Publishing is intentionally manual. GitHub Actions validates release commits
and tags but has no npm credentials and does not run npm publish.
- Start from a clean
maincheckout and runpnpm check. - Run
pnpm release:versionand select independent package versions. - Review the generated changelogs, package versions, lockfile, release commit, and Lerna package tags.
- Run
pnpm pack:check; package verification must pass before building the Pages artifact, because the site must describe the exact package inputs that were validated for release. - Run
pnpm build:pages, then push the release commit and tags and wait for tag validation to pass. CI enforces the same package-before-Pages sequence.
For the repository cutover, the intended releases are:
@constructive-io/ui@0.8.0@constructive-io/data@0.5.0@constructive-io/sheets@0.8.0@constructive-io/command-palette@0.4.0@constructive-io/schema-builder@0.4.0
json-renderer, blocks-schema, blocks-renderer, json-schema-to-blocks,
meta-to-blocks, and flow-to-blocks release independently of that cutover set.
blocks-schema depends on json-renderer, so publish json-renderer first.
They are built with makage and publish from dist (publishConfig.directory),
so their entry points are root-level files and consumers get deep imports
(blocks-schema/compose, json-renderer/compose) without an exports map. pnpm pack:check verifies that
layout in an isolated consumer, including packed dependents resolving the packed
schema.
From the validated tag checkout:
pnpm install --frozen-lockfile
pnpm check
pnpm pack:checkpnpm pack:check builds every package and installs the tarballs into clean
consumers, including an isolated Sheets consumer that checks its runtime icon
dependencies and Tailwind v4 stylesheet export. Before publishing, point a
temporary downstream checkout at the tarballs in .artifacts/npm, install from
scratch, and run its typecheck and production build. Do not commit file: or
link: dependency specifications.
For a downstream lockfile that must keep semver specifications, run
pnpm local:registry after pnpm pack:local, temporarily point the
@constructive-io npm scope at http://127.0.0.1:4873, and regenerate the
lockfile. The read-only server serves these five exact tarballs and proxies other
public packages; remove the temporary registry setting afterward and verify the
lockfile contains no localhost URLs.
Publish the tarballs themselves so npm receives the exact files that passed the local checks:
npm publish .artifacts/npm/constructive-io-ui-0.8.0.tgz --access public
npm publish .artifacts/npm/constructive-io-data-0.5.0.tgz --access public
npm publish .artifacts/npm/constructive-io-sheets-0.8.0.tgz --access public
npm publish .artifacts/npm/constructive-io-command-palette-0.4.0.tgz --access public
npm publish .artifacts/npm/constructive-io-schema-builder-0.4.0.tgz --access publicVerify all five packages with npm view and a clean consumer install. Published
versions are immutable; release corrections as a forward patch.