From 8330cf7900f3fab6b629c3682dfa3fefb204c976 Mon Sep 17 00:00:00 2001 From: Giancarmine Salucci Date: Thu, 10 Sep 2026 00:51:06 +0200 Subject: [PATCH] ci: publish @redsentech/lean-harness to GitHub Packages - Rename npm package scope @redsen -> @redsentech (GitHub Packages requires the scope to match the owning org/user login). - Add publishConfig.registry pointing at npm.pkg.github.com. - Add .github/workflows/publish.yml: on push of a vX.Y.Z tag (or manual dispatch), runs validate + test, checks the tag matches package.json's version, then npm publish using the auto-issued GITHUB_TOKEN (packages: write permission, no secret to manage). - Update README/QUICKSTART lh-CLI install instructions for the private, org-scoped registry (.npmrc scope + auth token setup). - Verified locally with npm publish --dry-run: 68 files, correct registry target, correct tarball contents. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- .github/workflows/publish.yml | 51 +++++++++++++++++++++++++++++++++++ README.md | 21 ++++++++++++--- docs/QUICKSTART.md | 6 ++--- package.json | 5 +++- 4 files changed, 75 insertions(+), 8 deletions(-) create mode 100644 .github/workflows/publish.yml diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml new file mode 100644 index 0000000..e184b78 --- /dev/null +++ b/.github/workflows/publish.yml @@ -0,0 +1,51 @@ +name: Publish + +# Builds and publishes @redsentech/lean-harness to GitHub Packages (npm.pkg.github.com), +# a private-by-default scoped registry tied to this repository — not the public npm registry. +# +# Triggers: +# - push of a version tag (v0.1.0, v1.2.3, ...) — the normal release path +# - manual dispatch, for re-publishing without cutting a new tag +# +# Auth: GITHUB_TOKEN (auto-issued per run, no secret to manage) is sufficient for GitHub +# Packages when the job declares `permissions: packages: write`. + +on: + push: + tags: + - 'v*.*.*' + workflow_dispatch: + +permissions: + contents: read + packages: write + +jobs: + publish: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + + - uses: actions/setup-node@v4 + with: + node-version: '20' + registry-url: 'https://npm.pkg.github.com' + scope: '@redsentech' + + - run: npm install + - run: npm run validate + - run: npm test + + - name: Verify tag matches package.json version + if: github.event_name == 'push' + run: | + TAG_VERSION="${GITHUB_REF_NAME#v}" + PKG_VERSION="$(node -p "require('./package.json').version")" + if [ "$TAG_VERSION" != "$PKG_VERSION" ]; then + echo "::error::tag v$TAG_VERSION does not match package.json version $PKG_VERSION" + exit 1 + fi + + - run: npm publish + env: + NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/README.md b/README.md index 82d5e88..a4c7ce0 100644 --- a/README.md +++ b/README.md @@ -68,12 +68,24 @@ read by both hosts. ### The `lh` CLI The behaviour layer above only works if the agents can actually call `lh` — it's what runs -`lh init`/`lh doctor`/`lh graph`/etc. under the hood. Not yet on the npm registry, so today: +`lh init`/`lh doctor`/`lh graph`/etc. under the hood. Published to **GitHub Packages** +(`npm.pkg.github.com`), a private, org-scoped registry — not the public npm registry, so it +needs one extra step: + +```bash +# one-time: point the @redsentech scope at GitHub Packages, with a token that has read:packages +echo "@redsentech:registry=https://npm.pkg.github.com" >> ~/.npmrc +echo "//npm.pkg.github.com/:_authToken=${GITHUB_TOKEN}" >> ~/.npmrc + +npm install -g @redsentech/lean-harness # or: npx @redsentech/lean-harness +lh doctor # verify the environment +``` + +No published version yet? Clone and link instead: ```bash git clone git@github.com:redsentech/lean-harness.git && cd lean-harness && npm install npm link # puts `lh` on PATH globally -# once published: npm install -g @redsen/lean-harness (or: npx @redsen/lean-harness ) lh doctor # verify the environment ``` @@ -141,8 +153,9 @@ node scripts/onboard.mjs /path/to/target-repo --yes # do it Safe to re-run: files that are already identical are left alone, and re-running `lh init` on an already-initialized repo warns instead of failing (rerun with `lh init --force` to reset). -`npm install -g @redsen/lean-harness` (once published) replaces steps 3–5 of the script with a -normal global install. +`npm install -g @redsentech/lean-harness` (once your `.npmrc` points `@redsentech` at GitHub +Packages — see [The `lh` CLI](#the-lh-cli)) replaces steps 3–5 of the script with a normal +global install. ## Pipeline diff --git a/docs/QUICKSTART.md b/docs/QUICKSTART.md index f7c3d22..43193c0 100644 --- a/docs/QUICKSTART.md +++ b/docs/QUICKSTART.md @@ -43,9 +43,9 @@ Use this when: you're a day-to-day Copilot CLI user who wants the harness availa multiple projects and doesn't need to modify the harness itself. Limitation: this installs the *behaviour* layer only. You still need `lh` on `PATH` (see -below) for `lh init`/`lh doctor` and everything the agents call automatically — the package -isn't on the npm registry yet, so today that means step B or C, not `npm install -g` (the -README's `npm install -g @redsen/lean-harness` line is the path once it's published). +below) — either `npm install -g @redsentech/lean-harness` from GitHub Packages (once you've +pointed the `@redsentech` scope at it, see [The `lh` CLI](../README.md#the-lh-cli)), or step +B/C below. ### B. Bootstrap an existing repo with the onboarding script diff --git a/package.json b/package.json index df62f8e..3de2965 100644 --- a/package.json +++ b/package.json @@ -1,5 +1,5 @@ { - "name": "@redsen/lean-harness", + "name": "@redsentech/lean-harness", "version": "0.1.0", "description": "Imperative, token-lean, self-documenting agent harness for GitHub Copilot CLI and VS Code Copilot.", "license": "MIT", @@ -8,6 +8,9 @@ "type": "git", "url": "git+https://github.com/redsentech/lean-harness.git" }, + "publishConfig": { + "registry": "https://npm.pkg.github.com" + }, "type": "module", "engines": { "node": ">=20"