Skip to content

release: v0.33.1 — activates npm provenance + first .mcpb bundle#322

Merged
raccioly merged 1 commit into
mainfrom
release/v0.33.1
Jul 16, 2026
Merged

release: v0.33.1 — activates npm provenance + first .mcpb bundle#322
raccioly merged 1 commit into
mainfrom
release/v0.33.1

Conversation

@raccioly

Copy link
Copy Markdown
Owner

Summary

Patch release whose whole point is distribution trust (features unchanged from 0.33.0):

  • First publish through the new npm publish --provenance path — the tarball gets a Sigstore attestation (npm Provenance badge; passes unknown-package legitimacy checks).
  • First release with docguard-v0.33.1.mcpb attached — one-click Claude Desktop install via the new build-mcpb job.
  • package.json + server.json → 0.33.1, CHANGELOG dated, skill/extension version markers synced.

Merging triggers release.yml: tag → GitHub Release (extension ZIP + .mcpb) → npm (with provenance) → PyPI.

Test plan

  • 1018/1018 tests at the bumped version; self-guard clean

🤖 Generated with Claude Code

- package.json + server.json → 0.33.1; CHANGELOG dated
- skill/extension version markers synced via docguard fix --write
- first release published with --provenance (Sigstore attestation) and
  with the docguard-v0.33.1.mcpb Claude Desktop extension attached

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@raccioly
raccioly merged commit fe12d13 into main Jul 16, 2026
9 checks passed
@raccioly
raccioly deleted the release/v0.33.1 branch July 16, 2026 18:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant