Maintainer rules for this repository.
- This repository is the canonical source for the published
@y0usaf/pi-jevnpm package. y0usaf/pi-flakevendors a copy ofsrc/and this README as a bundled pi extension. A change here needs a matching change there, or the two drift.
- Runtime dependencies stay at zero. The Jev client is
fetchplus types, so do not add a client library. - Pi-bundled imports (
@earendil-works/pi-ai,@earendil-works/pi-coding-agent,typebox) belong inpeerDependencieswith a"*"range and must not be bundled. - The gate fails open by design. Do not change an error path to block a tool call.
- Shadow mode is the default. Any change that makes enforcement implicit needs justifying in the README.
- A threshold change belongs with a measurement in the
## Calibrationtable, not with a guess.
-
A GitHub release publishes from
.github/workflows/publish.ymlusing trusted publishing (OIDC), so the repo holds no npm token and no OTP is involved. -
One-time setup, npmjs.com, package settings, Trusted Publisher: user
y0usaf, repositorypi-jev, workflowpublish.yml, environment empty. -
A local publish before that is configured needs a token with 2FA bypass enabled:
npm publish --access public --//registry.npmjs.org/:_authToken="$(cat path/to/token)" -
The package name is scoped (
@y0usaf/pi-jev) because the npm token is scoped to@y0usaf. A bare name cannot be published with it.