Skip to content

Fix npm provenance metadata for v1.1.0 - #13

Merged
ahmadrivaldi-arv merged 1 commit into
mainfrom
agent/fix-npm-provenance
Jul 27, 2026
Merged

ahmadrivaldi-arv merged 1 commit into
mainfrom
agent/fix-npm-provenance

Conversation

@ahmadrivaldi-arv

Copy link
Copy Markdown
Owner

What changed

  • add the canonical GitHub repository URL to package.json
  • make package verification reject missing or incorrect provenance repository metadata

Why

The v1.1.0 npm publish reached the registry but provenance validation rejected it because package.json did not declare repository.url. npm expected the URL to match the GitHub Actions provenance source.

Validation

  • bun run check
  • bun run verify:package
  • 19 test files / 64 tests passed

@ahmadrivaldi-arv
ahmadrivaldi-arv merged commit 79a681d into main Jul 27, 2026
3 checks passed
@ahmadrivaldi-arv
ahmadrivaldi-arv deleted the agent/fix-npm-provenance branch July 28, 2026 03:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant