From 6084e28c1980960fc9e78ac619c9e4359316167b Mon Sep 17 00:00:00 2001 From: Ben Jacobson Date: Fri, 25 Sep 2026 13:15:29 -0700 Subject: [PATCH] fix: unblock release changeset and document npm bootstrap --- .changeset/public-custom-runtimes.md | 1 - CONTRIBUTING.md | 11 +++++++++++ 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/.changeset/public-custom-runtimes.md b/.changeset/public-custom-runtimes.md index 747fed8..6104311 100644 --- a/.changeset/public-custom-runtimes.md +++ b/.changeset/public-custom-runtimes.md @@ -3,7 +3,6 @@ "@triplex-build/triplex-sql": minor "@triplex-build/triplex-sqlite": patch "@triplex-build/triplex-postgres": patch -"@triplex-build/triplex-cloudflare": minor "@triplex-build/triplex-testkit": minor --- diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 959ee5d..55f06cb 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -40,3 +40,14 @@ Add a Changeset for a publishable package change. Packages are not yet published release must also validate a registry-only canary in a clean external consumer and retain the existing PostgreSQL integration gate in CI. Current maturity and release gates live in [`docs/current-state.md`](docs/current-state.md). + +The first npm release needs a short-lived granular npm token with read/write publish access to the +`@triplex-build` scope and bypass 2FA enabled for unattended publishing. Organization-management +access is not needed. Add it as the `NPM_TOKEN` secret on the `npm-publish` GitHub environment before +approving the release job. After the packages exist, configure a trusted publisher on each npm +package for GitHub owner `bjacobso`, repository `triplex`, workflow `release.yml`, and environment +`npm-publish`, with direct publishing allowed. Then remove the bootstrap token. The workflow already +grants `id-token: write` and uses an OIDC-capable npm CLI for subsequent releases. + +Keep private packages out of Changeset frontmatter. Changesets cannot version a public release +when a Changeset mixes private and publishable packages.