Skip to content

fix(release): reconcile published npm package name and harden packaging gate - #40

Merged
kalaris-labs merged 1 commit into
mainfrom
fix/reconcile-npm-scope-and-pipeline-gate
Sep 13, 2026
Merged

kalaris-labs merged 1 commit into
mainfrom
fix/reconcile-npm-scope-and-pipeline-gate

Conversation

@kalaris-labs

@kalaris-labs kalaris-labs commented Sep 13, 2026 •

Copy link
Copy Markdown
Member

User description

Overview

This PR addresses release-pipeline defects, reconciles the published npm package name to @security.kalarislabs/skill-doctor across all tracked files, hardens the release packaging gate, and aligns repository documentation with production truth.

Key Changes

  1. Canonical npm Scope Reconciliation:

    • Enumerating grep proves @security.kalarislabs/skill-doctor is the sole scope in tracked files (0 occurrences of stale @kalarislabs/ or @kalarislabsai/ scopes).
    • Reconciled .github/workflows/install-verify.yml, docs/RELEASE.md, docs/PAPER-RECONCILIATION.md, and skills/release-publish/SKILL.md.
  2. CI Name-Drift Protection (ci.yml):

    • Added equality assertions to version-sync ensuring package.json name matches README.md (npx ${NPM_NAME} and npm install -g ${NPM_NAME}).
    • Added automated check failing if any non-canonical @.../skill-doctor scope appears in repository markdown, JSON, or YAML files.
  3. Release Pipeline Hardening (release.yml):

    • Implemented Fix A: Created isolated packaging-dry-run job running on a clean checkout in parallel with build-release, gated on git status --porcelain.
    • Divided dry-runs into Tier 1 hard leaf gates (skill-doctor-neutralize, skill-doctor-rules, skill-doctor-sandbox) and tolerant advisory loop for downstream crates (skill-doctor-core, skill-doctor-mcp, skill-doctor).
    • Narrowed SBOM cleanup glob from destructive rm -f crates/*/*.json to rm -f crates/*/*.cdx.json crates/*/bom.json, followed by clean tree check.
    • Removed obsolete dirty dry-run step from provenance-and-release.
  4. Install & Post-Release Verification Hardening (install-verify.yml):

    • Updated to use @security.kalarislabs/skill-doctor.
    • Added explicit exit status contract assertions: benign fixture (exit 0), command-injection attack fixture (exit 2).
    • Added checklist reminder comment to bump pinned composite action pin on release.
  5. Documentation Alignment (README.md & docs/RELEASE.md):

    • Preserved exact required strings for version-sync (cargo install --path crates/skill-doctor-cli --locked --features mcp, Requires Rust 1.93.0+ (MSRV), uses: KalarisLabs/Skill-Doctor@v0.1.0).
    • Documented SKILL_DOCTOR_SKIP_DOWNLOAD=1 and --features mcp requirement.
    • Added disclaimer note to community-generated DeepWiki badge.
    • Updated "Build from source" test invocation to match CI (SD_L3_REQUIRE_INTERPRETER=1 cargo test --workspace --all-features --locked).
    • Rewrote docs/RELEASE.md packaging architecture explanation and corrected skill-doctor-sandbox tiering.

Verifiable Evidence Table

Item Before After Evidence Unverified?
npm Live Scope 3 historical scopes (@kalarislabs/, @kalarislabsai/, @security.kalarislabs/) 1 canonical live scope: @security.kalarislabs/skill-doctor npm view @security.kalarislabs/skill-doctor version dist-tags -> 0.1.0, latest: 0.1.0 (other scopes 404) No
Repo Scope References 5 @kalarislabs/, 7 @kalarislabsai/, 7 @security.kalarislabs/ 18 @security.kalarislabs/skill-doctor, 0 stale scopes grep -rhoE "@[A-Za-z0-9._-]+/skill-doctor" ... | sort | uniq -c No
CI Scope Assertion Only version checked; name drift undetected Strict equality + check for bad scopes in version-sync Tested failure on mangled README (exit 1), passed when restored (exit 0) No
Release Packaging Gate --allow-dirty used; downstreams skipped Clean checkout job (packaging-dry-run), no --allow-dirty, Tier 1 hard + downstream advisory loop Local run of dry-run loop across all 6 crates and npm pack --dry-run passed with exit code 0 No
Release SBOM Cleanup Destructive rm -f crates/*/*.json rm -f crates/*/*.cdx.json crates/*/bom.json + git status --porcelain check Verified in release.yml No
GitHub Release v0.1.0 Body Auto-generated notes without install commands Updated with canonical install commands, preserving changelog and numbers isDraft=false, isLatest=true, install lines verified No
PR #35 Status & Retractions Merged with inaccurate claims Closed, retraction comment posted (#issuecomment-5651121107), branch deleted git log origin/main..origin/fix/pre-release-audit empty; comment live No
E2E Live Installation Unverified against new packaging Clean usage error on nonexistent path (exit 1), benign scan (exit 0), attack scan (exit 2) Run in isolated temp directory via npx @security.kalarislabs/skill-doctor@0.1.0 No

CodeAnt-AI Description

Align the published npm package name and strengthen release verification

What Changed

  • Replaced outdated npm package references with @security.kalarislabs/skill-doctor across installation checks, release guidance, and documentation
  • Added CI checks that detect npm package name mismatches and stale package scopes before release
  • Added a clean-checkout packaging gate that blocks releases when leaf packages cannot be packaged or when unexpected packaging errors occur
  • Added post-release checks for successful scans of both benign and malicious skills, including the expected failure status for high-severity findings
  • Documented source builds without downloading binaries and clarified that MCP support requires the MCP feature

Impact

✅ Fewer failed npm installations from package name drift
✅ Earlier detection of invalid release packages
✅ Verified malicious-skill detection after release

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

RetriggerConfidence Score: 4/5

Not safe to merge until unexpected missing dependencies cause release verification to fail.

Fix All in CodexFindings

  1. P1 Missing Dependencies Are Ignored ▶
Fix with agent prompt
### Issue 1
.github/workflows/release.yml:147-148
The advisory publish check converts every Cargo failure containing `no matching package` into a warning without confirming that the missing package is an unpublished workspace dependency. A stale or misspelled external dependency produces the same message, so an unpublishable downstream crate can pass verification and fail only during manual publication. Restrict this exception to explicitly expected workspace dependencies and keep all other publish dry-run failures fatal.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

  • The release verification can treat an unpublishable crate as ready when an unrelated external dependency is missing. This must be corrected before merging.

Reviews (1) · Last reviewed commit: "fix(release): reconcile published npm pa..."

@codeant-ai

codeant-ai Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Reviewed your PR 6c497d7 Sep 13, 2026 · 04:33 04:35

@codeant-ai

codeant-ai Bot commented Sep 13, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@hacktron-app

hacktron-app Bot commented Sep 13, 2026

Copy link
Copy Markdown

Hacktron Security Check - Skipped

Reason: Billing required for Code Review seats

Add a payment method and start Code Review seat billing in organization billing settings

Go to: https://app.hacktron.ai/kalarislabs/billing

@codeant-ai codeant-ai Bot added the size:L This PR changes 100-499 lines, ignoring generated files label Sep 13, 2026
@coderabbitai

coderabbitai Bot commented Sep 13, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 47 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: f00a6caa-ad28-47f8-ad31-eb1f1b479eb4

📥 Commits

Reviewing files that changed from the base of the PR and between e18e72d and 6c497d7.

📒 Files selected for processing (7)
  • .github/workflows/ci.yml
  • .github/workflows/install-verify.yml
  • .github/workflows/release.yml
  • README.md
  • docs/PAPER-RECONCILIATION.md
  • docs/RELEASE.md
  • skills/release-publish/SKILL.md

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread .github/workflows/ci.yml
echo "npm package name: $NPM_NAME"
grep -Fq "npx ${NPM_NAME}" README.md || { echo "ERROR: README missing 'npx ${NPM_NAME}'"; exit 1; }
grep -Fq "npm install -g ${NPM_NAME}" README.md || { echo "ERROR: README missing 'npm install -g ${NPM_NAME}'"; exit 1; }
BAD=$(grep -rhoE "@[A-Za-z0-9._-]+/skill-doctor" \

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: The unanchored pattern also matches names such as @security.kalarislabs/skill-doctor-old, then filters that match as canonical, allowing a non-canonical package name through. [logic error]

Assessment: 🟠 Major · 🔁 Occurrence: Sometimes

Use CodeAnt Skill Fix in Cursor Fix in VSCode Claude

Prompt for AI Agent 🤖
This is a comment left during a code review.

**Path:** .github/workflows/ci.yml
**Line:** 86:86
**Comment:**
	*Logic Error: The unanchored pattern also matches names such as `@security.kalarislabs/skill-doctor-old`, then filters that match as canonical, allowing a non-canonical package name through.

Validate the correctness of the flagged issue. If correct, How can I resolve this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask user if the user wants to fix the rest of the comments as well. if said yes, then fetch all the comments validate the correctness and implement a minimal fix
👍 | 👎

Comment thread README.md
```

The npm package is a thin installer that verifies SHA-256 digests against official release checksums and places the prebuilt static binary; there is no Node runtime dependency at scan time. Prebuilt standalone binaries are also downloadable directly from [GitHub Releases](https://github.com/KalarisLabs/Skill-Doctor/releases).
To build the npm package from source without downloading prebuilt binaries, set `SKILL_DOCTOR_SKIP_DOWNLOAD=1`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion: This only skips downloading; it does not build or install a binary, so the npm command fails unless target/release already contains one. [api mismatch]

Assessment: 🟠 Major · 🔁 Occurrence: Sometimes

Use CodeAnt Skill Fix in Cursor Fix in VSCode Claude

Prompt for AI Agent 🤖
This is a comment left during a code review.

**Path:** README.md
**Line:** 39:39
**Comment:**
	*Api Mismatch: This only skips downloading; it does not build or install a binary, so the npm command fails unless `target/release` already contains one.

Validate the correctness of the flagged issue. If correct, How can I resolve this? If you propose a fix, implement it and please make it concise.
Once fix is implemented, also check other comments on the same PR, and ask user if the user wants to fix the rest of the comments as well. if said yes, then fetch all the comments validate the correctness and implement a minimal fix
👍 | 👎

Comment on lines +147 to +148
if echo "$out" | grep -Fq "no matching package"; then
echo "::warning::$c dry-run deferred: workspace dep not yet on crates.io for this version"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Missing Dependencies Are Ignored

The advisory publish check converts every Cargo failure containing no matching package into a warning without confirming that the missing package is an unpublished workspace dependency. A stale or misspelled external dependency produces the same message, so an unpublishable downstream crate can pass verification and fail only during manual publication. Restrict this exception to explicitly expected workspace dependencies and keep all other publish dry-run failures fatal.

Artifacts

Evidence from the check

  • Creates a disposable external-dependency crate, runs a real Cargo dry run, and evaluates the extracted workflow branch; it demonstrates the unsafe classification condition.

Command output from the check

  • Captured real `cargo publish --dry-run` command, working directory, exit code 101, and Cargo diagnostic containing `no matching package`; it proves an external failure has the matched phrase.

Command output from the check

  • Captured execution of the extracted release workflow decision branch using the real Cargo output; it emits the warning and exits 0 without workspace dependency verification, confirming suppression.

View artifacts

T-Rex Ran code and verified through T-Rex

Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/release.yml
Line: 147-148

Comment:
**Missing Dependencies Are Ignored**

The advisory publish check converts every Cargo failure containing `no matching package` into a warning without confirming that the missing package is an unpublished workspace dependency. A stale or misspelled external dependency produces the same message, so an unpublishable downstream crate can pass verification and fail only during manual publication. Restrict this exception to explicitly expected workspace dependencies and keep all other publish dry-run failures fatal.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Codex Fix in Claude Code Fix in Conductor Fix in Cursor

@kalaris-labs
kalaris-labs merged commit d963031 into main Sep 13, 2026
32 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L This PR changes 100-499 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants