Make npm bootstrap resumable - #154

Closed
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery
Closed

Make npm bootstrap resumable#154
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery

Conversation

@taras

@tarastaras commented Jul 26, 2026

Copy link
Copy Markdown
Owner

Why

New workspace packages need an npm package record before GitHub Actions can be
configured as their trusted publisher. A completed npm web-auth flow can leave
the bootstrap version published while the invoking command fails before
configuring trust, making the original bootstrap script impossible to rerun.

What changes

Before:

  • The bootstrap script always required an absent npm package.
  • A partial first run required manual recovery.
  • Local npm registry settings could redirect the bootstrap.

After:

  • The script publishes an absent bootstrap package or resumes the expected
    bootstrap state and configures trusted publishing.
  • It targets public npm explicitly and documents an interactive-terminal,
    Volta-compatible workflow.

How it works

package lookup → publish only when absent → configure trusted publisher → verify tags and trust

Review guide

Start with:scripts/bootstrap-npm-package.md

Then review:

  1. The distinction between an absent package, the expected bootstrap version,
    and an unexpected existing package.
  2. The recovery path: an existing bootstrap version skips publication but still
    configures trusted publishing.
  3. scripts/tests/bootstrap-npm-package.test.ts, which drives each state with
    a fake npm command.
  4. The concise release-process contract.

Look carefully at:

  • The script never overwrites an existing version or assigns latest.

What must stay true

  • Only 0.0.0-bootstrap.0 under the bootstrap dist-tag is resumable — the
    script validates both before skipping publication.
  • The implementation is not built or published by this script — the first
    tagged release remains responsible for latest.
  • Trusted publishing remains bound to publish-packages.yml, the repository,
    and the npm-publish environment.

How to verify it

  • The focused bootstrap suite proves absent packages publish before trust,
    expected bootstrap packages resume with no second publish, unexpected
    versions fail safely, and a package sitting at 0.0.0-bootstrap.0 under
    some other dist-tag is rejected with the expected-tag diagnostic without
    publishing or configuring trust. Disabling the dist-tag guard fails that
    fourth case alone, so it does not overlap the other three.
  • deno task lint passes.
  • deno task check:jsr passes.
  • The tracked repository type-check passes.

The canonical deno task check and deno task test are blocked locally by an
untracked .claude/worktrees/issue-140-workspace-task-scope checkout that Deno
discovers and type-checks. Its pre-existing errors are outside this diff.

Scope

Included

  • Resumable public-npm bootstrap and trusted-publisher setup.
  • Operator instructions for npm web authentication and Volta.
  • Focused behavior tests and the release-process contract.

Intentionally unchanged

Risks and limitations

Scope confirmation

  • Every changed file supports the purpose described above.
  • Unrelated cleanup and formatting changes are excluded.
  • Generated or mechanical changes are clearly identified.
  • The description matches the final diff and test results.

@github-actions

github-actionsBot commented Jul 26, 2026

Copy link
Copy Markdown

PR #154: Make npm bootstrap resumable

3 files, +334 / -13

Scope

✅ PR scope looks good.

Structural

🟡 1 console statements.

Slop

✅ Slop indicators look low.

Static Analysis

✅ Oxlint found no issues.

Correctness

No extraneous code patterns detected.

@taras

taras commented Aug 3, 2026

Copy link
Copy Markdown
OwnerAuthor

Superseded by #308, which closes #276. That PR rebuilds this document on main around <Elicit>: the OTP is asked for at the point of use, so the npm commands are non-interactive and the awk-the-block-out-of-the-document workaround is gone. The shell guards, the preview/publish split, the empty 0.0.0-bootstrap.0 artifact under the bootstrap dist-tag, the npm trust github invocation, and the verification output all carry over from here.

@tarastaras closed this Aug 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@taras
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Make npm bootstrap resumable - #154

Closed
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery
Closed

Make npm bootstrap resumable#154
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery

Conversation

@taras

@tarastaras commented Jul 26, 2026

Copy link
Copy Markdown
Owner

Why

New workspace packages need an npm package record before GitHub Actions can be
configured as their trusted publisher. A completed npm web-auth flow can leave
the bootstrap version published while the invoking command fails before
configuring trust, making the original bootstrap script impossible to rerun.

What changes

Before:

  • The bootstrap script always required an absent npm package.
  • A partial first run required manual recovery.
  • Local npm registry settings could redirect the bootstrap.

After:

  • The script publishes an absent bootstrap package or resumes the expected
    bootstrap state and configures trusted publishing.
  • It targets public npm explicitly and documents an interactive-terminal,
    Volta-compatible workflow.

How it works

package lookup → publish only when absent → configure trusted publisher → verify tags and trust

Review guide

Start with:scripts/bootstrap-npm-package.md

Then review:

  1. The distinction between an absent package, the expected bootstrap version,
    and an unexpected existing package.
  2. The recovery path: an existing bootstrap version skips publication but still
    configures trusted publishing.
  3. scripts/tests/bootstrap-npm-package.test.ts, which drives each state with
    a fake npm command.
  4. The concise release-process contract.

Look carefully at:

  • The script never overwrites an existing version or assigns latest.

What must stay true

  • Only 0.0.0-bootstrap.0 under the bootstrap dist-tag is resumable — the
    script validates both before skipping publication.
  • The implementation is not built or published by this script — the first
    tagged release remains responsible for latest.
  • Trusted publishing remains bound to publish-packages.yml, the repository,
    and the npm-publish environment.

How to verify it

  • The focused bootstrap suite proves absent packages publish before trust,
    expected bootstrap packages resume with no second publish, unexpected
    versions fail safely, and a package sitting at 0.0.0-bootstrap.0 under
    some other dist-tag is rejected with the expected-tag diagnostic without
    publishing or configuring trust. Disabling the dist-tag guard fails that
    fourth case alone, so it does not overlap the other three.
  • deno task lint passes.
  • deno task check:jsr passes.
  • The tracked repository type-check passes.

The canonical deno task check and deno task test are blocked locally by an
untracked .claude/worktrees/issue-140-workspace-task-scope checkout that Deno
discovers and type-checks. Its pre-existing errors are outside this diff.

Scope

Included

  • Resumable public-npm bootstrap and trusted-publisher setup.
  • Operator instructions for npm web authentication and Volta.
  • Focused behavior tests and the release-process contract.

Intentionally unchanged

Risks and limitations

Scope confirmation

  • Every changed file supports the purpose described above.
  • Unrelated cleanup and formatting changes are excluded.
  • Generated or mechanical changes are clearly identified.
  • The description matches the final diff and test results.

@github-actions

github-actionsBot commented Jul 26, 2026

Copy link
Copy Markdown

PR #154: Make npm bootstrap resumable

3 files, +334 / -13

Scope

✅ PR scope looks good.

Structural

🟡 1 console statements.

Slop

✅ Slop indicators look low.

Static Analysis

✅ Oxlint found no issues.

Correctness

No extraneous code patterns detected.

@taras

taras commented Aug 3, 2026

Copy link
Copy Markdown
OwnerAuthor

Superseded by #308, which closes #276. That PR rebuilds this document on main around <Elicit>: the OTP is asked for at the point of use, so the npm commands are non-interactive and the awk-the-block-out-of-the-document workaround is gone. The shell guards, the preview/publish split, the empty 0.0.0-bootstrap.0 artifact under the bootstrap dist-tag, the npm trust github invocation, and the verification output all carry over from here.

@tarastaras closed this Aug 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@taras
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make npm bootstrap resumable - #154

Closed
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery
Closed

Make npm bootstrap resumable#154
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery

Conversation

@taras

@tarastaras commented Jul 26, 2026

Copy link
Copy Markdown
Owner

Why

New workspace packages need an npm package record before GitHub Actions can be
configured as their trusted publisher. A completed npm web-auth flow can leave
the bootstrap version published while the invoking command fails before
configuring trust, making the original bootstrap script impossible to rerun.

What changes

Before:

  • The bootstrap script always required an absent npm package.
  • A partial first run required manual recovery.
  • Local npm registry settings could redirect the bootstrap.

After:

  • The script publishes an absent bootstrap package or resumes the expected
    bootstrap state and configures trusted publishing.
  • It targets public npm explicitly and documents an interactive-terminal,
    Volta-compatible workflow.

How it works

package lookup → publish only when absent → configure trusted publisher → verify tags and trust

Review guide

Start with:scripts/bootstrap-npm-package.md

Then review:

  1. The distinction between an absent package, the expected bootstrap version,
    and an unexpected existing package.
  2. The recovery path: an existing bootstrap version skips publication but still
    configures trusted publishing.
  3. scripts/tests/bootstrap-npm-package.test.ts, which drives each state with
    a fake npm command.
  4. The concise release-process contract.

Look carefully at:

  • The script never overwrites an existing version or assigns latest.

What must stay true

  • Only 0.0.0-bootstrap.0 under the bootstrap dist-tag is resumable — the
    script validates both before skipping publication.
  • The implementation is not built or published by this script — the first
    tagged release remains responsible for latest.
  • Trusted publishing remains bound to publish-packages.yml, the repository,
    and the npm-publish environment.

How to verify it

  • The focused bootstrap suite proves absent packages publish before trust,
    expected bootstrap packages resume with no second publish, unexpected
    versions fail safely, and a package sitting at 0.0.0-bootstrap.0 under
    some other dist-tag is rejected with the expected-tag diagnostic without
    publishing or configuring trust. Disabling the dist-tag guard fails that
    fourth case alone, so it does not overlap the other three.
  • deno task lint passes.
  • deno task check:jsr passes.
  • The tracked repository type-check passes.

The canonical deno task check and deno task test are blocked locally by an
untracked .claude/worktrees/issue-140-workspace-task-scope checkout that Deno
discovers and type-checks. Its pre-existing errors are outside this diff.

Scope

Included

  • Resumable public-npm bootstrap and trusted-publisher setup.
  • Operator instructions for npm web authentication and Volta.
  • Focused behavior tests and the release-process contract.

Intentionally unchanged

Risks and limitations

Scope confirmation

  • Every changed file supports the purpose described above.
  • Unrelated cleanup and formatting changes are excluded.
  • Generated or mechanical changes are clearly identified.
  • The description matches the final diff and test results.

@github-actions

github-actionsBot commented Jul 26, 2026

Copy link
Copy Markdown

PR #154: Make npm bootstrap resumable

3 files, +334 / -13

Scope

✅ PR scope looks good.

Structural

🟡 1 console statements.

Slop

✅ Slop indicators look low.

Static Analysis

✅ Oxlint found no issues.

Correctness

No extraneous code patterns detected.

@taras

taras commented Aug 3, 2026

Copy link
Copy Markdown
OwnerAuthor

Superseded by #308, which closes #276. That PR rebuilds this document on main around <Elicit>: the OTP is asked for at the point of use, so the npm commands are non-interactive and the awk-the-block-out-of-the-document workaround is gone. The shell guards, the preview/publish split, the empty 0.0.0-bootstrap.0 artifact under the bootstrap dist-tag, the npm trust github invocation, and the verification output all carry over from here.

@tarastaras closed this Aug 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@taras
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make npm bootstrap resumable - #154

Closed
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery
Closed

Make npm bootstrap resumable#154
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery

Conversation

@taras

@tarastaras commented Jul 26, 2026

Copy link
Copy Markdown
Owner

Why

New workspace packages need an npm package record before GitHub Actions can be
configured as their trusted publisher. A completed npm web-auth flow can leave
the bootstrap version published while the invoking command fails before
configuring trust, making the original bootstrap script impossible to rerun.

What changes

Before:

  • The bootstrap script always required an absent npm package.
  • A partial first run required manual recovery.
  • Local npm registry settings could redirect the bootstrap.

After:

  • The script publishes an absent bootstrap package or resumes the expected
    bootstrap state and configures trusted publishing.
  • It targets public npm explicitly and documents an interactive-terminal,
    Volta-compatible workflow.

How it works

package lookup → publish only when absent → configure trusted publisher → verify tags and trust

Review guide

Start with:scripts/bootstrap-npm-package.md

Then review:

  1. The distinction between an absent package, the expected bootstrap version,
    and an unexpected existing package.
  2. The recovery path: an existing bootstrap version skips publication but still
    configures trusted publishing.
  3. scripts/tests/bootstrap-npm-package.test.ts, which drives each state with
    a fake npm command.
  4. The concise release-process contract.

Look carefully at:

  • The script never overwrites an existing version or assigns latest.

What must stay true

  • Only 0.0.0-bootstrap.0 under the bootstrap dist-tag is resumable — the
    script validates both before skipping publication.
  • The implementation is not built or published by this script — the first
    tagged release remains responsible for latest.
  • Trusted publishing remains bound to publish-packages.yml, the repository,
    and the npm-publish environment.

How to verify it

  • The focused bootstrap suite proves absent packages publish before trust,
    expected bootstrap packages resume with no second publish, unexpected
    versions fail safely, and a package sitting at 0.0.0-bootstrap.0 under
    some other dist-tag is rejected with the expected-tag diagnostic without
    publishing or configuring trust. Disabling the dist-tag guard fails that
    fourth case alone, so it does not overlap the other three.
  • deno task lint passes.
  • deno task check:jsr passes.
  • The tracked repository type-check passes.

The canonical deno task check and deno task test are blocked locally by an
untracked .claude/worktrees/issue-140-workspace-task-scope checkout that Deno
discovers and type-checks. Its pre-existing errors are outside this diff.

Scope

Included

  • Resumable public-npm bootstrap and trusted-publisher setup.
  • Operator instructions for npm web authentication and Volta.
  • Focused behavior tests and the release-process contract.

Intentionally unchanged

Risks and limitations

Scope confirmation

  • Every changed file supports the purpose described above.
  • Unrelated cleanup and formatting changes are excluded.
  • Generated or mechanical changes are clearly identified.
  • The description matches the final diff and test results.

@github-actions

github-actionsBot commented Jul 26, 2026

Copy link
Copy Markdown

PR #154: Make npm bootstrap resumable

3 files, +334 / -13

Scope

✅ PR scope looks good.

Structural

🟡 1 console statements.

Slop

✅ Slop indicators look low.

Static Analysis

✅ Oxlint found no issues.

Correctness

No extraneous code patterns detected.

@taras

taras commented Aug 3, 2026

Copy link
Copy Markdown
OwnerAuthor

Superseded by #308, which closes #276. That PR rebuilds this document on main around <Elicit>: the OTP is asked for at the point of use, so the npm commands are non-interactive and the awk-the-block-out-of-the-document workaround is gone. The shell guards, the preview/publish split, the empty 0.0.0-bootstrap.0 artifact under the bootstrap dist-tag, the npm trust github invocation, and the verification output all carry over from here.

@tarastaras closed this Aug 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@taras
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Make npm bootstrap resumable - #154

Closed
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery
Closed

Make npm bootstrap resumable#154
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery

Conversation

@taras

@tarastaras commented Jul 26, 2026

Copy link
Copy Markdown
Owner

Why

New workspace packages need an npm package record before GitHub Actions can be
configured as their trusted publisher. A completed npm web-auth flow can leave
the bootstrap version published while the invoking command fails before
configuring trust, making the original bootstrap script impossible to rerun.

What changes

Before:

  • The bootstrap script always required an absent npm package.
  • A partial first run required manual recovery.
  • Local npm registry settings could redirect the bootstrap.

After:

  • The script publishes an absent bootstrap package or resumes the expected
    bootstrap state and configures trusted publishing.
  • It targets public npm explicitly and documents an interactive-terminal,
    Volta-compatible workflow.

How it works

package lookup → publish only when absent → configure trusted publisher → verify tags and trust

Review guide

Start with:scripts/bootstrap-npm-package.md

Then review:

  1. The distinction between an absent package, the expected bootstrap version,
    and an unexpected existing package.
  2. The recovery path: an existing bootstrap version skips publication but still
    configures trusted publishing.
  3. scripts/tests/bootstrap-npm-package.test.ts, which drives each state with
    a fake npm command.
  4. The concise release-process contract.

Look carefully at:

  • The script never overwrites an existing version or assigns latest.

What must stay true

  • Only 0.0.0-bootstrap.0 under the bootstrap dist-tag is resumable — the
    script validates both before skipping publication.
  • The implementation is not built or published by this script — the first
    tagged release remains responsible for latest.
  • Trusted publishing remains bound to publish-packages.yml, the repository,
    and the npm-publish environment.

How to verify it

  • The focused bootstrap suite proves absent packages publish before trust,
    expected bootstrap packages resume with no second publish, unexpected
    versions fail safely, and a package sitting at 0.0.0-bootstrap.0 under
    some other dist-tag is rejected with the expected-tag diagnostic without
    publishing or configuring trust. Disabling the dist-tag guard fails that
    fourth case alone, so it does not overlap the other three.
  • deno task lint passes.
  • deno task check:jsr passes.
  • The tracked repository type-check passes.

The canonical deno task check and deno task test are blocked locally by an
untracked .claude/worktrees/issue-140-workspace-task-scope checkout that Deno
discovers and type-checks. Its pre-existing errors are outside this diff.

Scope

Included

  • Resumable public-npm bootstrap and trusted-publisher setup.
  • Operator instructions for npm web authentication and Volta.
  • Focused behavior tests and the release-process contract.

Intentionally unchanged

Risks and limitations

Scope confirmation

  • Every changed file supports the purpose described above.
  • Unrelated cleanup and formatting changes are excluded.
  • Generated or mechanical changes are clearly identified.
  • The description matches the final diff and test results.

@github-actions

github-actionsBot commented Jul 26, 2026

Copy link
Copy Markdown

PR #154: Make npm bootstrap resumable

3 files, +334 / -13

Scope

✅ PR scope looks good.

Structural

🟡 1 console statements.

Slop

✅ Slop indicators look low.

Static Analysis

✅ Oxlint found no issues.

Correctness

No extraneous code patterns detected.

@taras

taras commented Aug 3, 2026

Copy link
Copy Markdown
OwnerAuthor

Superseded by #308, which closes #276. That PR rebuilds this document on main around <Elicit>: the OTP is asked for at the point of use, so the npm commands are non-interactive and the awk-the-block-out-of-the-document workaround is gone. The shell guards, the preview/publish split, the empty 0.0.0-bootstrap.0 artifact under the bootstrap dist-tag, the npm trust github invocation, and the verification output all carry over from here.

@tarastaras closed this Aug 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@taras
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make npm bootstrap resumable - #154

Closed
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery
Closed

Make npm bootstrap resumable#154
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery

Conversation

@taras

@tarastaras commented Jul 26, 2026

Copy link
Copy Markdown
Owner

Why

New workspace packages need an npm package record before GitHub Actions can be
configured as their trusted publisher. A completed npm web-auth flow can leave
the bootstrap version published while the invoking command fails before
configuring trust, making the original bootstrap script impossible to rerun.

What changes

Before:

  • The bootstrap script always required an absent npm package.
  • A partial first run required manual recovery.
  • Local npm registry settings could redirect the bootstrap.

After:

  • The script publishes an absent bootstrap package or resumes the expected
    bootstrap state and configures trusted publishing.
  • It targets public npm explicitly and documents an interactive-terminal,
    Volta-compatible workflow.

How it works

package lookup → publish only when absent → configure trusted publisher → verify tags and trust

Review guide

Start with:scripts/bootstrap-npm-package.md

Then review:

  1. The distinction between an absent package, the expected bootstrap version,
    and an unexpected existing package.
  2. The recovery path: an existing bootstrap version skips publication but still
    configures trusted publishing.
  3. scripts/tests/bootstrap-npm-package.test.ts, which drives each state with
    a fake npm command.
  4. The concise release-process contract.

Look carefully at:

  • The script never overwrites an existing version or assigns latest.

What must stay true

  • Only 0.0.0-bootstrap.0 under the bootstrap dist-tag is resumable — the
    script validates both before skipping publication.
  • The implementation is not built or published by this script — the first
    tagged release remains responsible for latest.
  • Trusted publishing remains bound to publish-packages.yml, the repository,
    and the npm-publish environment.

How to verify it

  • The focused bootstrap suite proves absent packages publish before trust,
    expected bootstrap packages resume with no second publish, unexpected
    versions fail safely, and a package sitting at 0.0.0-bootstrap.0 under
    some other dist-tag is rejected with the expected-tag diagnostic without
    publishing or configuring trust. Disabling the dist-tag guard fails that
    fourth case alone, so it does not overlap the other three.
  • deno task lint passes.
  • deno task check:jsr passes.
  • The tracked repository type-check passes.

The canonical deno task check and deno task test are blocked locally by an
untracked .claude/worktrees/issue-140-workspace-task-scope checkout that Deno
discovers and type-checks. Its pre-existing errors are outside this diff.

Scope

Included

  • Resumable public-npm bootstrap and trusted-publisher setup.
  • Operator instructions for npm web authentication and Volta.
  • Focused behavior tests and the release-process contract.

Intentionally unchanged

Risks and limitations

Scope confirmation

  • Every changed file supports the purpose described above.
  • Unrelated cleanup and formatting changes are excluded.
  • Generated or mechanical changes are clearly identified.
  • The description matches the final diff and test results.

@github-actions

github-actionsBot commented Jul 26, 2026

Copy link
Copy Markdown

PR #154: Make npm bootstrap resumable

3 files, +334 / -13

Scope

✅ PR scope looks good.

Structural

🟡 1 console statements.

Slop

✅ Slop indicators look low.

Static Analysis

✅ Oxlint found no issues.

Correctness

No extraneous code patterns detected.

@taras

taras commented Aug 3, 2026

Copy link
Copy Markdown
OwnerAuthor

Superseded by #308, which closes #276. That PR rebuilds this document on main around <Elicit>: the OTP is asked for at the point of use, so the npm commands are non-interactive and the awk-the-block-out-of-the-document workaround is gone. The shell guards, the preview/publish split, the empty 0.0.0-bootstrap.0 artifact under the bootstrap dist-tag, the npm trust github invocation, and the verification output all carry over from here.

@tarastaras closed this Aug 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@taras
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make npm bootstrap resumable - #154

Closed
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery
Closed

Make npm bootstrap resumable#154
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery

Conversation

@taras

@tarastaras commented Jul 26, 2026

Copy link
Copy Markdown
Owner

Why

New workspace packages need an npm package record before GitHub Actions can be
configured as their trusted publisher. A completed npm web-auth flow can leave
the bootstrap version published while the invoking command fails before
configuring trust, making the original bootstrap script impossible to rerun.

What changes

Before:

  • The bootstrap script always required an absent npm package.
  • A partial first run required manual recovery.
  • Local npm registry settings could redirect the bootstrap.

After:

  • The script publishes an absent bootstrap package or resumes the expected
    bootstrap state and configures trusted publishing.
  • It targets public npm explicitly and documents an interactive-terminal,
    Volta-compatible workflow.

How it works

package lookup → publish only when absent → configure trusted publisher → verify tags and trust

Review guide

Start with:scripts/bootstrap-npm-package.md

Then review:

  1. The distinction between an absent package, the expected bootstrap version,
    and an unexpected existing package.
  2. The recovery path: an existing bootstrap version skips publication but still
    configures trusted publishing.
  3. scripts/tests/bootstrap-npm-package.test.ts, which drives each state with
    a fake npm command.
  4. The concise release-process contract.

Look carefully at:

  • The script never overwrites an existing version or assigns latest.

What must stay true

  • Only 0.0.0-bootstrap.0 under the bootstrap dist-tag is resumable — the
    script validates both before skipping publication.
  • The implementation is not built or published by this script — the first
    tagged release remains responsible for latest.
  • Trusted publishing remains bound to publish-packages.yml, the repository,
    and the npm-publish environment.

How to verify it

  • The focused bootstrap suite proves absent packages publish before trust,
    expected bootstrap packages resume with no second publish, unexpected
    versions fail safely, and a package sitting at 0.0.0-bootstrap.0 under
    some other dist-tag is rejected with the expected-tag diagnostic without
    publishing or configuring trust. Disabling the dist-tag guard fails that
    fourth case alone, so it does not overlap the other three.
  • deno task lint passes.
  • deno task check:jsr passes.
  • The tracked repository type-check passes.

The canonical deno task check and deno task test are blocked locally by an
untracked .claude/worktrees/issue-140-workspace-task-scope checkout that Deno
discovers and type-checks. Its pre-existing errors are outside this diff.

Scope

Included

  • Resumable public-npm bootstrap and trusted-publisher setup.
  • Operator instructions for npm web authentication and Volta.
  • Focused behavior tests and the release-process contract.

Intentionally unchanged

Risks and limitations

Scope confirmation

  • Every changed file supports the purpose described above.
  • Unrelated cleanup and formatting changes are excluded.
  • Generated or mechanical changes are clearly identified.
  • The description matches the final diff and test results.

@github-actions

github-actionsBot commented Jul 26, 2026

Copy link
Copy Markdown

PR #154: Make npm bootstrap resumable

3 files, +334 / -13

Scope

✅ PR scope looks good.

Structural

🟡 1 console statements.

Slop

✅ Slop indicators look low.

Static Analysis

✅ Oxlint found no issues.

Correctness

No extraneous code patterns detected.

@taras

taras commented Aug 3, 2026

Copy link
Copy Markdown
OwnerAuthor

Superseded by #308, which closes #276. That PR rebuilds this document on main around <Elicit>: the OTP is asked for at the point of use, so the npm commands are non-interactive and the awk-the-block-out-of-the-document workaround is gone. The shell guards, the preview/publish split, the empty 0.0.0-bootstrap.0 artifact under the bootstrap dist-tag, the npm trust github invocation, and the verification output all carry over from here.

@tarastaras closed this Aug 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@taras
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Make npm bootstrap resumable - #154

Closed
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery
Closed

Make npm bootstrap resumable#154
taras wants to merge 2 commits into
mainfrom
codex/bootstrap-recovery

Conversation

@taras

@tarastaras commented Jul 26, 2026

Copy link
Copy Markdown
Owner

Why

New workspace packages need an npm package record before GitHub Actions can be
configured as their trusted publisher. A completed npm web-auth flow can leave
the bootstrap version published while the invoking command fails before
configuring trust, making the original bootstrap script impossible to rerun.

What changes

Before:

  • The bootstrap script always required an absent npm package.
  • A partial first run required manual recovery.
  • Local npm registry settings could redirect the bootstrap.

After:

  • The script publishes an absent bootstrap package or resumes the expected
    bootstrap state and configures trusted publishing.
  • It targets public npm explicitly and documents an interactive-terminal,
    Volta-compatible workflow.

How it works

package lookup → publish only when absent → configure trusted publisher → verify tags and trust

Review guide

Start with:scripts/bootstrap-npm-package.md

Then review:

  1. The distinction between an absent package, the expected bootstrap version,
    and an unexpected existing package.
  2. The recovery path: an existing bootstrap version skips publication but still
    configures trusted publishing.
  3. scripts/tests/bootstrap-npm-package.test.ts, which drives each state with
    a fake npm command.
  4. The concise release-process contract.

Look carefully at:

  • The script never overwrites an existing version or assigns latest.

What must stay true

  • Only 0.0.0-bootstrap.0 under the bootstrap dist-tag is resumable — the
    script validates both before skipping publication.
  • The implementation is not built or published by this script — the first
    tagged release remains responsible for latest.
  • Trusted publishing remains bound to publish-packages.yml, the repository,
    and the npm-publish environment.

How to verify it

  • The focused bootstrap suite proves absent packages publish before trust,
    expected bootstrap packages resume with no second publish, unexpected
    versions fail safely, and a package sitting at 0.0.0-bootstrap.0 under
    some other dist-tag is rejected with the expected-tag diagnostic without
    publishing or configuring trust. Disabling the dist-tag guard fails that
    fourth case alone, so it does not overlap the other three.
  • deno task lint passes.
  • deno task check:jsr passes.
  • The tracked repository type-check passes.

The canonical deno task check and deno task test are blocked locally by an
untracked .claude/worktrees/issue-140-workspace-task-scope checkout that Deno
discovers and type-checks. Its pre-existing errors are outside this diff.

Scope

Included

  • Resumable public-npm bootstrap and trusted-publisher setup.
  • Operator instructions for npm web authentication and Volta.
  • Focused behavior tests and the release-process contract.

Intentionally unchanged

Risks and limitations

Scope confirmation

  • Every changed file supports the purpose described above.
  • Unrelated cleanup and formatting changes are excluded.
  • Generated or mechanical changes are clearly identified.
  • The description matches the final diff and test results.

@github-actions

github-actionsBot commented Jul 26, 2026

Copy link
Copy Markdown

PR #154: Make npm bootstrap resumable

3 files, +334 / -13

Scope

✅ PR scope looks good.

Structural

🟡 1 console statements.

Slop

✅ Slop indicators look low.

Static Analysis

✅ Oxlint found no issues.

Correctness

No extraneous code patterns detected.

@taras

taras commented Aug 3, 2026

Copy link
Copy Markdown
OwnerAuthor

Superseded by #308, which closes #276. That PR rebuilds this document on main around <Elicit>: the OTP is asked for at the point of use, so the npm commands are non-interactive and the awk-the-block-out-of-the-document workaround is gone. The shell guards, the preview/publish split, the empty 0.0.0-bootstrap.0 artifact under the bootstrap dist-tag, the npm trust github invocation, and the verification output all carry over from here.

@tarastaras closed this Aug 3, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@taras