Skip to content

fix(js): the package metadata, and two things it got wrong - #19

Merged
Abdeali099 merged 1 commit into
developfrom
js-package-metadata
Aug 20, 2026
Merged

Abdeali099 merged 1 commit into
developfrom
js-package-metadata

Conversation

@Abdeali099

Copy link
Copy Markdown
Member

Published 0.1.0 to npm, then read js/package.json properly. Two real errors, plus the metadata that was missing.

Two bugs

The README claimed the wrong licence.

To publish to npm (package name `docsigner`, MIT):

package.json and LICENSE both say Apache-2.0. That line said MIT — a licence claim in the file people actually read.

js/ had no LICENSE or NOTICE, so the tarball now on npm carries neither. Same bug #18 fixed for core/; I'd only looked at core at the time.

package.json: 245 → 723 bytes

Added homepage (→ js/), repository with "directory": "js" so npm knows it's a monorepo subfolder, bugs, and keywords. That's the GitHub link and keyword search the npm page currently lacks — npm view docsigner shows no repo at all.

A files list fixes what ships:

before after
docsigner.js, README.md, package.json ✓ ✓
test/*.test.js ✓ 10 KB dropped
LICENSE, NOTICE — ✓

Also widened the description — "Browser library for the DocSigner document signing stack" doesn't say what it does. Now "Sign PDFs in the browser with a DSC token."

README

It's the npm project page now, so it was rewritten for that reader: npm install docsigner up front, and every relative link made absolute — ../CONTRACTS.md and friends all 404 on npmjs.com. The stale "to publish, run npm publish" section is gone, since CI builds the tarball and it's already published. Contributor bits below a divider.

Verified

  • npm pack --dry-run → 5 files, tests out, licences in
  • no relative links and no MIT claim left
  • the licence drift test now covers js/ as well as core/ — 128 tests, up from 126 — and tampering with js/NOTICE fails it
  • node --test green

Note

npm freezes metadata per version, so the live 0.1.0 page keeps what it has. All of this appears when 0.1.1 publishes.

Published 0.1.0 and then read package.json properly. Two real errors:

- README said the package is MIT. It is Apache-2.0, in package.json and
  in LICENSE. A licence claim in the file people actually read.
- js/ had no LICENSE or NOTICE, so the published tarball carries
  neither. Same bug PR #18 fixed for core; I had only looked at core.

package.json gains homepage, repository (with directory: js, so npm
knows it is a monorepo subfolder), bugs and keywords -- the GitHub link
and keyword search the npm page was missing. A files list drops the two
test files from the tarball and adds the licences.

The README is the npm page now, so every relative link is absolute:
they all 404 on npmjs.com. 'To publish, run npm publish' is gone, since
CI builds it and it is already published.

The licence drift test now covers js/ as well as core/. Verified with
npm pack --dry-run (5 files, tests out, licences in) and by tampering
with js/NOTICE, which fails it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@Abdeali099
Abdeali099 merged commit e7d5907 into develop Aug 20, 2026
16 checks passed
@Abdeali099
Abdeali099 deleted the js-package-metadata branch August 20, 2026 12:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant