Skip to content

Automate CLI npm releases and Factory tracking - #24

Merged
daveosterjr merged 4 commits into
masterfrom
codex/production-releases-cli
Oct 1, 2026
Merged

daveosterjr merged 4 commits into
masterfrom
codex/production-releases-cli

Conversation

@daveosterjr

Copy link
Copy Markdown
Contributor

Master changes currently need a manual npm release, and Factory cannot track whether both CLI packages were actually published. This adds a source-bound publisher for @dealmachine/cli and the dealmachine alias, with production build receipts for Factory.

The reviewed stable baseline is 0.4.0. After commissioning, master pushes select the next stable patch, validate both archives in a clean consumer, publish them in dependency order and verify their integrity, source SHA, exact alias dependency and latest tags. Retries resume an immutable partial pair; stale master sources and conflicting registry state stop. Manual dispatch can bind an expected source SHA.

Publication remains disabled until PRODUCTION_DEPLOY_ENABLED=true is explicitly authorized and configured. Source delivery does not configure npm trusted publishers or activate publication. Factory intake likewise retains its separate enablement gate. Owner instructions and release documentation describe these boundaries and required access.

Validation: npm run check passed (11 Vitest files, 76 tests, typecheck, build, plugin validation and public artifact guard); npm run test:package passed for both packages; the earlier automatic release dry run passed without publication; workflow YAML parsing and git diff --check passed.

Regression coverage is owned by the release planner's partial-pair, stale-source, integrity and channel checks plus the existing packed consumer test. No public Command or Endpoint behavior changes, no shared regression catalog edit, no feature rollout and no production publication are part of this source delivery.

@daveosterjr
daveosterjr merged commit a1fd125 into master Oct 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant