deepseek-harness/.github/workflows
imccyu a213befd0f build(release): publish the vendored framework and the native packages publicly
The three release sequences shipped with publishConfig.access: restricted, so
nothing in the @deepseek-ai scope was installable from outside the organization.

A restricted dependency is what actually blocks a public consumer: every harness
package declares the vendored framework as a peerDependency, and
dsh-sandbox-local declares the Landlock entry as a dependency. Those two
sequences therefore go public first — the nine vendor/* packages and the three
native/landlock-run packages — while the dsh family stays restricted until its
own sequence is opened deliberately. No public package requires a restricted one
in this arrangement.

Access is now per sequence, so no publish path can pass --access: one flag
cannot express two levels and would override the manifest that owns the fact.
publish.ts stops passing it, matching the native workflow, and
check-workspace-constraints holds each manifest to its own sequence's level,
which is what stops the scope from drifting one package at a time.

Harness consumers reference the Landlock entry as workspace:^ instead of
workspace:*, so a published harness package accepts the entry's patch and minor
releases. The entry keeps workspace:* for its platform packages, where the
binary must match the entry version exactly.

Two rationales that named a private registry no longer describe the vendored
sequence; they now state the durable reason, which is that the verification must
not depend on the registry already carrying matching versions.
2026-08-13 14:05:48 +08:00
..
build-exe-for-python-sdk.yml fix(ci): require Python runtime release path 2026-08-12 16:30:35 +08:00
ci.yml refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
docs-pages.yml ci: disable session telemetry in all GitHub workflows 2026-07-31 01:34:41 +08:00
e2b-e2e.yml ci(e2b): add manual live sandbox workflow 2026-08-09 00:51:56 +08:00
e2e.yml ci: disable session telemetry in all GitHub workflows 2026-07-31 01:34:41 +08:00
expected-filenames.yml ci: disable session telemetry in all GitHub workflows 2026-07-31 01:34:41 +08:00
issue-lifecycle.yml fix(ci): narrow issue lifecycle review events 2026-08-10 23:35:05 +08:00
issue-policy.yml chore: enable Issue management automation 2026-08-03 19:53:36 +08:00
landlock-run-release.yml fix(release): close the review findings on the release sequences 2026-08-11 01:26:36 +08:00
landlock-run.yml fix(landlock-run): publish under deepseek scope 2026-08-06 14:41:17 +08:00
pi-ai-provider-e2e.yml ci: disable session telemetry in all GitHub workflows 2026-07-31 01:34:41 +08:00
python-release.yml fix: address Python release review feedback 2026-08-11 20:09:33 +08:00
release-vendor.yml fix(release): close the review findings on the release sequences 2026-08-11 01:26:36 +08:00
release.yml build(release): publish the vendored framework and the native packages publicly 2026-08-13 14:05:48 +08:00
sandbox.yml refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00