Skip to content

Publish the TypeScript reference implementation to npm #130

Description

@brunoborges

Parent: #129

Publish reference-implementations/typescript as the public ESM package @tomlschema/tomlschema@1.0.0-rc.2 on npm. The scoped package was not found when checked on 2026-08-19.

Maintainer setup — required before implementation can publish

  • Create/sign in to the project-owned npm account, enable 2FA, and create or claim the tomlschema npm organization/scope.
  • Use the agreed package coordinate @tomlschema/tomlschema; tomlschema.org is the canonical project domain.
  • Add primary and backup maintainers to the organization and confirm both can administer @tomlschema/tomlschema.
  • Bootstrap/reserve the public package if npm requires an initial authenticated publication before its trusted publisher can be configured. Use --access public; scoped packages otherwise default to private.
  • Create a protected GitHub environment named npm, restrict it to typescript-v* tags, and require maintainer approval where supported.
  • Configure npm trusted publishing for repository brunoborges/toml-schema, the exact release workflow filename, and environment npm. Prefer stage-only permission for the first release if available so a maintainer reviews before final promotion.
  • After trusted publishing works, configure publishing access to require 2FA and disallow traditional tokens, then revoke any temporary bootstrap token.

Repository implementation — after scope ownership is confirmed

  • Change package.json and its lockfile from @tomlschema/toml-schema to @tomlschema/tomlschema.
  • Add publishConfig with access: "public" and the npm registry so an accidental default cannot create a private package or target another registry.
  • Add an explicit prepack/prepublishOnly strategy that cleans, typechecks, tests, and builds deterministically; ensure source checkout state cannot leave stale dist files in the tarball.
  • Add a version/tag guard so typescript-v1.0.0-rc.2 exactly matches package.json and lockfile metadata.
  • Run npm pack --dry-run --json in CI and assert that only dist, README, license/package metadata, and intended declarations/source maps are present. Confirm no tests, source secrets, caches, or repository-root files leak into the package.
  • Verify exports, main, types, ESM-only behavior, Node engines, and declaration files from the packed tarball rather than the source tree.
  • Add .github/workflows/release-typescript.yml, triggered only by typescript-v* plus safe manual dry run. It must use a current npm CLI with trusted-publisher support, minimal permissions plus id-token: write only in the publish job, environment npm, npm ci, typecheck, tests, build, tarball inspection, clean install smoke tests, and npm publish --access public or staged publish.
  • Update the TypeScript README and REFERENCE_IMPLEMENTATIONS.md to remove “not a package-registry release,” add the npm install command/URL, explain ESM requirements, tag convention, and artifact-vs-language version distinction.

Execution plan

  1. Run npm --prefix reference-implementations/typescript ci, typecheck, tests, and build.
  2. Create the tarball with npm pack, inspect its JSON file list and unpacked size, then install that tarball in clean ESM JavaScript and TypeScript consumers to verify runtime imports and declarations.
  3. Merge the exact workflow registered with npm and create typescript-v1.0.0-rc.2 from the reviewed commit.
  4. Approve the protected trusted-publishing job (and promote the staged package if stage-only mode is used).
  5. With an empty npm cache and clean project, install @tomlschema/tomlschema@1.0.0-rc.2, import the package root, compile TypeScript against its declarations, and run the documented validation example.
  6. Confirm npm displays the expected public access, owners, provenance, README, MIT license, repository/subdirectory, Node engine, dependencies, and prerelease dist-tag behavior. Do not assign prerelease rc.2 to latest; use an rc/next tag until the final release.

Acceptance criteria

  • @tomlschema/tomlschema@1.0.0-rc.2 installs publicly from npm under a prerelease dist-tag.
  • Clean JavaScript and TypeScript consumers validate the ESM entry point and declarations.
  • Tarball contents are minimal and deterministic.
  • Publication uses npm trusted publishing with provenance and no retained long-lived write token.

References: organization-scoped public packages, npm trusted publishers, package provenance.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions