diff --git a/.npmrc b/.npmrc index bd5acc8..e87c0a0 100644 --- a/.npmrc +++ b/.npmrc @@ -4,3 +4,4 @@ prefer-workspace-packages=true # Fetch all public Kolektiv packages from the aggregated group repository. # (Publishing goes to the per-project hosted repo, e.g. brand-npm.) @kolektiv:registry=https://repo.yuri.capital/repository/npm-public/ +# Dual-publish target (CI): @kolektiv:registry=https://npm.pkg.github.com diff --git a/docs/CI_DUAL_PUBLISH.md b/docs/CI_DUAL_PUBLISH.md new file mode 100644 index 0000000..7714ea3 --- /dev/null +++ b/docs/CI_DUAL_PUBLISH.md @@ -0,0 +1,39 @@ +# Dual-publish (GH Packages npm + JSR) + +Org epic: [KolektivComputer/.github#2](https://github.com/KolektivComputer/.github/issues/2) +Spine (Maven siblings): [gradle-conventions#1](https://github.com/KolektivComputer/gradle-conventions/pull/1) → `computer.kolektiv.publishing` + +## npm +- Packages under **`@kolektiv/...` only** (already `@kolektiv/brand-core`, etc.) — do not invent a second JS scope +- Dual: existing Yuri Capital npm **and** `https://npm.pkg.github.com` with `@kolektiv:registry=…` +- Auth: `NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}` with `permissions.packages: write` + +## JSR +- Scope `@kolektiv` (owned); stub `packages/core/jsr.json` for `@kolektiv/brand-core` +- Actions: OIDC only — `permissions.id-token: write` — **no org `JSR_TOKEN`** +- Mey: link package on jsr.io for GitHub Actions trusted publishing +- Not a substitute for npm publish + +## Workflow paste (token may lack `workflows` scope) + +```yaml +permissions: + contents: read + packages: write + id-token: write # JSR OIDC +``` + +```yaml +- uses: actions/setup-node@v4 + with: + registry-url: https://npm.pkg.github.com + scope: "@kolektiv" +env: + NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }} +``` + +```yaml +- run: npx jsr publish +``` + +Reference implementation: KolektivComputer/themes `publish.yml` + `.github/scripts/publish-*.sh`. diff --git a/packages/core/jsr.json b/packages/core/jsr.json new file mode 100644 index 0000000..3d3f9f5 --- /dev/null +++ b/packages/core/jsr.json @@ -0,0 +1,8 @@ +{ + "name": "@kolektiv/brand-core", + "version": "0.1.1", + "exports": "./dist/index.js", + "publish": { + "include": ["dist", "jsr.json", "README.md", "LICENSE"] + } +}