You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Publish reference-implementations/typescript as the public ESM package @tomlschema/tomlschema@1.0.0-rc.2 on npm. The scoped package was not found when checked on 2026-08-19.
Maintainer setup — required before implementation can publish
Create/sign in to the project-owned npm account, enable 2FA, and create or claim the tomlschema npm organization/scope.
Use the agreed package coordinate @tomlschema/tomlschema; tomlschema.org is the canonical project domain.
Add primary and backup maintainers to the organization and confirm both can administer @tomlschema/tomlschema.
Bootstrap/reserve the public package if npm requires an initial authenticated publication before its trusted publisher can be configured. Use --access public; scoped packages otherwise default to private.
Create a protected GitHub environment named npm, restrict it to typescript-v* tags, and require maintainer approval where supported.
Configure npm trusted publishing for repository brunoborges/toml-schema, the exact release workflow filename, and environment npm. Prefer stage-only permission for the first release if available so a maintainer reviews before final promotion.
After trusted publishing works, configure publishing access to require 2FA and disallow traditional tokens, then revoke any temporary bootstrap token.
Repository implementation — after scope ownership is confirmed
Change package.json and its lockfile from @tomlschema/toml-schema to @tomlschema/tomlschema.
Add publishConfig with access: "public" and the npm registry so an accidental default cannot create a private package or target another registry.
Add an explicit prepack/prepublishOnly strategy that cleans, typechecks, tests, and builds deterministically; ensure source checkout state cannot leave stale dist files in the tarball.
Add a version/tag guard so typescript-v1.0.0-rc.2 exactly matches package.json and lockfile metadata.
Run npm pack --dry-run --json in CI and assert that only dist, README, license/package metadata, and intended declarations/source maps are present. Confirm no tests, source secrets, caches, or repository-root files leak into the package.
Verify exports, main, types, ESM-only behavior, Node engines, and declaration files from the packed tarball rather than the source tree.
Add .github/workflows/release-typescript.yml, triggered only by typescript-v* plus safe manual dry run. It must use a current npm CLI with trusted-publisher support, minimal permissions plus id-token: write only in the publish job, environment npm, npm ci, typecheck, tests, build, tarball inspection, clean install smoke tests, and npm publish --access public or staged publish.
Update the TypeScript README and REFERENCE_IMPLEMENTATIONS.md to remove “not a package-registry release,” add the npm install command/URL, explain ESM requirements, tag convention, and artifact-vs-language version distinction.
Execution plan
Run npm --prefix reference-implementations/typescript ci, typecheck, tests, and build.
Create the tarball with npm pack, inspect its JSON file list and unpacked size, then install that tarball in clean ESM JavaScript and TypeScript consumers to verify runtime imports and declarations.
Merge the exact workflow registered with npm and create typescript-v1.0.0-rc.2 from the reviewed commit.
Approve the protected trusted-publishing job (and promote the staged package if stage-only mode is used).
With an empty npm cache and clean project, install @tomlschema/tomlschema@1.0.0-rc.2, import the package root, compile TypeScript against its declarations, and run the documented validation example.
Confirm npm displays the expected public access, owners, provenance, README, MIT license, repository/subdirectory, Node engine, dependencies, and prerelease dist-tag behavior. Do not assign prerelease rc.2 to latest; use an rc/next tag until the final release.
Acceptance criteria
@tomlschema/tomlschema@1.0.0-rc.2 installs publicly from npm under a prerelease dist-tag.
Clean JavaScript and TypeScript consumers validate the ESM entry point and declarations.
Tarball contents are minimal and deterministic.
Publication uses npm trusted publishing with provenance and no retained long-lived write token.
Parent: #129
Publish
reference-implementations/typescriptas the public ESM package@tomlschema/tomlschema@1.0.0-rc.2on npm. The scoped package was not found when checked on 2026-08-19.Maintainer setup — required before implementation can publish
tomlschemanpm organization/scope.@tomlschema/tomlschema;tomlschema.orgis the canonical project domain.@tomlschema/tomlschema.--access public; scoped packages otherwise default to private.npm, restrict it totypescript-v*tags, and require maintainer approval where supported.brunoborges/toml-schema, the exact release workflow filename, and environmentnpm. Prefer stage-only permission for the first release if available so a maintainer reviews before final promotion.Repository implementation — after scope ownership is confirmed
package.jsonand its lockfile from@tomlschema/toml-schemato@tomlschema/tomlschema.publishConfigwithaccess: "public"and the npm registry so an accidental default cannot create a private package or target another registry.prepack/prepublishOnlystrategy that cleans, typechecks, tests, and builds deterministically; ensure source checkout state cannot leave staledistfiles in the tarball.typescript-v1.0.0-rc.2exactly matchespackage.jsonand lockfile metadata.npm pack --dry-run --jsonin CI and assert that onlydist, README, license/package metadata, and intended declarations/source maps are present. Confirm no tests, source secrets, caches, or repository-root files leak into the package.exports,main,types, ESM-only behavior, Nodeengines, and declaration files from the packed tarball rather than the source tree..github/workflows/release-typescript.yml, triggered only bytypescript-v*plus safe manual dry run. It must use a current npm CLI with trusted-publisher support, minimal permissions plusid-token: writeonly in the publish job, environmentnpm,npm ci, typecheck, tests, build, tarball inspection, clean install smoke tests, andnpm publish --access publicor staged publish.REFERENCE_IMPLEMENTATIONS.mdto remove “not a package-registry release,” add the npm install command/URL, explain ESM requirements, tag convention, and artifact-vs-language version distinction.Execution plan
npm --prefix reference-implementations/typescript ci, typecheck, tests, and build.npm pack, inspect its JSON file list and unpacked size, then install that tarball in clean ESM JavaScript and TypeScript consumers to verify runtime imports and declarations.typescript-v1.0.0-rc.2from the reviewed commit.@tomlschema/tomlschema@1.0.0-rc.2, import the package root, compile TypeScript against its declarations, and run the documented validation example.rc.2tolatest; use anrc/nexttag until the final release.Acceptance criteria
@tomlschema/tomlschema@1.0.0-rc.2installs publicly from npm under a prerelease dist-tag.References: organization-scoped public packages, npm trusted publishers, package provenance.