Skip to content

Release new artifacts - #37

Merged
kin0992 merged 1 commit into
mainfrom
changeset-release/main
May 30, 2026
Merged

Release new artifacts#37
kin0992 merged 1 commit into
mainfrom
changeset-release/main

Conversation

@dev-toolkit-app

@dev-toolkit-app dev-toolkit-app Bot commented May 30, 2026

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@kin0992/oxc-config@0.3.0

Minor Changes

  • 51632aa: Publish to the public npm registry (npmjs.org) with provenance.

    These packages now ship from https://registry.npmjs.org under public access
    instead of GitHub Packages. Consumers no longer need a read:packages token or
    a scoped .npmrc entry — a plain pnpm add @kin0992/<pkg> works anonymously.
    Existing GitHub Packages versions remain available but will not receive updates.

Patch Changes

  • 149ac97: Ignore CHANGELOG.md files in the shared oxfmt and oxlint configs so generated
    changelogs are left untouched by formatting and linting.

@kin0992/skills@0.2.0

Minor Changes

  • 51632aa: Publish to the public npm registry (npmjs.org) with provenance.

    These packages now ship from https://registry.npmjs.org under public access
    instead of GitHub Packages. Consumers no longer need a read:packages token or
    a scoped .npmrc entry — a plain pnpm add @kin0992/<pkg> works anonymously.
    Existing GitHub Packages versions remain available but will not receive updates.

@kin0992/tsconfig@0.1.0

Minor Changes

  • 51632aa: Publish to the public npm registry (npmjs.org) with provenance.

    These packages now ship from https://registry.npmjs.org under public access
    instead of GitHub Packages. Consumers no longer need a read:packages token or
    a scoped .npmrc entry — a plain pnpm add @kin0992/<pkg> works anonymously.
    Existing GitHub Packages versions remain available but will not receive updates.

@kin0992/vitest-config@0.1.0

Minor Changes

  • 51632aa: Publish to the public npm registry (npmjs.org) with provenance.

    These packages now ship from https://registry.npmjs.org under public access
    instead of GitHub Packages. Consumers no longer need a read:packages token or
    a scoped .npmrc entry — a plain pnpm add @kin0992/<pkg> works anonymously.
    Existing GitHub Packages versions remain available but will not receive updates.

@dev-toolkit-app
dev-toolkit-app Bot requested a review from kin0992 as a code owner May 30, 2026 20:19
@github-actions

Copy link
Copy Markdown
Contributor

=== branch-name ===

Running benchmark: branch-name-eval
Skill: git/branch-name
Engine: mock
Model: claude-sonnet-4-20250514

✓ [1/3] Feature Branch Naming
✓ [2/3] Fix Branch Naming
✓ [3/3] Should Not Trigger

🧪 Waza Eval Results

Status: ✅ Passed | Score: 1.00 | Duration: 224ms

  • Tests: 3 total, 3 passed, 0 failed, 0 errors
  • Success Rate: 100.0%
  • Score Range: 1.00 - 1.00 (σ=0.0000)

Task Results

Task Score Status Graders
Feature Branch Naming 1.00 has_output, no_ids
Fix Branch Naming 1.00 has_output, no_ids
Should Not Trigger 1.00 has_output, no_ids

Benchmark: branch-name-eval | Skill: git/branch-name | Model: claude-sonnet-4-20250514

=== commit-message ===

Running benchmark: commit-message-eval
Skill: git/commit-message
Engine: mock
Model: claude-sonnet-4-20250514

✓ [1/3] Basic Bug Fix Commit
✓ [2/3] Multi-Area Diff
✓ [3/3] Should Not Trigger - PR Description Request

🧪 Waza Eval Results

Status: ✅ Passed | Score: 1.00 | Duration: 226ms

  • Tests: 3 total, 3 passed, 0 failed, 0 errors
  • Success Rate: 100.0%
  • Score Range: 1.00 - 1.00 (σ=0.0000)

Task Results

Task Score Status Graders
Basic Bug Fix Commit 1.00 has_output, no_conventional_commits, no_period_ending
Multi-Area Diff 1.00 has_output, no_conventional_commits, no_period_ending
Should Not Trigger - PR Description Request 1.00 has_output, no_conventional_commits, no_period_ending

Benchmark: commit-message-eval | Skill: git/commit-message | Model: claude-sonnet-4-20250514

=== pr-title-description ===

Running benchmark: pr-title-description-eval
Skill: git/pr-title-description
Engine: mock
Model: claude-sonnet-4-20250514

✓ [1/3] Basic Feature PR
✓ [2/3] PR With Template
✓ [3/3] Should Not Trigger - Commit Message Request

🧪 Waza Eval Results

Status: ✅ Passed | Score: 1.00 | Duration: 241ms

  • Tests: 3 total, 3 passed, 0 failed, 0 errors
  • Success Rate: 100.0%
  • Score Range: 1.00 - 1.00 (σ=0.0000)

Task Results

Task Score Status Graders
Basic Feature PR 1.00 has_output
PR With Template 1.00 has_output
Should Not Trigger - Commit Message Request 1.00 has_output

Benchmark: pr-title-description-eval | Skill: git/pr-title-description | Model: claude-sonnet-4-20250514

═══════════════════════════════════════════════
MULTI-SKILL RUN SUMMARY
═══════════════════════════════════════════════

Skill Status Pass Rate Avg Score
──────────────────────────────────────────────────────────────────────
branch-name ✅ Passed 100.0% 1.00
commit-message ✅ Passed 100.0% 1.00
pr-title-description ✅ Passed 100.0% 1.00

@dev-toolkit-app
dev-toolkit-app Bot force-pushed the changeset-release/main branch from 6809313 to 262e196 Compare May 30, 2026 20:29
@github-actions

Copy link
Copy Markdown
Contributor

=== branch-name ===

Running benchmark: branch-name-eval
Skill: git/branch-name
Engine: mock
Model: claude-sonnet-4-20250514

✓ [1/3] Feature Branch Naming
✓ [2/3] Fix Branch Naming
✓ [3/3] Should Not Trigger

🧪 Waza Eval Results

Status: ✅ Passed | Score: 1.00 | Duration: 239ms

  • Tests: 3 total, 3 passed, 0 failed, 0 errors
  • Success Rate: 100.0%
  • Score Range: 1.00 - 1.00 (σ=0.0000)

Task Results

Task Score Status Graders
Feature Branch Naming 1.00 has_output, no_ids
Fix Branch Naming 1.00 has_output, no_ids
Should Not Trigger 1.00 has_output, no_ids

Benchmark: branch-name-eval | Skill: git/branch-name | Model: claude-sonnet-4-20250514

=== commit-message ===

Running benchmark: commit-message-eval
Skill: git/commit-message
Engine: mock
Model: claude-sonnet-4-20250514

✓ [1/3] Basic Bug Fix Commit
✓ [2/3] Multi-Area Diff
✓ [3/3] Should Not Trigger - PR Description Request

🧪 Waza Eval Results

Status: ✅ Passed | Score: 1.00 | Duration: 245ms

  • Tests: 3 total, 3 passed, 0 failed, 0 errors
  • Success Rate: 100.0%
  • Score Range: 1.00 - 1.00 (σ=0.0000)

Task Results

Task Score Status Graders
Basic Bug Fix Commit 1.00 has_output, no_conventional_commits, no_period_ending
Multi-Area Diff 1.00 has_output, no_conventional_commits, no_period_ending
Should Not Trigger - PR Description Request 1.00 has_output, no_conventional_commits, no_period_ending

Benchmark: commit-message-eval | Skill: git/commit-message | Model: claude-sonnet-4-20250514

=== pr-title-description ===

Running benchmark: pr-title-description-eval
Skill: git/pr-title-description
Engine: mock
Model: claude-sonnet-4-20250514

✓ [1/3] Basic Feature PR
✓ [2/3] PR With Template
✓ [3/3] Should Not Trigger - Commit Message Request

🧪 Waza Eval Results

Status: ✅ Passed | Score: 1.00 | Duration: 252ms

  • Tests: 3 total, 3 passed, 0 failed, 0 errors
  • Success Rate: 100.0%
  • Score Range: 1.00 - 1.00 (σ=0.0000)

Task Results

Task Score Status Graders
Basic Feature PR 1.00 has_output
PR With Template 1.00 has_output
Should Not Trigger - Commit Message Request 1.00 has_output

Benchmark: pr-title-description-eval | Skill: git/pr-title-description | Model: claude-sonnet-4-20250514

═══════════════════════════════════════════════
MULTI-SKILL RUN SUMMARY
═══════════════════════════════════════════════

Skill Status Pass Rate Avg Score
──────────────────────────────────────────────────────────────────────
branch-name ✅ Passed 100.0% 1.00
commit-message ✅ Passed 100.0% 1.00
pr-title-description ✅ Passed 100.0% 1.00

@kin0992
kin0992 merged commit 84bf6e2 into main May 30, 2026
7 checks passed
@kin0992
kin0992 deleted the changeset-release/main branch May 30, 2026 20:30
kin0992 added a commit that referenced this pull request Jun 1, 2026
## Problem

Published packages (e.g. `@kin0992/oxc-config@0.3.0`) have **no
provenance** — the registry's attestation endpoint returns `Not found`
and the #37 release log never printed a "Signed provenance statement".

Root cause, from the release log:
- The `Configure npm scope auth` step wrote the npm token into `.npmrc`,
so `changeset publish` authenticated **by token**.
- `changeset publish` did not produce provenance under that path,
despite `NPM_CONFIG_PROVENANCE: true` and `publishConfig.provenance:
true`.
- changesets/action even reported `OIDC is available - using npm trusted
publishing`, but the on-disk token overrode it.

## Change

Switch to pure **npm Trusted Publishing (OIDC)**:
- Remove the `Configure npm scope auth` step (no token on disk).
- Remove `NODE_AUTH_TOKEN` from the publish env.
- Keep `id-token: write` and `NPM_CONFIG_PROVENANCE`.

npm then exchanges the workflow's id-token for a short-lived credential
and **signs provenance automatically**.

## Required manual step before merging / next release

A **Trusted Publisher** must be configured on npmjs.org for each
package, or the next publish will fail auth:

> npmjs.org → each of
`@kin0992/{oxc-config,skills,tsconfig,vitest-config}` → Settings →
Trusted Publisher → GitHub Actions → owner `kin0992`, repo
`dev-toolkit`, workflow `release.yml`.

Provenance attaches on the **next** version bump; existing `0.3.0` can't
be back-filled.

`npm_token` secret / `registry-url` input are left declared (marked
deprecated) for backward compatibility with any other callers.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant