Skip to content

fix(ci): SDK publish skips cleanly when the @threatcrush scope is missing - #261

Merged
ralyodio merged 1 commit into
masterfrom
fix/sdk-publish-skip-missing-scope
Sep 26, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix/sdk-publish-skip-missing-scope

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Problem

Every release since v0.13.10 shows a red X: the "Publish SDK to npm" job fails with npm error 404 Scope not found - @threatcrush/sdk. The @threatcrush npm org/scope was never created (the CLI ships as @profullstack/threatcrush), and the SDK is documented as "not on npm yet." The separate CLI publish job succeeds, so releases do reach npm — but the release looks broken.

Fix

The SDK publish step now treats scope-not-found (E404) as a clean skip (with a ::warning:: naming the two ways to actually enable it), while still failing on any real error — auth, version conflict, build. Workflow-only change.

To actually publish the SDK later (separate decision)

  • create the @threatcrush npm org, or
  • rename the package under the working @profullstack scope (touches ~30 files: every module/boilerplate imports @threatcrush/sdk).

🤖 Generated with Claude Code

…sing

The npm-publish workflow gained a "Publish SDK" job that fails E404 "Scope not
found" on every release since v0.13.10, because the @threatcrush npm org/scope was
never created (the CLI ships under @profullstack). That is a not-yet-set-up state,
not a release failure, and the separate CLI publish job is unaffected — but the
red job made every release look broken.

Skip green on scope-not-found (with a warning naming the two ways to actually
enable it: create the org, or rename under @profullstack); still fail on any real
error (auth, version conflict, build).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

16 finding(s)

HIGH/CRITICAL: 1 | MEDIUM: 7 | LOW: 8

Severity Rule Location
HIGH secret-aws-access-key prd/0003-detect-hardcoded-secrets-before-they-are-committed-or-served.md:126
MEDIUM sql-string-concatenation .github/workflows/migrate-dev2.yml:113
MEDIUM js-open-redirect apps/web/src/app/auth/login/page.tsx:67
MEDIUM js-unescaped-html-sink apps/web/src/app/hire/page.tsx:104
MEDIUM js-unescaped-html-sink apps/web/src/app/hire/page.tsx:108
MEDIUM js-open-redirect apps/web/src/components/funding/FundingClient.tsx:97
MEDIUM js-unescaped-html-sink apps/web/src/components/GuideReader.tsx:265
MEDIUM js-uninitialized-buffer packages/scan/src/node-rules.ts:456
LOW secret-generic-credential apps/web/src/app/api/auth/refresh/route.ts:17
LOW secret-generic-credential apps/web/src/app/api/auth/reset-password/route.ts:26
LOW secret-generic-credential apps/web/src/app/api/auth/reset-password/route.ts:27
LOW secret-generic-credential PRD.md:269
LOW tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:121
LOW tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:122
LOW sh-remote-script-execution scripts/smoke-test.sh:72
LOW secret-aws-access-key scripts/smoke-test.sh:150

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit b0a89cf into master Sep 26, 2026
12 checks passed
@ralyodio
ralyodio deleted the fix/sdk-publish-skip-missing-scope branch September 26, 2026 20:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant