Skip to content

Fix npm provenance repository identity for Shield 2.1.2 - #5

Merged
x1xhlol merged 2 commits into
masterfrom
fix/npm-provenance-repository
Oct 4, 2026
Merged

x1xhlol merged 2 commits into
masterfrom
fix/npm-provenance-repository

Conversation

@x1xhlol

@x1xhlol x1xhlol commented Oct 4, 2026

Copy link
Copy Markdown
Member

Npm rejected Shield 2.1.1 because its lowercase repository URL did not match the case-sensitive GitHub Actions provenance identity. Correct the URL to https://github.com/ZeroLeaks/shield, validate that identity before publishing, and prepare 2.1.2 with matching package and registry documentation. Keep earlier source tags without rewriting them.

Validation: repository identity check passes locally; full package CI covers typecheck, 1,263 tests (two optional model tests skipped), build, package contents, and isolated AI SDK 5–7 consumers and the registry example. Publishing uses the persistent NPM_TOKEN secret in the npm GitHub environment.

@x1xhlol
x1xhlol merged commit f272ca1 into master Oct 4, 2026
1 check passed
@x1xhlol
x1xhlol deleted the fix/npm-provenance-repository branch October 4, 2026 18:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant