mirror of
https://github.com/priyanshujain/sanderling.git
synced 2026-10-02 19:17:10 +00:00
Collapsing them left the npm publish steps in a job holding contents: write, because GoReleaser needs it, so npm ci ran its dependency lifecycle scripts with a write-capable GITHUB_TOKEN in reach of the same job as a live NPM_TOKEN. Release (npm) is back on contents: read and Release (cli) keeps contents: write, which is what they each had before. Each validates the tag from its own copy of the pattern rather than waiting on a job that exists only to pass a string. Release (cli) is tags only: there is no CLI to cut on a merge. Claude-Session: https://claude.ai/code/session_01ShuAy8q8ZfPi8KHxwc8JpQ