* fix(release): wait for npm metadata before verifying publish
Direct publish-npm verified immediately after npm accepted 1.22.1,
while registry metadata still lacked dist.tarball. Poll until
integrity exists, then keep the strict pack/gitHead compare. When
the version is already on npm and matches the pack from cli_sha,
skip publish and only complete tag/Release.
* chore(release): prepare v1.22.2
---------
Co-authored-by: Claude <noreply@anthropic.com>
* feat(skills): guide CLI setup, named downloads and updates
* fix(skills): bound npm inventory checks on cold Windows runners
* fix(skills): align launch guide with 10xCards PRD journey
* fix(tests): make helper checks portable on Windows
* test(helpers): trace Windows npm pack startup
* fix(helpers): allow bounded Windows npm startup time
* fix(helpers): use released lesson-scoped skill filters
Correct setup/guide examples and sync ownership to match CLI 1.21.
Exercise the documented preview/write commands through CAC and the
real partial writer, preserving all three trees and the PRD schema.
Refs: https://github.com/przeprogramowani/10x-cli/pull/41
---------
Co-authored-by: Claude <noreply@anthropic.com>
The tag step compared the tag ref's object SHA with the source commit, so an
existing annotated tag at the correct commit failed the run (v1.21.0). Peel
the tag to its commit before comparing, and add an idempotent step that
creates the GitHub Release with the verified npm tarball, which was missing
for 1.21.0 and had to be created by hand.
Co-authored-by: Claude <noreply@anthropic.com>
Dispatch-only workflow that packs, smoke-installs and publishes an exact
source SHA once with the existing NPM_TOKEN, verifies the actual registry
bytes and gitHead afterwards, and tags the source. It carries no Toolkit
receipt, lease or coordinator contract.
Co-authored-by: Claude <noreply@anthropic.com>
* docs(10xdevs4-cli-access): record membership gates and bootstrap context (p1)
Add canonical access plan, accepted decisions and supporting context.
Record phase 1 verification, Toolkit revision and remaining evidence gaps.
* docs(10xdevs4-cli-access): record course access gates and scoped review (p2)
Update canonical Progress, change status, evidence and implementation review.
Record Toolkit revisions, inherited typecheck limitation and phase 3 prerequisites.
* docs(10xdevs4-cli-access): persist reviewed revisions and phase 3 boundary
Record final reviewed Toolkit and CLI context revisions.
Persist Progress attribution and unresolved W04/W05/W08 prerequisites.
Keep phases 3–6, phase 7 and Manual criteria open.
* docs(10xdevs4-cli-access): record squash-safe source prerequisite
Record PR #30, verified gates, permanent-pin lessons and the remaining merge dependency.
Keep phase 3 and all manual rollout criteria pending.
* docs(10xdevs4-cli-access): record source prerequisite review
Record independent review of PR #30 and verified CI evidence.
Keep the master pin and delivery phase completion pending.
* docs(10xdevs4-cli-access): distinguish candidate checks from final master pins
Record passing pre-merge v4 checks and defer workflow suspension.
Keep the final v3 maintenance pin dependent on the resulting master SHA.
* feat: prepare v4 course delivery and protected project sync
Capture the reviewed implementation and manual rehearsal for draft PR review. Master source prerequisites, full clean verification and coordinated Windows CI remain open; production rollout is separate.
* fix: keep paid CI evidence private and converge cumulative sync
* docs: record merged source prerequisite and passing clean gate
* fix: preserve generated API type line endings on Windows
---------
Co-authored-by: Claude <noreply@anthropic.com>
The notify-slack job checked only check, e2e, and publish-npm but
missed version and github-release from its needs list. A failure in
either would show a green notification and skip #alerting.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- .github/workflows/ci.yml: add e2e + e2e-windows jobs with Resend secrets,
extend check-windows with build:binary + smoke tests
- docs/reference/platform-support.md: update CI testing table to match reality
- context/changes/e2e/plan.md: mark phase 5 automated steps complete
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Switch Windows CI job to native PowerShell with Get-ChildItem for test
file enumeration (no glob expansion needed). Add platform-support
reference doc for learners.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
PowerShell does not expand glob patterns — use Git Bash (available on
all GitHub Actions Windows runners) so tests/*.test.ts resolves.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
PowerShell does not expand bare globs — bun test needs ./tests/*.test.ts
to resolve the path on Windows runners.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Move version bump, binary builds, npm publish, and GitHub release from a
separate workflow_run-triggered release.yml into ci.yml gated behind
`github.ref == 'refs/heads/master'`. All jobs now appear in a single
workflow run on the commit in the GitHub UI.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The release workflow silently skipped every release because auto-version.mjs
imported conventional-recommended-bump which was never in devDependencies.
The error handler treated the import crash as "no bump needed." Now the
dependency is installed and the bump step distinguishes expected skip (exit 1)
from real crashes (any other non-zero exit).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Auto-version from conventional commits (auto-version.mjs) with git-diff
gate: only releases when src/ or package.json actually changed
- 5-platform binary builds (linux x64/arm64, macOS x64/arm64, windows)
- npm publish with auth token wiring
- GitHub Release with auto-generated notes and binary attachments
- Smoke tests for package tarball and auto-version script
- Hardened: top-level permissions: {}, env bindings (no expression injection),
persist-credentials only where needed for git push
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Pin GitHub Actions by full SHA to prevent tag-swapping attacks
- Add .npmrc with ignore-scripts and 7-day minimum-release-age quarantine
- Add 30s default request timeout for API calls without caller signal
- Remove unused `open` dependency to reduce attack surface
- Strip OpenAPI source URL from generated types header
- Add SECURITY.md documenting threat model (T1–T8), review history, and
design decisions
- Add persist-credentials: false to checkout action
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>