Skip to content

Commit af1e401

Browse files
Sergiu Oalacursoragent
andcommitted
docs: clarify withholding approval skips npm publishing
Co-authored-by: Cursor <cursoragent@cursor.com>
1 parent 79f4a84 commit af1e401

2 files changed

Lines changed: 5 additions & 5 deletions

File tree

‎.github/workflows/npm-publish.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -75,12 +75,12 @@ jobs:
7575
node-version: 26.x
7676
registry-url: https://registry.npmjs.org
7777

78-
- name: publish to npm
78+
- name: npm stage publish
7979
env:
8080
RELEASE_TAG: ${{ inputs.tag }}
8181
run: |
8282
if [[ "$RELEASE_TAG" == *-rc* ]]; then
83-
npm publish --provenance --tag rc
83+
npm stage publish --provenance --tag rc
8484
else
85-
npm publish --provenance
85+
npm stage publish --provenance
8686
fi

‎README.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -548,9 +548,9 @@ make codestyle-fix
548548
Releases are automated with [release-please](https://github.com/googleapis/release-please#readme). Versioning comes from conventional commits on `master` (`fix:` patches, `feat:` minor, `!` / `BREAKING CHANGE` major). `chore:` does not bump. There is a **single** shared Release PR; RC and stable take turns on it.
549549

550550
1. Merge `fix:` / `feat:` PRs into `master`. `release-please` opens or updates that PR as a **release candidate** (`X.Y.Z-rc`, then `X.Y.Z-rc.1`, …). `package.json` on the PR is already the version that will be tagged.
551-
2. Merge the RC PR when you want to cut an RC. `release-please` tags a GitHub **prerelease** (`vX.Y.Z-rc`) and dispatches `npm-publish`. Approve the **Publish** environment to publish to npm with dist-tag `rc`; withhold approval to skip npm (the git tag still exists).
551+
2. Merge the RC PR when you want to cut an RC. `release-please` tags a GitHub **prerelease** (`vX.Y.Z-rc`) and dispatches `npm-publish`. Approve the **Publish** environment to run `npm stage publish --provenance --tag rc`; withhold approval to skip staging (the git tag still exists). A maintainer then approves the staged package on npm (2FA) before it is installable.
552552
3. After the RC merge, the shared PR is rewritten as the matching **stable** Release PR (`X.Y.Z`).
553-
4. Merge that stable PR to ship `X.Y.Z` (GitHub Release + `npm-publish` without `--tag rc`, npm dist-tag `latest`). Same **Publish** approval gate.
553+
4. Merge that stable PR to ship `X.Y.Z` (GitHub Release + `npm stage publish --provenance`, npm dist-tag `latest` after npm approval). Same **Publish** environment gate, then npm 2FA approve.
554554
5. Further `fix:` / `feat:` commits on `master` while the stable PR is still open rewrite it into the **next RC** (`X.Y.Z-rc.1`, …) instead of shipping that stable. Use that when you want another candidate; merge stable with no extra bumping commits when you want to publish `latest`.
555555

556556
## License

0 commit comments

Comments
 (0)