Releasing
How a version of @bloxwap/sfx reaches npm.
Releases are published from GitHub Actions with npm trusted publishing. No npm token is stored in the repository, and every version gets a provenance attestation.
Flow
- Open a PR that bumps
versioninpackages/sfx/package.jsonand updatespackages/sfx/CHANGELOG.md. - Merge it after the Tests, Documentation, and Security checks pass.
- Create a GitHub release tagged
v<version>, for examplev0.1.0. - The Publish to npm workflow checks that the tag matches the package version, runs the full test suite (
prepublishOnly), and publishes.
Pre-release versions (0.2.0-beta.1) publish under the matching dist-tag (beta, alpha, rc) instead of latest.
One-time setup
- On npmjs.com, add a trusted publisher to
@bloxwap/sfx: GitHub Actions, repositorybloxwap/sfx, workflowpublish_npm.yml. - In the repository settings, set GitHub Pages to deploy from GitHub Actions.
- Protect
main, and require the Tests check.