From ea29ef590e57732ff34e0c7b15e49d4373f689cc Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 5 Oct 2026 16:20:24 +0000 Subject: [PATCH] Fix npm publish treating the tarball path as a GitHub repo `npm publish dist/x.tgz` parses `dist/...` as GitHub shorthand and tries to git ls-remote it; use an explicit `./` path. Add the `repository` field that npm provenance / trusted publishing verifies against the source repo. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01A7iNWzEEZrwfmb3a8J3F7L --- .github/workflows/publish-npm.yml | 2 +- _packages/node/package.json | 6 ++++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/publish-npm.yml b/.github/workflows/publish-npm.yml index c35e71d7..a6c2c8b0 100644 --- a/.github/workflows/publish-npm.yml +++ b/.github/workflows/publish-npm.yml @@ -32,6 +32,6 @@ jobs: - name: Publish to NPM Registry # Uses npm trusted publishing (OIDC) when configured on npmjs.com, otherwise falls back to NPM_TOKEN - run: npm publish dist/*.tgz --access public --provenance + run: npm publish ./dist/*.tgz --access public --provenance env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} diff --git a/_packages/node/package.json b/_packages/node/package.json index 2906347c..e95348aa 100644 --- a/_packages/node/package.json +++ b/_packages/node/package.json @@ -4,6 +4,12 @@ "version": "1.0.643", "license": "MIT", "author": "Rick Mark ", + "repository": { + "type": "git", + "url": "git+https://github.com/hack-different/apple-knowledge.git", + "directory": "_packages/node" + }, + "homepage": "https://docs.hackdiffe.rent", "keywords": [ "apple", "data",