Skip to content

Fix npm publish treating the tarball path as a GitHub repo - #162

Merged
rickmark merged 1 commit into
mainfrom
claude/loving-einstein-agzeu3
Oct 5, 2026
Merged

rickmark merged 1 commit into
mainfrom
claude/loving-einstein-agzeu3

Conversation

@rickmark

@rickmark rickmark commented Oct 5, 2026

Copy link
Copy Markdown
Member

Summary

The first publish after #161 failed on npm (run). The other three publish workflows succeeded: PyPI, RubyGems and the site.

npm error command git --no-replace-objects ls-remote ssh://git@github.com/dist/apple-data-1.0.657.tgz.git
npm error git@github.com: Permission denied (publickey).

npm publish dist/<file>.tgz reads dist/... as GitHub user/repo shorthand. This PR changes two things:

  • Publish ./dist/*.tgz so npm treats the argument as a local tarball.
  • Add repository (with directory: _packages/node) and homepage to package.json. npm provenance and trusted publishing check that repository.url matches the GitHub repo the workflow runs in.

The npm trusted publisher is already configured: publish-npm.yml, environment node-push.

Testing

  • npm publish ./apple-data-*.tgz --dry-run resolves to + apple-data@1.0.643, the version in the tarball packed from this branch.
  • The packed tarball's package.json contains the new repository field.
  • actionlint passes.

🤖 Generated with Claude Code

https://claude.ai/code/session_01A7iNWzEEZrwfmb3a8J3F7L


Generated by Claude Code

`npm publish dist/x.tgz` parses `dist/...` as GitHub shorthand and tries to
git ls-remote it; use an explicit `./` path. Add the `repository` field that
npm provenance / trusted publishing verifies against the source repo.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A7iNWzEEZrwfmb3a8J3F7L
@rickmark
rickmark marked this pull request as ready for review October 5, 2026 16:21
@rickmark
rickmark merged commit 7b2ba25 into main Oct 5, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants