跳到主要内容
知仓学习社ZHICANG

package-publisher

Publish packages to language-specific registries

不碰外部(只输出文字)无严重或高危命中a5c-ai/babysitter

它会碰到什么

扫了多少2 个文本文件,3 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Package Publisher Skill

Overview

This skill manages SDK package publishing to language-specific registries including npm, PyPI, Maven Central, NuGet, and crates.io with proper signing and verification.

Capabilities

  • Publish to npm, PyPI, Maven Central, NuGet, crates.io
  • Implement package signing and verification
  • Configure CDN distribution for performance
  • Verify installation across environments
  • Support pre-release and stable channels
  • Implement rollback capabilities
  • Configure scoped/namespaced packages
  • Generate installation documentation

Target Processes

  • Package Distribution
  • SDK Versioning and Release Management
  • Multi-Language SDK Strategy

Integration Points

  • npm registry
  • PyPI (Python Package Index)
  • Maven Central
  • NuGet Gallery
  • crates.io
  • GitHub Packages

Input Requirements

  • Target registries
  • Package metadata
  • Signing requirements
  • Distribution channels
  • Verification requirements

Output Artifacts

  • Publishing automation scripts
  • Package signing configuration
  • Registry configurations
  • Verification test scripts
  • Installation documentation
  • Rollback procedures

Usage Example

skill:
  name: package-publisher
  context:
    packages:
      - registry: npm
        scope: "@myorg"
        access: public
      - registry: pypi
        name: mysdk
      - registry: maven
        groupId: com.myorg
        artifactId: mysdk
    signing:
      enabled: true
      gpg: true
    distribution:
      cdn: true
      mirrors: true
    channels:
      - stable
      - beta
      - alpha

Best Practices

  1. Sign all published packages
  2. Use scoped/namespaced packages
  3. Support multiple distribution channels
  4. Verify installation post-publish
  5. Document installation clearly
  6. Implement rollback procedures

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 1,796
本站分层T1
该仓技能数2115
原文件路径library/specializations/sdk-platform-development/skills/package-publisher/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 2115 个技能