Skip to content

Docs: describe npm releases instead of vendored tarballs - #57

Merged
nedtwigg merged 2 commits into
mainfrom
docs-npm-releases
Oct 4, 2026
Merged

nedtwigg merged 2 commits into
mainfrom
docs-npm-releases

Conversation

@nedtwigg

@nedtwigg nedtwigg commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Two docs still described the time before pgstencil was published to npm:

  • SECURITY.md, "Reporting a vulnerability": said pgstencil is "unpublished to npm" and that a fix reaches consumers through "a re-vendored tarball". It now says a fix lands on main and ships in the next npm release, with a link to PACKAGES.md → Releasing. It still says there's no backport branch.
  • PACKAGES.md, end of "Application composition": said trusted publishing and release automation "remain deferred". It now points to Releasing and keeps the local archives as the way to try unreleased changes.
  • PACKAGES.md, "Dependencies": said "re-vendoring" carries a raised dependency floor into each application. It now says the next release does.

SECURITY.md is the spec the security audit runs against. This only changes the reporting paragraph, not any FAIL IF check.

🤖 Generated with Claude Code

nedtwigg and others added 2 commits October 4, 2026 16:03
SECURITY.md said pgstencil is unpublished and fixes reach consumers by
re-vendoring; PACKAGES.md said npm publishing and release automation
were deferred. Both shipped with 0.2.0/0.3.0.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@nedtwigg
nedtwigg merged commit d906a17 into main Oct 4, 2026
1 check passed
@nedtwigg
nedtwigg deleted the docs-npm-releases branch October 4, 2026 23:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant