SikongJueluo 77ef5483ed ci(publish): add tag-driven npm publish workflow
- add .github/workflows/publish.yml triggered by <npm-name>@<version> tags
- verify tag matches package.json name and version before publishing
- run check and test before publishing with npm provenance
- pin pnpm via packageManager field for pnpm/action-setup
- document the release flow in both READMEs
2026-09-17 17:59:00 +08:00
2026-08-08 18:14:37 +08:00

pi-extensions

English | 简体中文

Personal extensions for the pi coding agent, focused on Bash permissions: unwrap, inspect, and re-adjudicate commands before they run.

Packages

Package npm Description
pi-permission-ai-judge @sikongjueluo/pi-permission-ai-judge AI judge — a model rules allow / deny / defer on each pending Bash ask; shadow logs only, enforce auto-approves
pi-permission-inner-cmd @sikongjueluo/pi-permission-inner-cmd Unwraps transparent Bash wrappers (timeout, time, …) and authorizes the inner command

Install

Per package from npm:

pi install npm:@sikongjueluo/pi-permission-ai-judge
pi install npm:@sikongjueluo/pi-permission-inner-cmd

Or the whole repo via git (both extensions mount through the root package.json pi.extensions manifest):

pi install git:github.com/SikongJueluo/pi-extensions

Either way, effective in any directory. Prerequisites:

  1. Enable @gotgenes/pi-permission-system ≥ 32
  2. Add the extensions to the authorizer chain — order is consultation order, UI sessions only:
// ~/.pi/agent/extensions/pi-permission-system/config.json
{ "authorizerChain": ["inner-cmd", "ai-bash-judge"] }

See the ai-judge README for modes, judge model, and guardrails.

Development

pnpm workspace, TypeScript + vitest.

pnpm install
pnpm check   # tsc --noEmit
pnpm test    # vitest run

Design decisions live in docs/adr/.

Release

Bump the version in packages/<pkg>/package.json, commit, then tag and push:

jj tag set @sikongjueluo/pi-permission-ai-judge@0.1.0 -r <rev>
jj git push   # pushes the bookmark and new tags

The publish workflow verifies the tag matches the package.json name and version, runs check and tests, then publishes to npm with provenance. Requires the NPM_TOKEN repository secret (granular token with publish rights on the @sikongjueluo scope, or a classic automation token).

License

GPL-3.0

S
Description
No description provided
Readme GPL-3.0
496 KiB
Languages
TypeScript 97.7%
JavaScript 2.3%