diff --git a/.npmrc b/.npmrc index 38c8c92..287d1eb 100644 --- a/.npmrc +++ b/.npmrc @@ -4,3 +4,4 @@ prefer-workspace-packages=true # Fetch all public Kolektiv packages from the aggregated group repository. # (Publishing goes to the hosted `brand-npm` repository.) @kolektiv:registry=https://repo.yuri.capital/repository/npm-public/ +# Dual-publish target (CI): @kolektiv:registry=https://npm.pkg.github.com diff --git a/docs/CI_DUAL_PUBLISH.md b/docs/CI_DUAL_PUBLISH.md new file mode 100644 index 0000000..7ef7a91 --- /dev/null +++ b/docs/CI_DUAL_PUBLISH.md @@ -0,0 +1,21 @@ +# CI dual-publish (GH Packages npm + JSR) + +Token used to open this PR cannot edit `.github/workflows/*` (missing `workflows` scope). Apply manually: + +```yaml +permissions: + contents: read + packages: write + id-token: write # JSR OIDC +``` + +npm → GitHub Packages: +- `registry-url: https://npm.pkg.github.com` +- `scope: "@kolektiv"` +- `NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}` + +Keep existing Yuri Capital npm publish as dual. + +JSR: claim `@kolektiv` on jsr.io, link package for OIDC, then `npx jsr publish`. + +Epic: https://github.com/KolektivComputer/.github/issues/2