-runlists README, package.json and alldistJS and.d.tsfiles. @gcm/mdcodeno longer appears anywhere in the repo.mdcode-tsstill appears in: the package README (badge, about 20 install/import lines),examples/CLI_EXAMPLES.md(about 15), the rootpackage.jsonfilter scripts, the root README,CLAUDE.md,TESTING.md, JSDoc insrc/index.tsandsrc/types.ts,packages/usage/package.json("mdcode": "workspace:mdcode-ts@*"),pnpm-lock.yaml, and every pending.bumpy/*.mdchangeset.- Line 27 of
.bumpy/extract-region-splice-force.mdsays the docs "now name the published packagemdcode-ts". This needs rewriting.
Repo changes
These go on branch
3-package-identity, offmain.packages/mdcode/package.jsonname: "@gcmdev/mdcode"publishConfig.access: "public". A scoped package publishes as restricted by default, which would break a manualnpm publish.- Add
bugs. Sethomepageto…/mdcode-ts#readme. Addrepository.directory: "packages/mdcode". - Add the keywords
cliandmdcode-ts, so searches for the old name still find the package. - Fix the
--filterin thebpscript.
- Root
package.json: fix the--filterinbuild,devandtest:watch. packages/usage: change the dependency to"@gcmdev/mdcode": "workspace:*", update imports inlibrary-usage,parser,transformandtest-utils, then runpnpm installto refresh the lockfile.- Package README
- Shields badge:
img.shields.io/npm/v/@gcmdev/mdcode, linking tonpmjs.com/package/@gcmdev/mdcode. - Every install and import uses
@gcmdev/mdcode. Usenpx @gcmdev/mdcode …andpnpm dlx @gcmdev/mdcode …; both work because the package has a single bin. - Add a "Migrating from mdcode-ts" section: swap the dependency, update imports, and note that the
mdcodecommand is unchanged.
- Shields badge:
- Apply the same changes to
examples/CLI_EXAMPLES.md, the root README,CLAUDE.md,TESTING.mdand the JSDoc examples. - Changesets: rekey every pending changeset to
"@gcmdev/mdcode", fix line 27 ofextract-region-splice-force.md, and add aminorchangeset for the rename. Together with the other pending minors, the first release will be0.1.0. - Unchanged: GitHub URLs (
adrianbrowning/mdcode-ts), since renaming the repo is out of scope, and all CLI and runtime behaviour.
17-commonmark-fencesadds a changeset that isn't onmainyet. Whichever branch merges second rekeys it.Verification
pnpm build,pnpm testandpnpm -r lint:tsall pass.npm packinpackages/mdcodeproducesgcmdev-mdcode-*.tgzcontaining README, package.json and thedistentry points.- Clean install from that tarball in a fresh temp directory:
Use
npm init -y && npm i /path/to/gcmdev-mdcode-*.tgz npx --no-install mdcode --help # must resolve the locally installed bin npx --no-install mdcode list sample.md node -e "import('@gcmdev/mdcode').then(m => console.log(Object.keys(m)))"
--no-installbecause a plainnpx mdcodecan fall back to fetching a registry package calledmdcode, which would not prove that the scoped package supplied the CLI. - Grep for
mdcode-ts. The only remaining hits should be GitHub URLs, the migration note and the keyword.
Maintainer steps (manual first publish)
npm only lets you configure a trusted publisher for a package that already exists (npm-trust docs: "Package must exist").
bumpy-release.ymlpublishes through OIDC, so its first run can't create@gcmdev/mdcode. The order below avoids that problem.- Merge the rename PR. Bumpy runs in
version-prmode and opens a PR for@gcmdev/mdcode@0.1.0. Nothing is published at this point. - Don't merge the version PR yet. As an optional safeguard, add a required reviewer to the
publishGitHub environment so the publish job can't run without your approval. - Check out the version PR branch and publish:
This release won't have provenance. Every CI publish after it will.
pnpm build cd packages/mdcode npm publish --access public - Configure the trusted publisher for
@gcmdev/mdcodeon npmjs.com, or withnpm trust. Use repoadrianbrowning/mdcode-ts, workflowbumpy-release.yml, environmentpublish. - Merge the version PR. Bumpy checks the registry with
npm infobefore publishing, so it should skip0.1.0. Bumpy's handling of the git tag and GitHub release for a skipped version is unverified, so check them afterwards and create them by hand if they're missing. If you added a reviewer in step 2, remove it. - Deprecate the old package:
npm deprecate mdcode-ts "Renamed to @gcmdev/mdcode: npm i @gcmdev/mdcode"
If the version PR is merged before step 4, the publish job fails at OIDC authentication without publishing anything. Re-run the job after steps 3 and 4.
What to build
Establish one canonical public package identity for mdcode and make the repository and published-package metadata describe it consistently. A prospective user should encounter the same package name, install command, badges, and repository links everywhere they look.
Acceptance criteria
Blocked by
None - can start immediately