Files
SikongJueluo 77ef5483ed ci(publish): add tag-driven npm publish workflow
- add .github/workflows/publish.yml triggered by <npm-name>@<version> tags
- verify tag matches package.json name and version before publishing
- run check and test before publishing with npm provenance
- pin pnpm via packageManager field for pnpm/action-setup
- document the release flow in both READMEs
2026-09-17 17:59:00 +08:00

67 lines
2.3 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# pi-extensions
[English](README.md) | 简体中文
[pi](https://www.npmjs.com/package/@earendil-works/pi-coding-agent) 编码代理的个人扩展集,专注 Bash 权限:放行前拆包、审视、再审。
## 包
| 包 | npm | 说明 |
|---|---|---|
| [pi-permission-ai-judge](packages/pi-permission-ai-judge) | [@sikongjueluo/pi-permission-ai-judge](https://www.npmjs.com/package/@sikongjueluo/pi-permission-ai-judge) | AI 判官。模型对每条待确认的 Bash 命令给出 allow / deny / defer;shadow 只记日志,enforce 代批放行 |
| [pi-permission-inner-cmd](packages/pi-permission-inner-cmd) | [@sikongjueluo/pi-permission-inner-cmd](https://www.npmjs.com/package/@sikongjueluo/pi-permission-inner-cmd) | 解包透明包装命令(`timeout`、`time` 等),按内层命令授权 |
## 安装
按包从 npm 安装:
```bash
pi install npm:@sikongjueluo/pi-permission-ai-judge
pi install npm:@sikongjueluo/pi-permission-inner-cmd
```
或整仓 git 安装(两个扩展经根 `package.json` 的 `pi.extensions` 清单挂载):
```bash
pi install git:github.com/SikongJueluo/pi-extensions
```
两种方式均任意目录生效。前提:
1. 启用 [`@gotgenes/pi-permission-system`](https://github.com/gotgenes/pi-permission-system) ≥ 32
2. 把扩展挂进授权链——顺序即咨询顺序,仅 UI 会话生效:
```jsonc
// ~/.pi/agent/extensions/pi-permission-system/config.json
{ "authorizerChain": ["inner-cmd", "ai-bash-judge"] }
```
ai-judge 的模式、判官模型与防线见其 [README](packages/pi-permission-ai-judge/README.md)。
## 开发
pnpm workspace,TypeScript + vitest。
```bash
pnpm install
pnpm check # tsc --noEmit
pnpm test # vitest run
```
设计决策见 [docs/adr/](docs/adr/)。
## 发版
先改 `packages/<pkg>/package.json` 的版本号并提交,然后打 tag、推送:
```bash
jj tag set @sikongjueluo/pi-permission-ai-judge@0.1.0 -r <rev>
jj git push # 推送 bookmark 和新 tag
```
[发布工作流](.github/workflows/publish.yml)会校验 tag 与 `package.json` 的 name、version 完全一致,跑 check 和 test,通过后带 provenance 发布到 npm。需要在仓库配置 `NPM_TOKEN` secret(对 `@sikongjueluo` scope 有发布权限的 granular token,或经典 automation token)。
## License
GPL-3.0