import type { Diagnostic } from "../adoption/check.ts"; import type { Registry } from "../packages/package.ts"; export declare const TRUST_NPM_VERSION = "11.15.0"; /** Derives the per-package staged-publish workflow filename from a package * name, so sibling packages in one workspace never collide on one file. */ export declare function stageWorkflowSlug(packageName: string): string; export declare function stageWorkflowFile(packageName: string): string; export interface PackageManagerSelection { name: "bun" | "npm" | "pnpm" | "yarn"; version?: string; } export interface WorkflowInput { packageManager: PackageManagerSelection; scripts: string[]; /** Relative package directory to build/test from, when the workflow lives * at a monorepo root rather than the package root itself. */ packageDir?: string; /** Sibling workspace packages (name -> declared range) that must already * be published on npm before this package's own stage can succeed. */ coreFirst?: Record; /** Package name slug used to scope this package's own release tag * ($tagPrefix-v*), so two workspace siblings never share one trigger. */ tagPrefix?: string; } export interface VersionCommandResult { code: number; stdout: string; stderr: string; } export type VersionCommand = () => Promise; export type TrustStatusCommand = (packageName: string) => Promise; export interface PublishSetupReport { root: string; ok: boolean; wrote: boolean; workflowPath: string; packageName?: string; repository?: string; trustCommand?: string; statusCommand?: string; webUrl?: string; diagnostics: Diagnostic[]; } export interface PublishStatusReport { root: string; ready: boolean; packageName?: string; repository?: string; workflowPath: string; checks: { packageExists: boolean; repository: boolean; workflow: boolean; lockfile: boolean; node: boolean; npm: boolean; trustedPublisher: "verified" | "not-verified" | "unknown"; /** true when every internal (workspace-sibling) dependency this package * declares is already published on npm at a satisfying version. */ coreFirst: boolean; /** Local machine login state (npm whoami) -- informative only, never * blocks ready: CI publishes over OIDC trusted-publisher config, not * local login. Surfaced so an interactive caller knows what to offer. */ loggedIn: boolean; }; diagnostics: Diagnostic[]; nextSteps: string[]; } export declare function renderStageWorkflow(input: WorkflowInput): string; export declare function versionAtLeast(actual: string, minimum: string): boolean; /** Supports the two range shapes this workspace actually uses (exact, ^, ~); * returns undefined rather than guessing for anything broader. */ export declare function satisfiesRange(version: string, range: string): boolean | undefined; export declare function runBounded(command: string[]): Promise; export declare const readNpmVersion: VersionCommand; export declare const readTrustStatus: TrustStatusCommand; export declare const readNpmWhoami: VersionCommand; export interface InteractiveRunResult { ok: boolean; code: number; } export declare function runInherited(command: string[]): Promise; /** Runs the real, interactive `npm login --auth-type=web`. npm's own * process polls for completion and writes ~/.npmrc itself -- no token ever * passes through Packed. Headless by default (`--no-browser`, npm's own * documented config: print the URL, never auto-launch anything); pass * `openBrowserAuto: true` only when a human on their own desktop terminal * explicitly opted in. Only ever invoked after the caller's own explicit * confirmation; never from a non-TTY or scripted context. */ export declare function runNpmLoginWeb(openBrowserAuto?: boolean): Promise; /** Pure command construction, kept separate from the actual spawn so tests * never risk invoking a real browser. */ export declare function browserOpenCommand(url: string): string[]; /** Best-effort browser open for a human-driven web handoff (npm's own * Trusted Publisher configuration UI, not a CLI command Packed constructs * itself). Only ever called when a human explicitly opted in -- the default * interactive path never spawns this, it only prints the URL. Failure is * silent and non-fatal -- the caller always prints the URL too, so a * missing/unknown opener never blocks the human. */ export declare function openBrowser(url: string): Promise; export declare function githubRepository(value: unknown): string | undefined; export declare function npmWebUrl(packageName: string): string; export declare class PublishManager { private readonly registry; private readonly versionCommand; private readonly trustStatusCommand; private readonly whoamiCommand; constructor(registry: Registry, versionCommand?: VersionCommand, trustStatusCommand?: TrustStatusCommand, whoamiCommand?: VersionCommand); setup(projectPath: string, options?: { force?: boolean; }): Promise; status(projectPath: string): Promise; /** Local, informative mirror of the CI-side ordering guard: every internal * (workspace-sibling) dependency must already be published on npm at a * version its declared range accepts. Empty when there are none. */ private coreFirstStatus; private trustedPublisherStatus; } export declare function formatPublishReport(report: PublishSetupReport | PublishStatusReport, json?: boolean): string; //# sourceMappingURL=publish.d.ts.map