Changelog
One file per release: changelog-<version>.md (for example changelog-0.1.1.md),
following the Keep a Changelog format.
How a release is cut
- Bump the version (source of truth: the root
package.json):node tools/version.mjs set 0.2.0 - Write
docs/changelog/changelog-0.2.0.mdwith what was added/changed/fixed. - Verify:
node tools/version.mjs check node tools/gen-apis.mjs --check node tools/check-apis.mjs node tools/license-header.mjs --check - Commit and tag:
git commit -am "chore(release): 0.2.0" git tag v0.2.0 git push origin master --tags - The
release.ymlworkflow builds, publishes to npm and creates the GitHub Release, using this file as the notes.
Sections
### Added · ### Changed · ### Fixed · ### Removed · ### Security
npm and authentication
Today release.yml publishes with the NPM_TOKEN secret (granular with 2FA
bypass) and signs with provenance.
Migrating to Trusted Publishing (OIDC, no token) — recommended, because bypass-2FA tokens lose direct publish around January 2027:
- On npmjs.com → each package → Settings → Trusted Publisher:
- Provider: GitHub Actions
- Repository:
Scrakk/Owear-Framework - Workflow:
release.yml - Environment: (empty)
- Once done, in
release.ymlremove theenv: NODE_AUTH_TOKENfrom the publish step (theid-token: writeis already there) and delete theNPM_TOKENsecret.