Repository navigation
Publishes to npm from a version tag push - #206
Merged
Merged
Conversation
A release workflow publishes @riddler/predicator to npm when a v*.*.* tag is pushed, and only when the tagged commit is on the default branch the push event names, the tag equals package.json's version there, npm does not already show that version, and the full gate, copied from ci.yml and read from gate.full, is green there. It publishes under npm trusted publishing: id-token write, no token anywhere, provenance automatic, npm checked against the floor and upgraded only when below it, and the prepack guard left to run. The authority table's npm publish row, its relay paragraph, the Release preps paragraph and the release recipe now say an agent or a session never runs npm publish: the workflow publishes on the tag push, and a failed run is re-run from its Actions page, never worked round by a local publish. ADR-0006 records the decision at proposed. No source file, version or tag moves. actionlint was not run. Run: the full pnpm gate green on this exact staged tree. Refs: pts-xt71
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The npm publish moves from a person's hand to a GitHub Actions workflow.
.github/workflows/release.ymlpublishes@riddler/predicatorwhen av*.*.*tag is pushed, and only when every check before the publish passesat the tagged commit:
named by the push event (
github.event.repository.default_branch), never aliteral name;
vequals.versioninpackage.jsonat that commit;reported, never published again; this also answers a re-run of a run that
did publish);
steps are copied byte for byte from
ci.yml, and the gate command is readfrom
gate.fullin.claude/wurk.jsonas CI reads it.The publish runs under npm trusted publishing: the job's permissions are
contents: readandid-token: write, no token exists in the file, therepository's secrets or anywhere else, and npm adds provenance itself. Before
the publish, node and npm are checked against trusted publishing's floor and
npm is upgraded only when it is below it.
npm publishruns undermise exec --, so the existingprepackpublish guard runs unchanged. Therun ends by printing the published version's address. Nothing else triggers
the workflow: no branch push, no pull request, no manual dispatch.
CLAUDE.md's boldnpm publishrow, two clauses of its relay paragraphand the publish sentence of its Release preps paragraph, and the publish
sentences of
.claude/wurk/release.md, now say the same thing: an agent or asession never runs
npm publish; the release workflow publishes on the tagpush the release-prep row already allows; a failed workflow is re-run from its
Actions page, never worked round by a local publish. The rewording is the
maintainer's own words, ruled by the operator, 2026-10-04.
ADR-0006 records the decision at proposed: the three conditions, the
registry, the trust model by name, what a failed publish does, the
documentation decision and that a published version stands. It also says a
re-run of a failed publish repeats the checks and the gate, and that a
prerelease tag is not a case it decides. It stays proposed
until a version has been published through the workflow.
No file under
src/changes, and no version or tag moves.Checks
mise exec -- pnpm run gate) green locally on this tree.actionlintwas not run: it is not installed on the machine this waswritten on. Instead the file was parsed as YAML, every
run:script passedbash -n, and the four check steps were exercised under bash in a scratchclone at the
v0.6.0tag with the step's environment set by hand: theancestry and version checks passed, the registry check stopped with
"already on npm", a mismatched tag name stopped the version check, an extra
commit off the default branch stopped the ancestry check, and an empty
default-branch name stopped the fetch. No step from the toolchain on, and
no publish, has run.
ci.ymland is identical.Direction check of the record
Every claim in ADR-0006 was checked against main and this branch:
package.json'srepository.url,files,publishConfigandprepackscript;
scripts/publish-guard.mjsas the guardprepackruns;.github/workflows/ci.yml's toolchain-to-gate steps;gate.fullin.claude/wurk.json; and each workflow step the record names, cited by itsstep name because the workflow exists only on this branch. The record cites no
commit.
git diff origin/main -- docs/adr/removes no line: the record is anew file and the index gains one row.
Provenance
read from the event, the version read from
package.jsonat the tag, thetoolchain copied from
ci.yml, npm trusted publishing, one record, no manualdispatch): decided by the conductor under a standing consent, 2026-10-03.
conductor under a standing consent, 2026-10-04.
mise.tomlpins already bundles an npm above the floor, so an unconditional upgrade
would only add an unpinned major to every release; the floor is still
enforced. Decided by the conductor under a standing consent, 2026-10-04.
the registry already shows is reported, not re-published".
concurrencyis set at the workflow's top level over its single job, keyedby the tag ref, with
cancel-in-progress: false.it false or ambiguous: in
CLAUDE.md's relay paragraph, "publishing" inthe list of what stays forbidden now reads "running
npm publish", and itslast clause names the workflow as what publishes; and the closing publish
sentence of
.claude/wurk/release.md. The ADRindex in
docs/adr/README.mdgains the new record's row, as every newrecord here has.
changelog.d/README.mdexcludes documentation, ADRsand CI changes.