Release checklist
September 18, 2026 ยท View on GitHub
This checklist records the completed v0.1.0 and v0.1.1 releases and the approval-gated process retained for future releases.
Completed preparation
- Package metadata, ESM
exports, declarations, and build output are configured. - Public runtime/type exports are reviewed and documented.
-
pnpm pack:checkcreates and inspects the package archive without publishing it. - A clean temporary consumer can install the packed tarball and import
jev-starter. - Node/pnpm and upstream SDK compatibility guidance is documented.
- Contributor and security guidance is present.
- Changelog has an
[Unreleased]entry. - CI runs typecheck, lint, tests, and all offline commands without a Jev API key.
- Live commands are explicit and separated from CI.
- Live smoke commands completed successfully against the Jev API.
- A manual release workflow verifies the approved tag and commit before publishing with npm trusted publishing.
Recorded release decisions
- Use the MIT License with copyright held by hamakyo.
- Use both npm package and GitHub template distribution; npm is primary.
- Keep
jev-starteras the package name and confirm the repository metadata and public API surface. - Use package version
0.1.0and Git tagv0.1.0. - Assign release ownership to
hamakyoand prefer GitHub Actions OIDC provenance.
Completed release gate
- Recheck that the npm name
jev-starteris still available. - Confirm that the release owner can authenticate to npm as
hamakyowith two-factor authentication enabled. - Bootstrap the unclaimed package name with a temporary public
0.0.0release and deprecate that version. - Configure npm trusted publishing for GitHub user
hamakyo, repositoryjev-starter, workflowrelease.yml, with directnpm publishallowed. - Obtain explicit approval for the
0.0.0bootstrap/deprecation, approved commit,v0.1.0tag, npm0.1.0publication, GitHub template setting, and GitHub Release.
Release verification commands
pnpm install --frozen-lockfile
pnpm typecheck
pnpm lint
pnpm test
pnpm eval:offline
pnpm examples:offline
pnpm rag:offline
pnpm build
pnpm package:check
The release owner completed the approved public operations on 2026-09-18.
Completed first-package bootstrap
npm trusted publishing could be configured only after the package existed. The release owner published 0.0.0 once with the authenticated hamakyo account, deprecated it as a trusted-publishing bootstrap version, and then configured the trusted publisher. The tracked package version remained 0.1.0; the bootstrap artifact was prepared in a temporary directory so the repository and release tag were not changed.
The trusted publisher must match these values exactly:
- Provider: GitHub Actions
- Organization or user:
hamakyo - Repository:
jev-starter - Workflow filename:
release.yml - Environment: none
- Allowed action: direct
npm publish
For v0.1.0, the release owner manually ran the release workflow with the approved tag and full commit SHA. No NPM_TOKEN was configured; the workflow obtained a short-lived OIDC credential and npm generated provenance automatically. Future releases follow the same approval gate with their own version, tag, and commit.
v0.1.0 result
- Approved package commit:
a420a7431cbf70a2fc1290c052827dae1889c241 - npm package:
jev-starter@0.1.0, published with trusted-publishing provenance - npm dist-tag:
latestpoints to0.1.0 - Registry clean-install and ESM import: passed
- Git tag and GitHub Release:
v0.1.0 - GitHub repository template setting: enabled
v0.1.1 result
- Approved package commit:
fcb1360239d672a859dc23f9e55ca52900052c0b - npm package:
jev-starter@0.1.1, published with trusted-publishing provenance - npm dist-tag:
latestpoints to0.1.1 - Registry clean-install and ESM import: passed
- Git tag and GitHub Release:
v0.1.1