Skip to content

Fix npm provenance metadata and prepare 0.6.1 - #6

Merged
backslash-f merged 1 commit into
mainfrom
codex/npm-provenance-metadata
Sep 7, 2026
Merged

Fix npm provenance metadata and prepare 0.6.1#6
backslash-f merged 1 commit into
mainfrom
codex/npm-provenance-metadata

Conversation

@backslash-f

Copy link
Copy Markdown
Contributor

npm rejected the 0.6.0 release with E422 because package.json lacked repository.url, which must match the GitHub repository in trusted-publishing provenance. Add the canonical Git repository metadata and prepare 0.6.1 without rewriting the existing release tag. No runtime behavior changes.

Validation: npm run build, npm test (34 tests), and git diff --check passed. Original failed publish: https://github.com/thatfactory/xcode-cloud-mcp/actions/runs/34115506186.

Exact-head ChatGPT review via Reasoning Relay pending.

@backslash-f

Copy link
Copy Markdown
Contributor Author

Final ChatGPT review through Reasoning Relay:

Verdict: APPROVED
Reviewed-PR: #6
Reviewed-Base: c5efe09
Reviewed-Head: dffd7fa
Blocking-Findings: None
Non-Blocking-Findings: None

Reviewer inspected the complete 3-file diff and package, lockfile, handshake, publish workflow, failed publish, tag state, and repository structure. Canonical npm-compatible repository metadata fixes the provenance mismatch; versions consistently advance to 0.6.1 without changing the 0.6.0 tag or weakening publishing security.

Relay delegation: del_b1fdb8fe-2a49-4c8c-a2a0-d54b1d7888d0
Response SHA-256: 87333e295848b86ff5b5ca373f2b7240b13a428ce145b47f5292434ba4df877c
Response bytes: 872.

@backslash-f
backslash-f marked this pull request as ready for review September 7, 2026 11:17
@backslash-f
backslash-f merged commit 3ef3296 into main Sep 7, 2026
1 check passed
@backslash-f
backslash-f deleted the codex/npm-provenance-metadata branch September 7, 2026 11:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant