diff --git a/.claude-plugin/marketplace.json b/.claude-plugin/marketplace.json index 556682e..e7b68e2 100644 --- a/.claude-plugin/marketplace.json +++ b/.claude-plugin/marketplace.json @@ -8,7 +8,7 @@ { "name": "offcut", "description": "Persistent construction discipline and concise responses for coding agents.", - "version": "0.4.1", + "version": "0.4.2", "source": "./plugins/offcut", "author": { "name": "skelvar" diff --git a/.claude-plugin/plugin.json b/.claude-plugin/plugin.json index 3ffdafd..f7eea58 100644 --- a/.claude-plugin/plugin.json +++ b/.claude-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "offcut", - "version": "0.4.1", + "version": "0.4.2", "description": "Persistent construction discipline and concise responses for coding agents.", "license": "MIT", "author": { diff --git a/.codex-plugin/plugin.json b/.codex-plugin/plugin.json index 7a45d90..d51e37e 100644 --- a/.codex-plugin/plugin.json +++ b/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "offcut", - "version": "0.4.1", + "version": "0.4.2", "description": "Persistent construction discipline and concise output for coding agents.", "license": "MIT", "author": { diff --git a/.cursor-plugin/marketplace.json b/.cursor-plugin/marketplace.json index 9ba75ef..0980c49 100644 --- a/.cursor-plugin/marketplace.json +++ b/.cursor-plugin/marketplace.json @@ -11,7 +11,7 @@ "name": "offcut", "source": "plugins/offcut", "description": "Persistent construction discipline and concise responses for coding agents.", - "version": "0.4.1", + "version": "0.4.2", "author": { "name": "skelvar" }, diff --git a/.cursor-plugin/plugin.json b/.cursor-plugin/plugin.json index b9fb2f8..26e0c1d 100644 --- a/.cursor-plugin/plugin.json +++ b/.cursor-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "offcut", - "version": "0.4.1", + "version": "0.4.2", "description": "Persistent construction discipline and concise responses for coding agents.", "author": { "name": "skelvar" diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 73343f5..dc09254 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -16,12 +16,25 @@ jobs: with: node-version: '22' registry-url: https://registry.npmjs.org + # Node 22 bundles npm 10; OIDC trusted publishing needs npm 11.5.1+. + - run: npm install -g npm@latest - name: Tag must match package.json run: | tag="${{ github.event.release.tag_name }}" ver="$(node -p "require('./package.json').version")" test "$tag" = "v$ver" || { echo "tag $tag != package.json v$ver"; exit 1; } - run: node --test tests/*.test.js - - run: npm publish --provenance --access public - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} + - name: Skip if this version is already on the registry + id: check + run: | + ver="$(node -p "require('./package.json').version")" + if npm view "@skelvar/offcut@$ver" version >/dev/null 2>&1; then + echo "exists=true" >> "$GITHUB_OUTPUT" + echo "::notice::@skelvar/offcut@$ver is already published; nothing to do." + else + echo "exists=false" >> "$GITHUB_OUTPUT" + fi + # No token: authentication is the OIDC trusted publisher configured on npmjs + # for this repository and this workflow file. + - if: steps.check.outputs.exists != 'true' + run: npm publish --provenance --access public diff --git a/README.md b/README.md index 608909a..b0aebd4 100644 --- a/README.md +++ b/README.md @@ -17,7 +17,10 @@ no dependencies. git diff | npx --yes github:skelvar/offcut scan --diff - ``` -Pin a version with `npx --yes github:skelvar/offcut#v0.4.0 scan --diff -`; marketplace installs accept the same tag as `--ref v0.4.0`. +The same command from npm: `git diff | npx --yes @skelvar/offcut scan --diff -`. +Pin a version with `npx --yes @skelvar/offcut@0.4.2 scan --diff -` or +`npx --yes github:skelvar/offcut#v0.4.2 scan --diff -`; marketplace installs +accept the same tag as `--ref v0.4.2`. ```text src/phone.js (1) @@ -143,7 +146,7 @@ Harness notes and benchmark receipts: [docs/development](docs/development/README The Releases page is not updated by the version fields; this step is what updates it. -4. Publishing the release triggers `.github/workflows/publish.yml`, which publishes `@skelvar/offcut` to npmjs with provenance. It needs a repository secret `NPM_TOKEN` (an npm granular access token with publish rights on the `@skelvar` scope). +4. Publishing the release triggers `.github/workflows/publish.yml`, which publishes `@skelvar/offcut` to npmjs with provenance. Authentication is npm's trusted publisher for this repository and workflow file (configured once with `npm trust github @skelvar/offcut --repo skelvar/offcut --file publish.yml --allow-publish`); no token is stored. If the version is already on the registry, the workflow exits without publishing. ## License diff --git a/package.json b/package.json index 38c922c..19deb4e 100644 --- a/package.json +++ b/package.json @@ -1,10 +1,10 @@ { "name": "@skelvar/offcut", - "version": "0.4.1", + "version": "0.4.2", "description": "Build the cheapest correct thing in the right place.", "type": "module", "bin": { - "offcut": "./tools/bootstrap.mjs" + "offcut": "tools/bootstrap.mjs" }, "files": [ "assets/", diff --git a/plugin.json b/plugin.json index 8e72724..2d53366 100644 --- a/plugin.json +++ b/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://raw.githubusercontent.com/anthropics/agent-plugins/main/schemas/plugin.schema.json", "name": "offcut", - "version": "0.4.1", + "version": "0.4.2", "description": "Persistent construction discipline and concise responses for coding agents.", "author": { "name": "skelvar" diff --git a/plugins/offcut/.claude-plugin/plugin.json b/plugins/offcut/.claude-plugin/plugin.json index 3ffdafd..f7eea58 100644 --- a/plugins/offcut/.claude-plugin/plugin.json +++ b/plugins/offcut/.claude-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "offcut", - "version": "0.4.1", + "version": "0.4.2", "description": "Persistent construction discipline and concise responses for coding agents.", "license": "MIT", "author": { diff --git a/plugins/offcut/.codex-plugin/plugin.json b/plugins/offcut/.codex-plugin/plugin.json index 7a45d90..d51e37e 100644 --- a/plugins/offcut/.codex-plugin/plugin.json +++ b/plugins/offcut/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "offcut", - "version": "0.4.1", + "version": "0.4.2", "description": "Persistent construction discipline and concise output for coding agents.", "license": "MIT", "author": { diff --git a/plugins/offcut/.cursor-plugin/plugin.json b/plugins/offcut/.cursor-plugin/plugin.json index b9fb2f8..26e0c1d 100644 --- a/plugins/offcut/.cursor-plugin/plugin.json +++ b/plugins/offcut/.cursor-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "offcut", - "version": "0.4.1", + "version": "0.4.2", "description": "Persistent construction discipline and concise responses for coding agents.", "author": { "name": "skelvar" diff --git a/plugins/offcut/README.md b/plugins/offcut/README.md index 608909a..b0aebd4 100644 --- a/plugins/offcut/README.md +++ b/plugins/offcut/README.md @@ -17,7 +17,10 @@ no dependencies. git diff | npx --yes github:skelvar/offcut scan --diff - ``` -Pin a version with `npx --yes github:skelvar/offcut#v0.4.0 scan --diff -`; marketplace installs accept the same tag as `--ref v0.4.0`. +The same command from npm: `git diff | npx --yes @skelvar/offcut scan --diff -`. +Pin a version with `npx --yes @skelvar/offcut@0.4.2 scan --diff -` or +`npx --yes github:skelvar/offcut#v0.4.2 scan --diff -`; marketplace installs +accept the same tag as `--ref v0.4.2`. ```text src/phone.js (1) @@ -143,7 +146,7 @@ Harness notes and benchmark receipts: [docs/development](docs/development/README The Releases page is not updated by the version fields; this step is what updates it. -4. Publishing the release triggers `.github/workflows/publish.yml`, which publishes `@skelvar/offcut` to npmjs with provenance. It needs a repository secret `NPM_TOKEN` (an npm granular access token with publish rights on the `@skelvar` scope). +4. Publishing the release triggers `.github/workflows/publish.yml`, which publishes `@skelvar/offcut` to npmjs with provenance. Authentication is npm's trusted publisher for this repository and workflow file (configured once with `npm trust github @skelvar/offcut --repo skelvar/offcut --file publish.yml --allow-publish`); no token is stored. If the version is already on the registry, the workflow exits without publishing. ## License diff --git a/plugins/offcut/package.json b/plugins/offcut/package.json index 38c922c..19deb4e 100644 --- a/plugins/offcut/package.json +++ b/plugins/offcut/package.json @@ -1,10 +1,10 @@ { "name": "@skelvar/offcut", - "version": "0.4.1", + "version": "0.4.2", "description": "Build the cheapest correct thing in the right place.", "type": "module", "bin": { - "offcut": "./tools/bootstrap.mjs" + "offcut": "tools/bootstrap.mjs" }, "files": [ "assets/", diff --git a/plugins/offcut/plugin.json b/plugins/offcut/plugin.json index 8e72724..2d53366 100644 --- a/plugins/offcut/plugin.json +++ b/plugins/offcut/plugin.json @@ -1,7 +1,7 @@ { "$schema": "https://raw.githubusercontent.com/anthropics/agent-plugins/main/schemas/plugin.schema.json", "name": "offcut", - "version": "0.4.1", + "version": "0.4.2", "description": "Persistent construction discipline and concise responses for coding agents.", "author": { "name": "skelvar" diff --git a/plugins/offcut/skills/offcut-audit/SKILL.md b/plugins/offcut/skills/offcut-audit/SKILL.md index d1521b6..d1233bd 100644 --- a/plugins/offcut/skills/offcut-audit/SKILL.md +++ b/plugins/offcut/skills/offcut-audit/SKILL.md @@ -12,7 +12,7 @@ description: > license: MIT compatibility: Requires Node.js on PATH to run scripts/scan.mjs. Touches no mode state. metadata: - version: "0.4.1" + version: "0.4.2" author: skelvar --- diff --git a/plugins/offcut/skills/offcut-help/SKILL.md b/plugins/offcut/skills/offcut-help/SKILL.md index ae60568..b7a9a13 100644 --- a/plugins/offcut/skills/offcut-help/SKILL.md +++ b/plugins/offcut/skills/offcut-help/SKILL.md @@ -8,7 +8,7 @@ description: > license: MIT compatibility: Text only. No Node.js required. Touches no mode state. metadata: - version: "0.4.1" + version: "0.4.2" author: skelvar --- diff --git a/plugins/offcut/skills/offcut-review/SKILL.md b/plugins/offcut/skills/offcut-review/SKILL.md index 431720e..5bbc0a9 100644 --- a/plugins/offcut/skills/offcut-review/SKILL.md +++ b/plugins/offcut/skills/offcut-review/SKILL.md @@ -12,7 +12,7 @@ description: > license: MIT compatibility: Requires Node.js on PATH to run scripts/scan.mjs. Touches no mode state. metadata: - version: "0.4.1" + version: "0.4.2" author: skelvar --- diff --git a/plugins/offcut/skills/offcut/SKILL.md b/plugins/offcut/skills/offcut/SKILL.md index f8ab3f4..f41fe66 100644 --- a/plugins/offcut/skills/offcut/SKILL.md +++ b/plugins/offcut/skills/offcut/SKILL.md @@ -12,7 +12,7 @@ compatibility: > Grok Build). Native persistent instructions are supported on all four hosts; the skill remains a compatibility fallback. metadata: - version: "0.4.1" + version: "0.4.2" author: skelvar --- diff --git a/scripts/build-agents-md.js b/scripts/build-agents-md.js index cdcfdaa..6fe297f 100644 --- a/scripts/build-agents-md.js +++ b/scripts/build-agents-md.js @@ -34,7 +34,7 @@ compatibility: > Grok Build). Native persistent instructions are supported on all four hosts; the skill remains a compatibility fallback. metadata: - version: "0.4.1" + version: "0.4.2" author: skelvar --- diff --git a/skills/offcut-audit/SKILL.md b/skills/offcut-audit/SKILL.md index d1521b6..d1233bd 100644 --- a/skills/offcut-audit/SKILL.md +++ b/skills/offcut-audit/SKILL.md @@ -12,7 +12,7 @@ description: > license: MIT compatibility: Requires Node.js on PATH to run scripts/scan.mjs. Touches no mode state. metadata: - version: "0.4.1" + version: "0.4.2" author: skelvar --- diff --git a/skills/offcut-help/SKILL.md b/skills/offcut-help/SKILL.md index ae60568..b7a9a13 100644 --- a/skills/offcut-help/SKILL.md +++ b/skills/offcut-help/SKILL.md @@ -8,7 +8,7 @@ description: > license: MIT compatibility: Text only. No Node.js required. Touches no mode state. metadata: - version: "0.4.1" + version: "0.4.2" author: skelvar --- diff --git a/skills/offcut-review/SKILL.md b/skills/offcut-review/SKILL.md index 431720e..5bbc0a9 100644 --- a/skills/offcut-review/SKILL.md +++ b/skills/offcut-review/SKILL.md @@ -12,7 +12,7 @@ description: > license: MIT compatibility: Requires Node.js on PATH to run scripts/scan.mjs. Touches no mode state. metadata: - version: "0.4.1" + version: "0.4.2" author: skelvar --- diff --git a/skills/offcut/SKILL.md b/skills/offcut/SKILL.md index f8ab3f4..f41fe66 100644 --- a/skills/offcut/SKILL.md +++ b/skills/offcut/SKILL.md @@ -12,7 +12,7 @@ compatibility: > Grok Build). Native persistent instructions are supported on all four hosts; the skill remains a compatibility fallback. metadata: - version: "0.4.1" + version: "0.4.2" author: skelvar --- diff --git a/tests/distribution.test.js b/tests/distribution.test.js index 8a85376..d24e8ab 100644 --- a/tests/distribution.test.js +++ b/tests/distribution.test.js @@ -15,7 +15,8 @@ test('universal package exposes a zero-dependency offcut installer', () => { const manifest = JSON.parse(fs.readFileSync(packagePath, 'utf8')); assert.equal(manifest.name, '@skelvar/offcut'); assert.equal(manifest.type, 'module'); - assert.equal(manifest.bin?.offcut, './tools/bootstrap.mjs'); + // npm 11.15+ drops bin entries whose path starts with "./" instead of cleaning them. + assert.equal(manifest.bin?.offcut, 'tools/bootstrap.mjs'); assert.deepEqual(manifest.dependencies || {}, {}); assert.match(manifest.engines?.node || '', />=20/); assert.ok(manifest.files.includes('scripts/scan.mjs'));