Automate CLI npm releases and Factory tracking - #24
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Master changes currently need a manual npm release, and Factory cannot track whether both CLI packages were actually published. This adds a source-bound publisher for
@dealmachine/cliand thedealmachinealias, with production build receipts for Factory.The reviewed stable baseline is 0.4.0. After commissioning, master pushes select the next stable patch, validate both archives in a clean consumer, publish them in dependency order and verify their integrity, source SHA, exact alias dependency and
latesttags. Retries resume an immutable partial pair; stale master sources and conflicting registry state stop. Manual dispatch can bind an expected source SHA.Publication remains disabled until
PRODUCTION_DEPLOY_ENABLED=trueis explicitly authorized and configured. Source delivery does not configure npm trusted publishers or activate publication. Factory intake likewise retains its separate enablement gate. Owner instructions and release documentation describe these boundaries and required access.Validation:
npm run checkpassed (11 Vitest files, 76 tests, typecheck, build, plugin validation and public artifact guard);npm run test:packagepassed for both packages; the earlier automatic release dry run passed without publication; workflow YAML parsing andgit diff --checkpassed.Regression coverage is owned by the release planner's partial-pair, stale-source, integrity and channel checks plus the existing packed consumer test. No public Command or Endpoint behavior changes, no shared regression catalog edit, no feature rollout and no production publication are part of this source delivery.