ci: publish @redsentech/lean-harness to GitHub Packages

- Rename npm package scope @redsen -> @redsentech (GitHub Packages
  requires the scope to match the owning org/user login).
- Add publishConfig.registry pointing at npm.pkg.github.com.
- Add .github/workflows/publish.yml: on push of a vX.Y.Z tag (or manual
  dispatch), runs validate + test, checks the tag matches
  package.json's version, then npm publish using the auto-issued
  GITHUB_TOKEN (packages: write permission, no secret to manage).
- Update README/QUICKSTART lh-CLI install instructions for the private,
  org-scoped registry (.npmrc scope + auth token setup).
- Verified locally with npm publish --dry-run: 68 files, correct
  registry target, correct tarball contents.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
2026-09-10 00:51:06 +02:00
co-authored by Copilot
parent cadbec5797
commit 8330cf7900
4 changed files with 75 additions and 8 deletions
+51
View File
@@ -0,0 +1,51 @@
name: Publish
# Builds and publishes @redsentech/lean-harness to GitHub Packages (npm.pkg.github.com),
# a private-by-default scoped registry tied to this repository — not the public npm registry.
#
# Triggers:
# - push of a version tag (v0.1.0, v1.2.3, ...) — the normal release path
# - manual dispatch, for re-publishing without cutting a new tag
#
# Auth: GITHUB_TOKEN (auto-issued per run, no secret to manage) is sufficient for GitHub
# Packages when the job declares `permissions: packages: write`.
on:
push:
tags:
- 'v*.*.*'
workflow_dispatch:
permissions:
contents: read
packages: write
jobs:
publish:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '20'
registry-url: 'https://npm.pkg.github.com'
scope: '@redsentech'
- run: npm install
- run: npm run validate
- run: npm test
- name: Verify tag matches package.json version
if: github.event_name == 'push'
run: |
TAG_VERSION="${GITHUB_REF_NAME#v}"
PKG_VERSION="$(node -p "require('./package.json').version")"
if [ "$TAG_VERSION" != "$PKG_VERSION" ]; then
echo "::error::tag v$TAG_VERSION does not match package.json version $PKG_VERSION"
exit 1
fi
- run: npm publish
env:
NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+17 -4
View File
@@ -68,12 +68,24 @@ read by both hosts.
### The `lh` CLI ### The `lh` CLI
The behaviour layer above only works if the agents can actually call `lh` — it's what runs The behaviour layer above only works if the agents can actually call `lh` — it's what runs
`lh init`/`lh doctor`/`lh graph`/etc. under the hood. Not yet on the npm registry, so today: `lh init`/`lh doctor`/`lh graph`/etc. under the hood. Published to **GitHub Packages**
(`npm.pkg.github.com`), a private, org-scoped registry — not the public npm registry, so it
needs one extra step:
```bash
# one-time: point the @redsentech scope at GitHub Packages, with a token that has read:packages
echo "@redsentech:registry=https://npm.pkg.github.com" >> ~/.npmrc
echo "//npm.pkg.github.com/:_authToken=${GITHUB_TOKEN}" >> ~/.npmrc
npm install -g @redsentech/lean-harness # or: npx @redsentech/lean-harness <command>
lh doctor # verify the environment
```
No published version yet? Clone and link instead:
```bash ```bash
git clone git@github.com:redsentech/lean-harness.git && cd lean-harness && npm install git clone git@github.com:redsentech/lean-harness.git && cd lean-harness && npm install
npm link # puts `lh` on PATH globally npm link # puts `lh` on PATH globally
# once published: npm install -g @redsen/lean-harness (or: npx @redsen/lean-harness <command>)
lh doctor # verify the environment lh doctor # verify the environment
``` ```
@@ -141,8 +153,9 @@ node scripts/onboard.mjs /path/to/target-repo --yes # do it
Safe to re-run: files that are already identical are left alone, and re-running `lh init` on an Safe to re-run: files that are already identical are left alone, and re-running `lh init` on an
already-initialized repo warns instead of failing (rerun with `lh init --force` to reset). already-initialized repo warns instead of failing (rerun with `lh init --force` to reset).
`npm install -g @redsen/lean-harness` (once published) replaces steps 3–5 of the script with a `npm install -g @redsentech/lean-harness` (once your `.npmrc` points `@redsentech` at GitHub
normal global install. Packages — see [The `lh` CLI](#the-lh-cli)) replaces steps 3–5 of the script with a normal
global install.
## Pipeline ## Pipeline
+3 -3
View File
@@ -43,9 +43,9 @@ Use this when: you're a day-to-day Copilot CLI user who wants the harness availa
multiple projects and doesn't need to modify the harness itself. multiple projects and doesn't need to modify the harness itself.
Limitation: this installs the *behaviour* layer only. You still need `lh` on `PATH` (see Limitation: this installs the *behaviour* layer only. You still need `lh` on `PATH` (see
below) for `lh init`/`lh doctor` and everything the agents call automatically — the package below) — either `npm install -g @redsentech/lean-harness` from GitHub Packages (once you've
isn't on the npm registry yet, so today that means step B or C, not `npm install -g` (the pointed the `@redsentech` scope at it, see [The `lh` CLI](../README.md#the-lh-cli)), or step
README's `npm install -g @redsen/lean-harness` line is the path once it's published). B/C below.
### B. Bootstrap an existing repo with the onboarding script ### B. Bootstrap an existing repo with the onboarding script
+4 -1
View File
@@ -1,5 +1,5 @@
{ {
"name": "@redsen/lean-harness", "name": "@redsentech/lean-harness",
"version": "0.1.0", "version": "0.1.0",
"description": "Imperative, token-lean, self-documenting agent harness for GitHub Copilot CLI and VS Code Copilot.", "description": "Imperative, token-lean, self-documenting agent harness for GitHub Copilot CLI and VS Code Copilot.",
"license": "MIT", "license": "MIT",
@@ -8,6 +8,9 @@
"type": "git", "type": "git",
"url": "git+https://github.com/redsentech/lean-harness.git" "url": "git+https://github.com/redsentech/lean-harness.git"
}, },
"publishConfig": {
"registry": "https://npm.pkg.github.com"
},
"type": "module", "type": "module",
"engines": { "engines": {
"node": ">=20" "node": ">=20"