feat: zero-dependency npm registry setup script

scripts/setup-npm-registry.mjs configures npm to pull @redsentech
packages (e.g. @redsentech/lean-harness) from GitHub Packages:

- Discovers a token: --token flag > env (NPM_REGISTRY_TOKEN/
  GITHUB_TOKEN/GH_TOKEN) > `gh auth token` > interactive masked prompt
  (raw-mode stdin, no echo, no external deps).
- Verifies the token against the GitHub API, reports the authenticated
  login, and warns if the OAuth scopes are missing read:packages/
  write:packages.
- Writes/updates only its own two lines in .npmrc (scope registry +
  auth token), preserving every other line; idempotent on rerun.
- Never prints the full token (masked in all output).
- --dry-run, --unset (clean removal), --local, --scope, --registry,
  --skip-verify, --npmrc <path> flags.
- Confirms the result with `npm whoami --registry ...`.

Verified live end-to-end: real GitHub PAT via `gh auth token` ->
verified against api.github.com -> written to a scratch .npmrc ->
`npm whoami` succeeded. Also confirmed the scope-warning is accurate:
installing @redsentech/lean-harness with a token lacking read:packages
correctly 403s, exactly as the script warns it will.

Adds tests/setup-npm-registry.test.mjs (7 hermetic tests: dry-run,
write+preserve, token never printed, idempotent rerun, --unset,
custom scope/registry, clean failure with no token). Adds
"setup-npm-registry" npm script. Documents the script in README (The
`lh` CLI section) and docs/QUICKSTART.md (install + troubleshooting).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
2026-09-10 00:56:30 +02:00
co-authored by Copilot
parent 8330cf7900
commit 58471c286f
5 changed files with 425 additions and 6 deletions
+1
View File
@@ -190,6 +190,7 @@ Everything the harness does is self-documenting — nothing lives only in a chat
| `lh` not found after onboarding | Re-run without `--no-npm-link`, or invoke via the absolute path the script prints |
| Agents/skills installed via `copilot plugin install` but `lh init`/`lh doctor` fail with "command not found" | Expected — plugin install only adds the behaviour layer. Run `npm link` from a clone (path C) or `scripts/onboard.mjs` (path B) to get `lh` on `PATH` |
| `copilot plugin install owner/repo` prints a deprecation warning | Expected for direct-source installs. Use `copilot plugin marketplace add` + `copilot plugin install name@marketplace` instead (path A) |
| `npm install -g @redsentech/lean-harness` gives `404`/`403` | `.npmrc` isn't pointed at GitHub Packages, or the token lacks `read:packages`. Run `node scripts/setup-npm-registry.mjs` |
| Pipeline stuck at design gate | `interrogator` is waiting on your answers — this is intentional, answer the questions |
## Next steps