Repository navigation
ci(release): publish @eqrm/ct-cli to GitHub Packages — no-PAT cross-repo consumption (#24) - #83
Merged
Merged
Conversation
…d no PAT (#24) ct-structure's CI can't 'npm install' ct-cli today: the git dependency ssh://git@github.com/eqrm/ct-cli.git needs a credential GITHUB_TOKEN can't provide across private repos in the same org (Permission denied (publickey)). The recent GitHub improvement — pulling private deps in CI with the built-in GITHUB_TOKEN, no PAT — applies to package REGISTRIES, not raw git deps. So publish ct-cli to GitHub Packages and let consumers depend on the package. - package.json: scope the name to @eqrm/ct-cli (GitHub Packages requires the owner scope); drop 'private: true' (it blocks 'npm publish'); pin publishConfig.registry to npm.pkg.github.com so a stray publish can never hit public npm; add the 'repository' field GitHub Packages links the package by. - .releaserc.json: add @semantic-release/npm before the github plugin — it bumps the in-workspace version and publishes, but ONLY when commit-analyzer finds a releasable feat/fix (no accidental republish). - release.yml: add 'packages: write'; run 'npm ci' + build in the release job (the package is published from this working tree, and the release-assets artifact carries only the binaries, not dist/); pass NPM_TOKEN=GITHUB_TOKEN to authenticate against GitHub Packages. Consumers (eqrm/ct-structure) then depend on @eqrm/ct-cli and install it in CI with just secrets.GITHUB_TOKEN + 'permissions: packages: read', after granting the consumer repo Actions access to the package — no personal PAT. Verified locally: 'npm pack' produces @eqrm/ct-cli with dist/ built via the prepare script; lint/typecheck/test/build all green. Note: this ci: commit is itself non-releasing, so the package first publishes on the next releasable feat/fix merged to main.
This was referenced Jul 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Publishes ct-cli to GitHub Packages so
eqrm/ct-structure(and any org repo) can consume it in CI with the built-inGITHUB_TOKEN— no personal PAT. Directly unblocks the CI half of #24 / #23.Why
ct-structure's
plan/applyworkflows fail atnpm ci:The git dependency needs a credential the workflow's
GITHUB_TOKENcan't provide — it still can't read another private repo's source in the same org. The recent GitHub improvement (pull private deps in CI withGITHUB_TOKEN, no PAT) applies to package registries (*.pkg.github.com), not raw git deps. So we publish ct-cli as a package.Changes
@eqrm/ct-cli(GitHub Packages requires the owner scope); dropprivate: true(it hard-blocksnpm publish); pinpublishConfig.registrytonpm.pkg.github.comso a straynpm publishcan never hit public npm; add therepositoryfield GitHub Packages links by.@semantic-release/npmbefore the github plugin. It bumps the in-workspace version and publishes, but only when commit-analyzer finds a releasablefeat/fix(no accidental republish; never public npm).packages: write; runnpm ci+npm run buildin the release job (the package publishes from this working tree; therelease-assetsartifact carries only the binaries, notdist/); passNPM_TOKEN=GITHUB_TOKEN.Consumer side (in eqrm/ct-structure — separate PR there)
One-time: in this repo's package settings, grant
eqrm/ct-structureActions access to the published package.Verification
npm pack→@eqrm/ct-cliwithdist/built via thepreparescript (4 files).npm run lint && npm run typecheck && npm test && npm run build— all green (535 tests). Only in-repo reference to the string"ct-cli"is an unrelated keychain-service constant; nothing imports the package by name.ci:commit is itself non-releasing, so the package first publishes on the next releasablefeat/fix. If the release ever fails on npm auth, revert this PR — the binary/GitHub-Release path is unchanged otherwise.