build(release): publish the vendored framework and the native packages publicly
The three release sequences shipped with publishConfig.access: restricted, so nothing in the @deepseek-ai scope was installable from outside the organization. A restricted dependency is what actually blocks a public consumer: every harness package declares the vendored framework as a peerDependency, and dsh-sandbox-local declares the Landlock entry as a dependency. Those two sequences therefore go public first — the nine vendor/* packages and the three native/landlock-run packages — while the dsh family stays restricted until its own sequence is opened deliberately. No public package requires a restricted one in this arrangement. Access is now per sequence, so no publish path can pass --access: one flag cannot express two levels and would override the manifest that owns the fact. publish.ts stops passing it, matching the native workflow, and check-workspace-constraints holds each manifest to its own sequence's level, which is what stops the scope from drifting one package at a time. Harness consumers reference the Landlock entry as workspace:^ instead of workspace:*, so a published harness package accepts the entry's patch and minor releases. The entry keeps workspace:* for its platform packages, where the binary must match the entry version exactly. Two rationales that named a private registry no longer describe the vendored sequence; they now state the durable reason, which is that the verification must not depend on the registry already carrying matching versions.
This commit is contained in:
@@ -81,8 +81,10 @@ jobs:
|
||||
run: pnpm run release:pack --family dsh --out dist/npm
|
||||
|
||||
# The harness packages declare the vendored framework as a peer, and this
|
||||
# job has no credentials for the private registry, so the verification
|
||||
# installs that family's pack output too. Only dist/npm is published.
|
||||
# verification must not depend on the registry already carrying matching
|
||||
# versions — one pull request may bump both families before either
|
||||
# publishes — so it installs that family's pack output too. Only dist/npm
|
||||
# is published.
|
||||
- name: Pack the vendored framework for verification
|
||||
run: pnpm run release:pack --family vendor --out dist/npm-vendor
|
||||
|
||||
|
||||
Reference in New Issue
Block a user