📦 docs: cereale is on npm, and release.yml moves to trusted publishing
0.4.0 published, so the three places that said it had not stopped being true: the README install section, the landing page's install panel, and the "what cereale is not" item. All three now say `npm install cereale`, and the last becomes a limitation that is actually still true — it is 0.x, where a minor bump is allowed to break you. An npm version badge joins the row, tinted the same brand brown as the rest. It was held back deliberately while the package did not exist, because a badge that renders "not found" is worse than no badge. page.js loses the install-shell substitution: it rewrote the tarball filename in a code block that no longer exists. --- release.yml: trusted publishing --- npm exchanges the workflow's short-lived GitHub identity token for a publish token scoped to this package, so no long-lived npm token has to exist. The header documents exactly what to enter on npmjs.com, including the two fields npm checks against the OIDC claims and refuses on mismatch: the workflow filename must match this file, and Environment must stay blank while the job declares none. The find that matters: Node 22 bundles npm 10.x, which has no OIDC code at all. Verified by unpacking the CLI — lib/utils/oidc.js is absent in 11.4.2 and present in 11.5.0. Since npm's OIDC step is deliberately non-throwing, an old CLI would have skipped trusted publishing in silence and fallen back to token auth while appearing to work. So the workflow raises npm and then asserts the version, rather than assuming it. NPM_TOKEN stays as a fallback for the same non-throwing reason: this can land before the registry side is configured, and nothing breaks. Delete the secret once a real run shows OIDC working. --provenance stays explicit. Under OIDC npm enables it itself for a public repo, but only when the flag is left at its default (config.isDefault check in oidc.js), so passing it just skips that auto-enable and lands in the same place — while remaining the only thing that produces an attestation on the token path. actionlint clean; the version guard tested against 10.9.7, 11.4.2, 11.5.0 and 12.0.2; the page re-rendered with no errors and no "not on npm" text left. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK
This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
# Cereale
|
||||
|
||||
[](https://www.npmjs.com/package/cereale)
|
||||
[](https://github.com/avalon-vanguard/cereale/actions/workflows/ci.yml)
|
||||
[](https://avalon-vanguard.github.io/cereale/)
|
||||
[](https://github.com/avalon-vanguard/cereale/blob/main/package.json)
|
||||
@@ -79,20 +80,13 @@ entity, anything with behaviour attached. Reach for Zod when you just want the d
|
||||
|
||||
## Installation
|
||||
|
||||
Not on npm yet: `npm install cereale` does **not** resolve to this library — the name is
|
||||
unclaimed on the registry. Installing straight from GitHub will not work either, because the
|
||||
build output is not committed. Until the first publish, install from a clone:
|
||||
|
||||
```bash
|
||||
git clone https://github.com/avalon-vanguard/cereale
|
||||
cd cereale
|
||||
npm install && npm run build
|
||||
npm pack # → cereale-0.4.0.tgz
|
||||
|
||||
# then, from your own project
|
||||
npm install ../cereale/cereale-0.4.0.tgz
|
||||
npm install cereale
|
||||
```
|
||||
|
||||
Published with [provenance](https://www.npmjs.com/package/cereale), so the registry carries a
|
||||
verified attestation linking the tarball to the commit it was built from.
|
||||
|
||||
Cereale uses **TC39 standard decorators** (since 0.2.0), so no `experimentalDecorators` flag:
|
||||
|
||||
```json
|
||||
|
||||
Reference in New Issue
Block a user