This checklist answers one question:
Can we launch this build today?Run the release gate from the repo root:
npm run release:checkThis command does not publish anything. It proves the product is ready enough for a human to make the final release decision.
npm run release:check runs the full agent-control proof, the external install
smoke, and then checks the release checklist itself.
It proves:
ripple initcan make a fresh repo ready- packed
@getripple/cliinstalls into a clean repo - packed
@getripple/mcpinstalls into a clean repo - the installed CLI can run
init -> plan -> doctor -> gate - the installed MCP stdio server can run
workflow -> doctor -> plan -> doctor -> gate - all three packages can install together into one clean external repo
- installed CLI and installed MCP both report the same boundary-crossing stop
- authorization gates catch boundary violations
- human approval gates block and unblock correctly
- CI speaks the same
continue,repair,human-review, andrestore-readinesslanguage - MCP host and MCP stdio speak the same gate language
- npm package metadata, entry points, bins, README install commands, and
npm pack --dry-runcontents are valid - public package versions match the root version
- release scripts and this checklist are wired together
- public docs match the product persona and avoid forbidden overclaims
These checks cannot be automated safely:
- Review the final diff and make sure it matches the intended release.
- Review
docs/product-persona.mdif the product promise, audience, or claims changed. - Run
npm run release:identityand consciously review the public product identity. - Run
npm run release:npm-preflight -- --liveand review npm registry readiness. - Confirm npm account access with
npm whoami. - Confirm the
@getripplenpm scope and package names are owned or available. - Confirm this version should be released publicly.
- Confirm no secret, private repo path, local credential, or accidental test artifact is included.
- Confirm the public README and package READMEs describe the product honestly.
Run:
npm run release:identityThis prints the public identity you are about to release.
Product identity:
Ripple is a local authorization gate for AI coding agents that defines what an agent may change, checks the real Git diff, and returns continue, repair, or human review.Package identity:
@getripple/core -> local engine
@getripple/cli -> terminal and CI interface
@getripple/mcp -> agent-facing MCP stdio interfaceHuman decision:
Are these names, version, scope, public promise, alpha status, and README claims exactly what we want to publish?Do not publish if:
- the
@getripplenpm scope or package names are not controlled by you - the version is not the version you want public
- the README sounds stronger than the product really is
- the release still depends on this local machine to work
- the package descriptions no longer match the product direction
- you feel rushed and have not reviewed the final diff
Run the dry preflight anytime:
npm run release:npm-preflightDry mode validates local package identity and prints the read-only registry checks. It does not hit the network.
Before publishing, run the live preflight:
npm run release:npm-preflight -- --liveLive mode runs read-only npm commands:
npm whoami
npm access ls-packages @getripple --json
npm view @getripple/core@1.0.9 version --json
npm view @getripple/cli@1.0.9 version --json
npm view @getripple/mcp@1.0.9 version --jsonExpected result before publishing a new version:
npm whoami succeeds
@getripple/core@1.0.9 is not found
@getripple/cli@1.0.9 is not found
@getripple/mcp@1.0.9 is not foundStop if:
- npm auth fails
- any target version already exists
- registry checks fail for a reason other than package not found
- you cannot confirm
@getripplescope/package ownership
Publish the packages in dependency order:
npm publish --workspace @getripple/core
npm publish --workspace @getripple/cli
npm publish --workspace @getripple/mcp@getripple/cli and @getripple/mcp depend on the matching @getripple/core version,
so core must publish first.
Before publishing, run the local external install smoke:
npm run smoke:external-installThis does not hit the public npm registry. It packs the local packages, installs
@getripple/core, @getripple/cli, and @getripple/mcp into a fresh temporary
consumer repo, then verifies:
installed ripple binary -> init, plan, approve, gate stop, repair
installed MCP server -> workflow, gate stopAfter publishing, you can run the same smoke against the public registry:
npm run smoke:external-install -- --liveAfter publishing, run the automated public install smoke:
npm run smoke:post-publish -- --liveWithout --live, the command only prints the smoke plan and does not hit the
network:
npm run smoke:post-publishThe live smoke creates a fresh temporary repo and verifies:
@getripple/cli -> ripple --version, init, plan, gate
@getripple/mcp -> ripple_get_agent_workflow, ripple_doctor, ripple_plan_context, ripple_gateManual equivalent for the CLI public install path:
npx -y @getripple/cli doctor
npx -y @getripple/cli init
npx -y @getripple/cli plan --file src/index.ts --task "smoke test Ripple" --mode file --save
npx -y @getripple/cli gate --intent latestFor MCP:
npx -y @getripple/mcp --workspace /absolute/path/to/your/repoThen connect an MCP client with:
{
"mcpServers": {
"ripple": {
"command": "npx",
"args": [
"-y",
"@getripple/mcp",
"--workspace",
"/absolute/path/to/your/repo"
]
}
}
}The first MCP calls to verify are:
ripple_get_agent_workflow
ripple_doctor
ripple_plan_context
ripple_gateIf npm run release:check fails, do not publish.
If it passes, publish only after the manual gates are reviewed by a human.