Skip to content

fix: add repository metadata so npm provenance validation passes - #30

Merged
nicosampler merged 1 commit into
mainfrom
fix/add-repository-metadata
Aug 3, 2026
Merged

fix: add repository metadata so npm provenance validation passes#30
nicosampler merged 1 commit into
mainfrom
fix/add-repository-metadata

Conversation

@nicosampler

Copy link
Copy Markdown
Collaborator

Summary

No related issue. Publishing 0.2.2 from CI failed with E422: npm's sigstore
provenance check requires repository.url in package.json to match the
GitHub repository the workflow runs from, and the field was missing.

Changes

  • Add the repository field (git+https://github.com/BootNodeDev/canton-barebones.git) to package.json
  • Sync package-lock.json
  • Add an empty changeset: 0.2.2 is versioned but unpublished, so no bump is needed — merging this lets CI retry the 0.2.2 publish

Acceptance criteria

  • The release workflow on main publishes @bootnodedev/canton-barebones@0.2.2 with provenance

Test plan

Automated tests

npm test — 30/30 pass. No new tests; metadata-only change.

Manual verification

Merge and watch the Release workflow publish 0.2.2 to npm.

Breaking changes

None.

Checklist

  • Self-reviewed my own diff
  • Tests added or updated
  • Docs updated (if applicable)
  • No unrelated changes bundled in

Screenshots

None.

@nicosampler nicosampler self-assigned this Aug 3, 2026
@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@nicosampler
nicosampler merged commit 14b7c2b into main Aug 3, 2026
3 checks passed
@nicosampler
nicosampler deleted the fix/add-repository-metadata branch August 3, 2026 18:06
nicosampler added a commit that referenced this pull request Aug 3, 2026
… 0.2.2 (#31)

## Summary

No related issue. The empty changeset added in #30 was meant to satisfy
the
changeset check without bumping the version, but changesets/action
treats
"only empty changesets" as pending work: it neither opens a Version PR
nor
publishes. Removing it unblocks the publish of the already-versioned
0.2.2.

## Changes

- Delete `.changeset/puny-knives-roll.md` (empty changeset)

## Acceptance criteria

- [ ] On merge, the Release workflow publishes
`@bootnodedev/canton-barebones@0.2.2` with provenance

## Test plan

### Automated tests

No automated tests added — no package code changes.

### Manual verification

`npx changeset status --since=origin/main` passes (no package changes
require a changeset). After merge, watch the Release run publish 0.2.2.

## Breaking changes

None.

## Checklist

- [x] Self-reviewed my own diff
- [ ] Tests added or updated
- [ ] Docs updated (if applicable)
- [x] No unrelated changes bundled in

## Screenshots

None.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants