{"_id":"@anizoptera/publish-clean","_rev":"12-34019da1b18a2cf6c035a88612b71b83","name":"@anizoptera/publish-clean","dist-tags":{"latest":"0.10.0"},"versions":{"0.2.0":{"name":"@anizoptera/publish-clean","version":"0.2.0","keywords":["bun","cleanup","monorepo","npm","pack","package","pnpm","publish"],"author":{"name":"Anizoptera"},"license":"Apache-2.0","_id":"@anizoptera/publish-clean@0.2.0","maintainers":[{"name":"art-shen","email":"amal.samally@gmail.com"}],"contributors":[{"name":"Art Shendrik"}],"homepage":"https://github.com/Anizoptera/publish-clean#readme","bugs":{"url":"https://github.com/Anizoptera/publish-clean/issues"},"bin":{"publish-clean":"dist/cli.js"},"dist":{"shasum":"7ab7c28fc04c5a169eb727971bc47a06d7de2f16","tarball":"https://registry.npmjs.org/@anizoptera/publish-clean/-/publish-clean-0.2.0.tgz","fileCount":4,"integrity":"sha512-6ma8GBvN3ZTlKklNDNrwx09gDwNnVlBOg982NSwZszoqQS9CsRpvGLU5ZaepJUn493r1PY4UD7cA39Pu6g2KMg==","signatures":[{"sig":"MEYCIQCUqMMijXZNkYyrrCyxDBDHm7X2ccxgd4cR+qYWF7i9QQIhAIVoNJkDDN0aEkFWFXQ4ncX4Z6iEoSsPlm6q0Z96rDf7","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anizoptera%2fpublish-clean@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":40869},"type":"module","_from":"file:/tmp/publish-clean-rW9awG/npm-pack/anizoptera-publish-clean-0.2.0.tgz","engines":{"node":">=20"},"exports":{"./package.json":"./package.json"},"_npmUser":{"name":"art-shen","email":"amal.samally@gmail.com"},"_resolved":"/tmp/publish-clean-rW9awG/npm-pack/anizoptera-publish-clean-0.2.0.tgz","_integrity":"sha512-6ma8GBvN3ZTlKklNDNrwx09gDwNnVlBOg982NSwZszoqQS9CsRpvGLU5ZaepJUn493r1PY4UD7cA39Pu6g2KMg==","repository":{"url":"git+https://github.com/Anizoptera/publish-clean.git","type":"git"},"_npmVersion":"11.16.0","description":"Publish pnpm workspace packages from a cleaned, validated package tarball.","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/publish-clean_0.2.0_1786386254375_0.9923385244253735","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@anizoptera/publish-clean","version":"0.3.0","keywords":["bun","cleanup","monorepo","npm","pack","package","package.json","pnpm","provenance","publish","supply-chain","workspace"],"author":{"name":"Anizoptera"},"license":"Apache-2.0","_id":"@anizoptera/publish-clean@0.3.0","maintainers":[{"name":"art-shen","email":"amal.samally@gmail.com"}],"contributors":[{"name":"Art Shendrik"}],"homepage":"https://github.com/Anizoptera/publish-clean#readme","bugs":{"url":"https://github.com/Anizoptera/publish-clean/issues"},"bin":{"publish-clean":"dist/cli.js"},"dist":{"shasum":"4a0ef3fe26f7866b488d8f0cf9859ed3c5cd5805","tarball":"https://registry.npmjs.org/@anizoptera/publish-clean/-/publish-clean-0.3.0.tgz","fileCount":4,"integrity":"sha512-04kIAmpt+/lHw0Zl9+cCmqtxoE9AcaBNYdjW2DisK9T2wbIMTRd2u95kwIooWiWNWH2bT/F2byrgWiCYWw5mVg==","signatures":[{"sig":"MEUCIQCWGTCFzQ4/IJ+qfh9m4gOImCYoU37FZxL4kcEgUwbr6wIgblZML+ZtdZ473OI1+d6+rfqMcLnGDuVz8QQnlRDTgko=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anizoptera%2fpublish-clean@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":62807},"type":"module","_from":"file:/tmp/publish-clean-yzfaxT/npm-pack/anizoptera-publish-clean-0.3.0.tgz","engines":{"node":">=20"},"exports":{"./package.json":"./package.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:16d2811a-0bf6-4d15-9058-7ffde9aeddde"}},"_resolved":"/tmp/publish-clean-yzfaxT/npm-pack/anizoptera-publish-clean-0.3.0.tgz","_integrity":"sha512-04kIAmpt+/lHw0Zl9+cCmqtxoE9AcaBNYdjW2DisK9T2wbIMTRd2u95kwIooWiWNWH2bT/F2byrgWiCYWw5mVg==","repository":{"url":"git+https://github.com/Anizoptera/publish-clean.git","type":"git"},"_npmVersion":"11.16.0","description":"Publish npm packages with a consumer-only package.json. Refuses to ship a .env, a private key, or an unresolved workspace dependency.","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/publish-clean_0.3.0_1786437913938_0.14769665857364456","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@anizoptera/publish-clean","version":"0.4.0","keywords":["bun","cleanup","monorepo","npm","pack","package","package.json","pnpm","provenance","publish","supply-chain","workspace"],"author":{"name":"Anizoptera"},"license":"Apache-2.0","_id":"@anizoptera/publish-clean@0.4.0","maintainers":[{"name":"art-shen","email":"amal.samally@gmail.com"}],"contributors":[{"name":"Art Shendrik"}],"homepage":"https://github.com/Anizoptera/publish-clean#readme","bugs":{"url":"https://github.com/Anizoptera/publish-clean/issues"},"bin":{"publish-clean":"dist/cli.js"},"dist":{"shasum":"6c41e6dfa15c00ec23b4a8b0f1ff3fd96104b7e6","tarball":"https://registry.npmjs.org/@anizoptera/publish-clean/-/publish-clean-0.4.0.tgz","fileCount":4,"integrity":"sha512-FYtBcN3H/WZaJWF8wB1+j3uCR7UBQhzUQQgewSPwPKfkELLHgLUPW71VMAxMAt5QxdZldQDgMgPASl5udDmrtg==","signatures":[{"sig":"MEQCIBWXNyafUSmUfxlnMd7Uw4Zs/VTNvrzoQIHyH7xZUmjWAiBWVYN7ZkHyclLLMjZwogx0Tn/t2WOn6bPstD8+2Wi1zA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anizoptera%2fpublish-clean@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":69426},"type":"module","_from":"file:/tmp/publish-clean-bUObS3/publish/anizoptera-publish-clean-0.4.0.tgz","engines":{"node":">=20"},"exports":{"./package.json":"./package.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:16d2811a-0bf6-4d15-9058-7ffde9aeddde"}},"_resolved":"/tmp/publish-clean-bUObS3/publish/anizoptera-publish-clean-0.4.0.tgz","_integrity":"sha512-FYtBcN3H/WZaJWF8wB1+j3uCR7UBQhzUQQgewSPwPKfkELLHgLUPW71VMAxMAt5QxdZldQDgMgPASl5udDmrtg==","repository":{"url":"git+https://github.com/Anizoptera/publish-clean.git","type":"git"},"_npmVersion":"11.12.1","description":"Publish npm packages with a consumer-only package.json. Refuses to ship a .env, a private key, or an unresolved workspace dependency.","directories":{},"sideEffects":false,"_nodeVersion":"24.15.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/publish-clean_0.4.0_1786456036387_0.6802978379743028","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@anizoptera/publish-clean","version":"0.5.0","keywords":["bun","cleanup","monorepo","npm","pack","package","package.json","pnpm","provenance","publish","supply-chain","workspace"],"author":{"name":"Anizoptera"},"license":"Apache-2.0","_id":"@anizoptera/publish-clean@0.5.0","maintainers":[{"name":"art-shen","email":"amal.samally@gmail.com"}],"contributors":[{"name":"Art Shendrik"}],"homepage":"https://github.com/Anizoptera/publish-clean#readme","bugs":{"url":"https://github.com/Anizoptera/publish-clean/issues"},"bin":{"publish-clean":"dist/cli.js"},"dist":{"shasum":"b1266e00bba00c24410b1331f9f02f8f908ee784","tarball":"https://registry.npmjs.org/@anizoptera/publish-clean/-/publish-clean-0.5.0.tgz","fileCount":4,"integrity":"sha512-r07wE8Z3YxjcIJ9sAmuwtD2q34QyyY+yx2523G6WSpCkscii0GeYfu5a10E2HkWF2aHybKDHD6yadUt2YCpCqw==","signatures":[{"sig":"MEUCIDmkSDRqlNjQSaT3AsqUx2ORgT2SY6glV6NllZdTtaPmAiEAinV+xItBZKa9UzbQoejpivoKZ602IwubHEw8SPocmKQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anizoptera%2fpublish-clean@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":70044},"type":"module","_from":"file:/tmp/publish-clean-5P7pjV/publish/anizoptera-publish-clean-0.5.0.tgz","engines":{"node":">=22.14.0"},"exports":{"./package.json":"./package.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:16d2811a-0bf6-4d15-9058-7ffde9aeddde"}},"_resolved":"/tmp/publish-clean-5P7pjV/publish/anizoptera-publish-clean-0.5.0.tgz","_integrity":"sha512-r07wE8Z3YxjcIJ9sAmuwtD2q34QyyY+yx2523G6WSpCkscii0GeYfu5a10E2HkWF2aHybKDHD6yadUt2YCpCqw==","repository":{"url":"git+https://github.com/Anizoptera/publish-clean.git","type":"git"},"_npmVersion":"11.12.1","description":"Pre-publish npm package cleaner that strips common useless noise and crap from package.json; prevents accidental publication of unwanted things and unresolved dependencies. No deps, one JS file.","directories":{},"sideEffects":false,"_nodeVersion":"24.15.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/publish-clean_0.5.0_1786470895507_0.5264762145008197","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@anizoptera/publish-clean","version":"0.6.0","keywords":["bun","cleanup","monorepo","npm","pack","package","package.json","pnpm","provenance","publish","supply-chain","workspace"],"author":{"name":"Anizoptera"},"license":"Apache-2.0","_id":"@anizoptera/publish-clean@0.6.0","maintainers":[{"name":"art-shen","email":"amal.samally@gmail.com"}],"contributors":[{"name":"Art Shendrik"}],"homepage":"https://github.com/Anizoptera/publish-clean#readme","bugs":{"url":"https://github.com/Anizoptera/publish-clean/issues"},"bin":{"publish-clean":"dist/cli.js"},"dist":{"shasum":"481ed57d24856e2b85995505fce1270efb243543","tarball":"https://registry.npmjs.org/@anizoptera/publish-clean/-/publish-clean-0.6.0.tgz","fileCount":4,"integrity":"sha512-lMU0i69ba5Rn5fvf28iOaa6WjNeqHnyVKLgKMkdJCVISIzUhj4Sz+uDV9836ul9eFrOm1eWu7JFmB6k3qPkxPQ==","signatures":[{"sig":"MEQCIEZUC3q1WFLoq5Tv+JiPQfnRbO0kStQHQ1JD4qGV1JOOAiBgc6GHSlvcbTmv8V/TEPpiThUS8J4fj/n33YkpKrpKZw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anizoptera%2fpublish-clean@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":76309},"type":"module","_from":"file:/tmp/publish-clean-WF0GCF/publish/anizoptera-publish-clean-0.6.0.tgz","engines":{"node":">=22.0.0"},"exports":{"./package.json":"./package.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:16d2811a-0bf6-4d15-9058-7ffde9aeddde"}},"_resolved":"/tmp/publish-clean-WF0GCF/publish/anizoptera-publish-clean-0.6.0.tgz","_integrity":"sha512-lMU0i69ba5Rn5fvf28iOaa6WjNeqHnyVKLgKMkdJCVISIzUhj4Sz+uDV9836ul9eFrOm1eWu7JFmB6k3qPkxPQ==","repository":{"url":"git+https://github.com/Anizoptera/publish-clean.git","type":"git"},"_npmVersion":"11.12.1","description":"Pre-publish npm package cleaner that strips common useless noise and crap from package.json; prevents accidental publication of unwanted things and unresolved dependencies. No deps, one JS file.","directories":{},"sideEffects":false,"_nodeVersion":"24.15.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/publish-clean_0.6.0_1786472542826_0.9286601382715156","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@anizoptera/publish-clean","version":"0.7.0","keywords":["bun","cleanup","monorepo","npm","pack","package","package.json","pnpm","provenance","publish","supply-chain","workspace"],"author":{"name":"Anizoptera"},"license":"Apache-2.0","_id":"@anizoptera/publish-clean@0.7.0","maintainers":[{"name":"art-shen","email":"amal.samally@gmail.com"}],"contributors":[{"name":"Art Shendrik"}],"homepage":"https://github.com/Anizoptera/publish-clean#readme","bugs":{"url":"https://github.com/Anizoptera/publish-clean/issues"},"bin":{"publish-clean":"dist/cli.js"},"dist":{"shasum":"1e3e63b8ea6f2e7857d7257a8d989133f37b6e28","tarball":"https://registry.npmjs.org/@anizoptera/publish-clean/-/publish-clean-0.7.0.tgz","fileCount":4,"integrity":"sha512-YQhvFvaq6fA8o4Evfl/Nqx3bUSq391G/3mWNTYZh2DfluqiSMUknXJzuOCSrLAmzqJtI4OxxhcvcVt9R/BWsDA==","signatures":[{"sig":"MEUCIQDmWxE1G5FlHNwFAUemCN61EN4oYX8y7oKghaFeuum+eAIgZ1GEb27fcB+x/cbiF/0pBRYLwUz6Q80Wa+GlXgmu3qU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anizoptera%2fpublish-clean@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":78073},"type":"module","_from":"file:/tmp/publish-clean-sKyJEq/publish/anizoptera-publish-clean-0.7.0.tgz","engines":{"node":">=22.0.0"},"exports":{"./package.json":"./package.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:16d2811a-0bf6-4d15-9058-7ffde9aeddde"}},"_resolved":"/tmp/publish-clean-sKyJEq/publish/anizoptera-publish-clean-0.7.0.tgz","_integrity":"sha512-YQhvFvaq6fA8o4Evfl/Nqx3bUSq391G/3mWNTYZh2DfluqiSMUknXJzuOCSrLAmzqJtI4OxxhcvcVt9R/BWsDA==","repository":{"url":"git+https://github.com/Anizoptera/publish-clean.git","type":"git"},"_npmVersion":"11.12.1","description":"Pre-publish npm package cleaner that strips common useless noise and crap from package.json; prevents accidental publication of unwanted things and unresolved dependencies. No deps, one JS file.","directories":{},"sideEffects":false,"_nodeVersion":"24.15.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/publish-clean_0.7.0_1786474278848_0.011151790909181614","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@anizoptera/publish-clean","version":"0.7.1","keywords":["bun","cleanup","monorepo","npm","pack","package","package.json","pnpm","provenance","publish","supply-chain","workspace"],"author":{"name":"Anizoptera"},"license":"Apache-2.0","_id":"@anizoptera/publish-clean@0.7.1","maintainers":[{"name":"art-shen","email":"amal.samally@gmail.com"}],"contributors":[{"name":"Art Shendrik"}],"homepage":"https://github.com/Anizoptera/publish-clean#readme","bugs":{"url":"https://github.com/Anizoptera/publish-clean/issues"},"bin":{"publish-clean":"dist/cli.js"},"dist":{"shasum":"6e153046e70da682244ce387f7022af048e1d15d","tarball":"https://registry.npmjs.org/@anizoptera/publish-clean/-/publish-clean-0.7.1.tgz","fileCount":4,"integrity":"sha512-/MxyzHQVOOfncgwoC+bNPVRf6M9UZ3cN4A8yJ/W67Mb8yGvwEWQMisQUuqk4xtD/qOReiPpgI4gyl3f9tKUBYA==","signatures":[{"sig":"MEUCIHpOBH7h3gIXKCoMd1Kvv4KfeRnKVdpLdm6WJrTGXUmDAiEAkV8wlmI2hZHnU8x6eM6PPQj12qsTeyuK9PqfuRkI+lk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anizoptera%2fpublish-clean@0.7.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":81616},"type":"module","_from":"file:/tmp/publish-clean-meR7fJ/publish/anizoptera-publish-clean-0.7.1.tgz","engines":{"node":">=22.0.0"},"exports":{"./package.json":"./package.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:16d2811a-0bf6-4d15-9058-7ffde9aeddde"}},"_resolved":"/tmp/publish-clean-meR7fJ/publish/anizoptera-publish-clean-0.7.1.tgz","_integrity":"sha512-/MxyzHQVOOfncgwoC+bNPVRf6M9UZ3cN4A8yJ/W67Mb8yGvwEWQMisQUuqk4xtD/qOReiPpgI4gyl3f9tKUBYA==","repository":{"url":"git+https://github.com/Anizoptera/publish-clean.git","type":"git"},"_npmVersion":"11.12.1","description":"Pre-publish npm package cleaner that strips common useless noise and crap from package.json; prevents accidental publication of unwanted things and unresolved dependencies. No deps, one JS file.","directories":{},"sideEffects":false,"_nodeVersion":"24.15.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/publish-clean_0.7.1_1786476417379_0.22363893791875333","host":"s3://npm-registry-packages-npm-production"}},"0.7.2":{"name":"@anizoptera/publish-clean","version":"0.7.2","keywords":["bun","cleanup","monorepo","npm","pack","package","package.json","pnpm","provenance","publish","supply-chain","workspace"],"author":{"name":"Anizoptera"},"license":"Apache-2.0","_id":"@anizoptera/publish-clean@0.7.2","maintainers":[{"name":"art-shen","email":"amal.samally@gmail.com"}],"contributors":[{"name":"Art Shendrik"}],"homepage":"https://github.com/Anizoptera/publish-clean#readme","bugs":{"url":"https://github.com/Anizoptera/publish-clean/issues"},"bin":{"publish-clean":"dist/cli.js"},"dist":{"shasum":"93ef7f8470f0f44d856ce564f935ea21695cf92c","tarball":"https://registry.npmjs.org/@anizoptera/publish-clean/-/publish-clean-0.7.2.tgz","fileCount":4,"integrity":"sha512-S5ChOp6q1YAZmO16om/0qdmmd4yjq2bA+y61oOiQSwqllexUDKDNm0a8I5bn9OeZzbxTUaB82KY+QWzInhKgZg==","signatures":[{"sig":"MEUCIQCDngXzF0c1UBfUHXqm9TqWfGbLl9s9RXsjWLnpDq/0dAIgTt4Qdq9CrP6tkeMK55dtfEz1XGSqkzF5aRlchsEwIyM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anizoptera%2fpublish-clean@0.7.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":85447},"type":"module","_from":"file:/tmp/publish-clean-FDEzqu/publish/anizoptera-publish-clean-0.7.2.tgz","engines":{"node":">=22.0.0"},"exports":{"./package.json":"./package.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:16d2811a-0bf6-4d15-9058-7ffde9aeddde"}},"_resolved":"/tmp/publish-clean-FDEzqu/publish/anizoptera-publish-clean-0.7.2.tgz","_integrity":"sha512-S5ChOp6q1YAZmO16om/0qdmmd4yjq2bA+y61oOiQSwqllexUDKDNm0a8I5bn9OeZzbxTUaB82KY+QWzInhKgZg==","repository":{"url":"git+https://github.com/Anizoptera/publish-clean.git","type":"git"},"_npmVersion":"11.12.1","description":"Pre-publish npm package cleaner that strips common useless noise and crap from package.json; prevents accidental publication of unwanted things and unresolved dependencies. No deps, one JS file.","directories":{},"sideEffects":false,"_nodeVersion":"24.15.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/publish-clean_0.7.2_1786477006022_0.18576926104486002","host":"s3://npm-registry-packages-npm-production"}},"0.7.3":{"name":"@anizoptera/publish-clean","version":"0.7.3","keywords":["bun","cleanup","monorepo","npm","pack","package","package.json","pnpm","provenance","publish","supply-chain","workspace"],"author":{"name":"Anizoptera"},"license":"Apache-2.0","_id":"@anizoptera/publish-clean@0.7.3","maintainers":[{"name":"art-shen","email":"amal.samally@gmail.com"}],"contributors":[{"name":"Art Shendrik"}],"homepage":"https://github.com/Anizoptera/publish-clean#readme","bugs":{"url":"https://github.com/Anizoptera/publish-clean/issues"},"bin":{"publish-clean":"dist/cli.js"},"dist":{"shasum":"39c25be40e94019a2501dc7bca07c01dbcfc138f","tarball":"https://registry.npmjs.org/@anizoptera/publish-clean/-/publish-clean-0.7.3.tgz","fileCount":4,"integrity":"sha512-1uzbI8Um0A6JaH0ZSfxixjF4HVYeo9LgSyJhgMLC981cD8VPLo7gtOYIAU2GqjjJIsCpzSbR01iuUGAdozncNA==","signatures":[{"sig":"MEUCIQDlBC4Kz8vQjWuEI3qXafW1FpAOdMoeNbMxSot/8yKY8QIgMdC1fzeAax8pHXoYIoRvwN/3epWjLt7mfqYOsk43Ovg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anizoptera%2fpublish-clean@0.7.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":85574},"type":"module","_from":"file:/tmp/publish-clean-NpUanS/publish/anizoptera-publish-clean-0.7.3.tgz","engines":{"node":">=22.0.0"},"exports":{"./package.json":"./package.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:16d2811a-0bf6-4d15-9058-7ffde9aeddde"}},"_resolved":"/tmp/publish-clean-NpUanS/publish/anizoptera-publish-clean-0.7.3.tgz","_integrity":"sha512-1uzbI8Um0A6JaH0ZSfxixjF4HVYeo9LgSyJhgMLC981cD8VPLo7gtOYIAU2GqjjJIsCpzSbR01iuUGAdozncNA==","repository":{"url":"git+https://github.com/Anizoptera/publish-clean.git","type":"git"},"_npmVersion":"11.12.1","description":"Pre-publish npm package cleaner that strips common useless noise and crap from package.json; prevents accidental publication of unwanted things and unresolved dependencies. No deps, one JS file.","directories":{},"sideEffects":false,"_nodeVersion":"24.15.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/publish-clean_0.7.3_1786477850581_0.07020942015471832","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@anizoptera/publish-clean","version":"0.8.0","keywords":["bun","cleanup","monorepo","npm","pack","package","package.json","pnpm","provenance","publish","supply-chain","workspace"],"author":{"name":"Anizoptera"},"license":"Apache-2.0","_id":"@anizoptera/publish-clean@0.8.0","maintainers":[{"name":"art-shen","email":"amal.samally@gmail.com"}],"contributors":[{"name":"Art Shendrik"}],"homepage":"https://github.com/Anizoptera/publish-clean#readme","bugs":{"url":"https://github.com/Anizoptera/publish-clean/issues"},"bin":{"publish-clean":"dist/cli.js"},"dist":{"shasum":"a03077cd73f7e2da0b504c488e1009b793573dea","tarball":"https://registry.npmjs.org/@anizoptera/publish-clean/-/publish-clean-0.8.0.tgz","fileCount":4,"integrity":"sha512-tdU/H2meGZsS3KVh1W09Ng+F26wHOk/EaSTNc9SZ4wa7SB1Irpa0HXC+BDUmyEUtjmpZ9j2eGeMfJUJEFRqKUA==","signatures":[{"sig":"MEYCIQCT8VBSMeVzqHyRF30vapiLWCgG8tgyeWOZ7QxpedrS/wIhAJ2weeH4Q6Erbpx7AD1E+PZTbTtL0ZSK197UzYsW8yUU","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anizoptera%2fpublish-clean@0.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":95010},"type":"module","_from":"file:/tmp/publish-clean-ellMOB/anizoptera-publish-clean-0.8.0.tgz","engines":{"node":">=22.0.0"},"exports":{"./package.json":"./package.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:16d2811a-0bf6-4d15-9058-7ffde9aeddde"}},"_resolved":"/tmp/publish-clean-ellMOB/anizoptera-publish-clean-0.8.0.tgz","_integrity":"sha512-tdU/H2meGZsS3KVh1W09Ng+F26wHOk/EaSTNc9SZ4wa7SB1Irpa0HXC+BDUmyEUtjmpZ9j2eGeMfJUJEFRqKUA==","repository":{"url":"git+https://github.com/Anizoptera/publish-clean.git","type":"git"},"_npmVersion":"11.19.0","description":"Pre-publish npm package cleaner that strips common useless noise and crap from package.json; prevents accidental publication of unwanted things and unresolved dependencies. No deps, one JS file.","directories":{},"sideEffects":false,"_nodeVersion":"24.20.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org","provenance":true,"@anizoptera:registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/publish-clean_0.8.0_1788823489253_0.8224303720221471","host":"s3://npm-registry-packages-npm-production"}},"0.9.1":{"name":"@anizoptera/publish-clean","version":"0.9.1","keywords":["bun","cleanup","monorepo","npm","pack","package","package.json","pnpm","provenance","publish","supply-chain","workspace"],"author":{"name":"Anizoptera"},"license":"Apache-2.0","_id":"@anizoptera/publish-clean@0.9.1","maintainers":[{"name":"art-shen","email":"amal.samally@gmail.com"}],"contributors":[{"name":"Art Shendrik"}],"homepage":"https://github.com/Anizoptera/publish-clean#readme","bugs":{"url":"https://github.com/Anizoptera/publish-clean/issues"},"bin":{"publish-clean":"dist/cli.js"},"dist":{"shasum":"3c35fa5f06a0d618c4f7d69c003d19031c9d5d8b","tarball":"https://registry.npmjs.org/@anizoptera/publish-clean/-/publish-clean-0.9.1.tgz","fileCount":4,"integrity":"sha512-x5sKg8r6zo7I0Z1GmYiJS02hhp+mJtl2U0a+ONSSET11qe/O7/+oViy5PwTMGdxmLte41aEMtimW1AwqxENn/g==","signatures":[{"sig":"MEYCIQCmcRprMktffxWLxQfYDMBoQudZUhwS/g+D9no0MhKRTAIhAM2GtQWCz0op1tbwlrYoPvIAgNvB0PBC71A3EUgbunVz","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anizoptera%2fpublish-clean@0.9.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":92792},"type":"module","_from":"file:/tmp/publish-clean-B4RyhD/anizoptera-publish-clean-0.9.1.tgz","engines":{"node":">=22.0.0"},"exports":{"./package.json":"./package.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:16d2811a-0bf6-4d15-9058-7ffde9aeddde"}},"_resolved":"/tmp/publish-clean-B4RyhD/anizoptera-publish-clean-0.9.1.tgz","_integrity":"sha512-x5sKg8r6zo7I0Z1GmYiJS02hhp+mJtl2U0a+ONSSET11qe/O7/+oViy5PwTMGdxmLte41aEMtimW1AwqxENn/g==","repository":{"url":"git+https://github.com/Anizoptera/publish-clean.git","type":"git"},"_npmVersion":"11.19.0","description":"Pre-publish npm package cleaner that strips common useless noise and crap from package.json; prevents accidental publication of unwanted things and unresolved dependencies. No deps, one JS file.","directories":{},"sideEffects":false,"_nodeVersion":"24.20.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org","provenance":true,"@anizoptera:registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/publish-clean_0.9.1_1788831225801_0.3129944821082127","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"@anizoptera/publish-clean","version":"0.10.0","description":"Cleans and helps to publish npm packages properly with a clean package.json (no unnecessary entries), verified exports, checks for unwanted files, unresolved workspace dependencies and missing entry points.","keywords":["bun","cleanup","exports","monorepo","npm","pack","package","package.json","pnpm","provenance","publish","supply-chain","workspace"],"homepage":"https://github.com/Anizoptera/publish-clean#readme","bugs":{"url":"https://github.com/Anizoptera/publish-clean/issues"},"license":"Apache-2.0","author":{"name":"Anizoptera"},"contributors":[{"name":"Art Shendrik"}],"repository":{"type":"git","url":"git+https://github.com/Anizoptera/publish-clean.git"},"bin":{"publish-clean":"dist/cli.js"},"type":"module","sideEffects":false,"exports":{"./package.json":"./package.json"},"publishConfig":{"access":"public","provenance":true,"registry":"https://registry.npmjs.org","@anizoptera:registry":"https://registry.npmjs.org"},"engines":{"node":">=22.0.0"},"_id":"@anizoptera/publish-clean@0.10.0","_integrity":"sha512-UT2PzaKSoI2J7pfkwZb5JzV3LB2ubO7C7T/fz5gWqw/Us6l2frc6c7dGwPzn7OTLe3t+PkAyXruEOONLJ0cLQw==","_resolved":"/tmp/publish-clean-Wbo9ea/anizoptera-publish-clean-0.10.0.tgz","_from":"file:/tmp/publish-clean-Wbo9ea/anizoptera-publish-clean-0.10.0.tgz","_nodeVersion":"24.21.0","_npmVersion":"11.19.0","dist":{"integrity":"sha512-UT2PzaKSoI2J7pfkwZb5JzV3LB2ubO7C7T/fz5gWqw/Us6l2frc6c7dGwPzn7OTLe3t+PkAyXruEOONLJ0cLQw==","shasum":"c02da622b345b9832bc16841317270732970dee8","tarball":"https://registry.npmjs.org/@anizoptera/publish-clean/-/publish-clean-0.10.0.tgz","fileCount":4,"unpackedSize":113000,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anizoptera%2fpublish-clean@0.10.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDamoi6pq4cvqmFXMCdpDzeDUb9nKTM+LKQrmCgAi/ZrAIhAKH+W8irdeYts4Gk98WCtOAy6YRpPET0UkJchHLcn96s"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:16d2811a-0bf6-4d15-9058-7ffde9aeddde"}},"directories":{},"maintainers":[{"name":"art-shen","email":"amal.samally@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/publish-clean_0.10.0_1789313189279_0.02470355346265163"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-10T18:24:14.182Z","modified":"2026-09-13T15:26:29.757Z","0.2.0":"2026-08-10T18:24:14.501Z","0.3.0":"2026-08-11T08:45:14.079Z","0.4.0":"2026-08-11T13:47:16.517Z","0.5.0":"2026-08-11T17:54:55.656Z","0.6.0":"2026-08-11T18:22:22.955Z","0.7.0":"2026-08-11T18:51:19.011Z","0.7.1":"2026-08-11T19:26:57.519Z","0.7.2":"2026-08-11T19:36:46.165Z","0.7.3":"2026-08-11T19:50:50.734Z","0.8.0":"2026-09-07T23:24:49.377Z","0.9.1":"2026-09-08T01:33:45.935Z","0.10.0":"2026-09-13T15:26:29.427Z"},"bugs":{"url":"https://github.com/Anizoptera/publish-clean/issues"},"author":{"name":"Anizoptera"},"license":"Apache-2.0","homepage":"https://github.com/Anizoptera/publish-clean#readme","keywords":["bun","cleanup","exports","monorepo","npm","pack","package","package.json","pnpm","provenance","publish","supply-chain","workspace"],"repository":{"type":"git","url":"git+https://github.com/Anizoptera/publish-clean.git"},"description":"Cleans and helps to publish npm packages properly with a clean package.json (no unnecessary entries), verified exports, checks for unwanted files, unresolved workspace dependencies and missing entry points.","contributors":[{"name":"Art Shendrik"}],"maintainers":[{"name":"art-shen","email":"amal.samally@gmail.com"}],"readme":"# @anizoptera/publish-clean\n\nCleans and helps to publish npm packages properly with a clean `package.json` (no unnecessary entries),\nverified `exports`, checks for unwanted files, unresolved workspace dependencies and missing entry points.\n\n[![npm version](https://img.shields.io/npm/v/@anizoptera/publish-clean?label=npm)](https://www.npmjs.com/package/@anizoptera/publish-clean)\n[![Signed provenance](https://img.shields.io/badge/provenance-signed-2ea44f?logo=npm&logoColor=white)](https://www.npmjs.com/package/@anizoptera/publish-clean#provenance)\n[![CI](https://github.com/Anizoptera/publish-clean/actions/workflows/check.yml/badge.svg?branch=main)](https://github.com/Anizoptera/publish-clean/actions/workflows/check.yml)\n[![Node >=22](https://img.shields.io/badge/node-%3E%3D22-339933?logo=node.js&logoColor=white)](package.json)\n[![Runtime deps](https://img.shields.io/badge/runtime_deps-0-2ea44f)](package.json)\n[![License](https://img.shields.io/github/license/Anizoptera/publish-clean)](LICENSE)\n\n**TL;DR** — pack once, clean and check *that* tarball, upload *those* bytes. It never repacks, so\nwhat was verified is exactly what the registry stores and what provenance signs.\n\n```text\npnpm pack ──▶ rewrite package.json inside the tarball ──▶ re-read it from disk\n                                                                      │\n                                                                   check it\n                                                                      │\n      exit 1 ◀── unrepaired, and it leaks or breaks a consumer ◀──────┤\n                                                                      │\n      npm publish <that exact file> ◀── repaired, or only reported ◀──┘\n```\n\n```sh\npnpm exec publish-clean verify     # all checks, uploads nothing\npnpm exec publish-clean --dry-run  # checks, prints file list and manifest\npnpm exec publish-clean -- --provenance --access public   # check, then publish\n```\n\n| What you get | How |\n| --- | --- |\n| [Broken packages stop here](#what-it-checks) | Declared entry points that resolve to nothing, `exports` conditions in an order that loses a consumer its target, `require` branches resolving to ESM, names two filesystems read as one file, `bin` without a shebang, `workspace:`/`catalog:` specs left unresolved. |\n| [Credential files can't ship](#a-packed-secret-is-already-leaked) | A packed `.env`, `.npmrc`, `.pem`/`.key`/keystore or SSH key aborts the run. No flag waives it, and it is not stripped for you: a stripped secret has still leaked and still needs rotating. Matched by file name, so a credential hardcoded inside your source is not caught. |\n| [No dead weight](#dead-weight-ships-forever) | `devDependencies`, `files`, `packageManager`, workspace and catalog config, and tool config blocks (`jest`, `eslint`, `prettier`, `turbo`, …) leave the published manifest. So does the whole `scripts` block, unless it holds an install or `prepare` hook consumers actually run. Packed files nothing references are reported. |\n| [Checked bytes = published bytes](#what-this-buys-for-provenance) | The manifest is rewritten inside pnpm's own tarball and that file is uploaded. A pipeline that repacks after checking signs bytes nothing verified. |\n| [Rules measured, not guessed](#rules-are-measured-not-guessed) | Every rule and every tolerance was measured against thousands of installed published packages first. Equality alone on declared paths refused 373 of 5192; a fixed `exports` order refused 97 of 3674. |\n| [Nothing new to trust](#install) | One JavaScript file, zero runtime dependencies. It runs on the path that handles your registry token, so a transitive package would be unaudited code next to a live credential. |\n| [Check without publishing](#checking-every-pull-request) | `verify` gates pull requests and works on `private: true` packages. Exit 1 on failure, findings on stderr. |\n\nIt edits nothing outside the tarball, and fixes only what the packed files settle without guessing.\nOne run lists every defect instead of stopping at the first. What it repaired does not fail the run;\nwhat it could not repair does. Every judgement call has a flag to waive it. A leaked credential\ndoes not.\n\n## Why\n\nPublishing is the one step you cannot take back. npm lets you unpublish within 72 hours only if no\nother package depends on yours. After that you also need fewer than 300 weekly downloads and a\nsingle maintainer. The version number is gone either way:\n[npm's policy](https://docs.npmjs.com/policies/unpublish) is that \"once `package@version` has been\nused, you can never use it again\". You fix a bad release by publishing another one.\n\nThe defects that reach consumers are the ones your own machine cannot show you:\n\n| Defect | Your machine | Consumer installs | Consumer uses it |\n| ------ | ------------ | ----------------- | ---------------- |\n| Two packed names differing only in letter case | fine (case-sensitive disk) | **reports success** | file silently missing |\n| `bin` file with no shebang | fine (you run `node file.js`) | fine | `exec format error` |\n| Package imports itself through a subpath `exports` hides | fine (resolves by path in your repo) | fine | cannot resolve |\n| `./Utils.js` imported as `./utils.js` | fine on macOS | fine | fails on Linux |\n| `types` pointing at JavaScript with no `.d.ts` | fine | fine | every type silently `any` |\n| `require` branch resolving to an ES module | fine (you use `import`) | fine | fails on older Node |\n\nGreen the whole way down. Nothing in the normal chain fails, so the first report comes from a\nstranger, against a version you can no longer replace.\n\n### A packed secret is already leaked\n\nThe worst case is not a broken package. It is a `.env` or an `.npmrc` inside the tarball. By the\ntime anything notices, the key exists outside your machine: it was written into an archive, and if\nthe upload went through, into a registry that hands it to anyone who asks.\n\n`publish-clean` refuses those outright. No flag waives it and `--strict` has nothing to add. It will\nnot strip the file for you either, though that is what most people expect: a stripped secret has\nstill leaked, and a clean-looking artifact is how it goes unrotated. The report says to rotate the\ncredential first, then narrow `files`.\n\n### Dead weight ships forever\n\nThe second cost is invisible to the only person who can fix it. You pay nothing for a bloated\npackage: you build it once. Everyone else pays, on every install, every CI run, every Docker layer.\nThose bytes sit in every `node_modules` that ever resolved your package, and they cannot be taken\nout of a version that is already published.\n\nNothing complains, because nothing is broken. A shipped `__tests__` directory installs fine. A jest\nconfig block in `package.json` parses fine. Both are downloaded forever by people who will never\nuse them.\n\nSo waste here is a defect with a rule id and an exit code, not a matter of taste. The one thing this\ntool will not do is drop a manifest field it does not recognise: breaking a stranger's build costs\nmore than the bytes do.\n\n### Rules are measured, not guessed\n\nA checker that rejects a working package is worse than no checker. Its mistake and a real defect\nlook identical from the outside, and the only way to find out which you have is to publish anyway.\nThat is the step this tool exists to protect.\n\nSo no rule here is written from the spec alone. Each is measured against thousands of installed\npackages first, and every tolerance exists because its absence refused a package that works.\nMatching declared paths to packed names by equality refused 373 of 5192 packages: `vite`, `svelte`,\nevery `@types/*` package, every `@aws-sdk` client. Demanding a fixed order for `exports` conditions\nrefused 97 of 3674. After the tolerances those measurements forced, 14 remain, every one a real\ndefect.\n[`docs/exports.md`](https://github.com/Anizoptera/publish-clean/blob/main/docs/exports.md) carries\nthe measurements and the specimens.\n\nIf it still refuses a package that works, that is a bug here. Report it.\n\n## What it does\n\n`publish-clean` removes `devDependencies`, workspace settings and tool config from the\npublished manifest. Consumer fields and lifecycle helpers stay. Unknown fields are\nreported for review and kept unless you choose to remove them.\n\nIt packs once with pnpm, cleans the manifest inside the tarball, checks that file, then uploads it\nwith npm. Cleaning leaves your source files alone; your pack hooks still run and can change them.\n\nCheck, then publish:\n\n```sh\npnpm exec publish-clean verify\npnpm exec publish-clean -- --access public --tag latest --provenance\n```\n\n`verify` runs every check and publishes nothing. It works on a `private: true` package, so\na package that never goes to a registry can still be checked by the rules it would face.\n\nRequires Node.js 22+ and pnpm, plus npm to publish. The publish command above needs\n[CI provenance setup](#publishing-a-public-package-from-ci).\n\n## Install\n\n| Project | Install                                 | Run                       |\n| ------- | --------------------------------------- | ------------------------- |\n| pnpm    | `pnpm add -D @anizoptera/publish-clean` | `pnpm exec publish-clean` |\n| Bun     | `bun add -d @anizoptera/publish-clean`  | `bunx publish-clean`      |\n| npm     | `npm i -D @anizoptera/publish-clean`    | `npm exec publish-clean`  |\n| Yarn    | `yarn add -D @anizoptera/publish-clean` | `yarn publish-clean`      |\n\nBoth `pnpm` and `npm` must be on `PATH` to publish, including in Bun, npm and Yarn projects\nand CI. `pnpm` alone is enough to check one: `verify` and `--dry-run` stop before the upload,\nso they never start npm. pnpm and npm are separate requirements, not bundled dependencies.\n\nThe CLI is one JavaScript file with no runtime dependencies, and that is deliberate: it sits on the\npublish path and handles registry credentials, so any transitive package would be unaudited code\nnext to a live token.\n\npnpm 12 installs its native binary from its own install script, so install it with build scripts\nallowed. Under Bun, which blocks them by default, list `pnpm` in `trustedDependencies`. Otherwise\npnpm's command stays a placeholder that this tool cannot start. pnpm 11 needs nothing special.\n\nFor trusted publishing, use Node.js 22.14+ and npm 11.5.1+. Provenance requires a public\npackage, a public source repository and a supported CI provider. See\n[npm's requirements](https://docs.npmjs.com/trusted-publishers/).\n\n### Running it under Bun\n\ngzip bytes depend on the runtime and version executing the CLI. To run it under Bun,\npass Bun the **file path**:\n\n```sh\nbun ./node_modules/.bin/publish-clean\n```\n\nThe installed command has a Node shebang. Passing the file directly avoids relying on\nhow a package runner selects an interpreter or changes the child tools' environment.\n\nKeep the runtime and its version fixed when rebuilding a release artifact. Node and\nBun can encode the same archive contents into different gzip bytes, which changes the\nartifact's hash.\n\n## Package managers\n\nThe CLI uses pnpm for workspace resolution and `publishConfig` overrides, and npm to upload the\nchecked tarball. The [packer comparison](https://github.com/Anizoptera/publish-clean/blob/main/docs/why-pnpm-and-npm.md) explains the trade-offs.\n\nStarting through another package manager prints an advisory on stderr. It does not change\nthe packer or stop publication, and there is no option to suppress it.\n\nFor `workspace:` and `catalog:` specs, pnpm needs the installed dependency in the packing\npackage's own `node_modules`. Compatibility depends on your install layout.\n\nBun gives each package its own `node_modules`, so a Bun workspace packs as it stands: no\n`pnpm-workspace.yaml`, no switching package managers. Yarn hoists workspace dependencies\nto the root instead, so pnpm doesn't find them, and Yarn PnP writes no `node_modules` at\nall. Both need a `pnpm-workspace.yaml` and one `pnpm install` before packing works. A Yarn\npackage with no `workspace:` or `catalog:` specs needs neither, because there's nothing to\nresolve.\n\nInstall the workspace before packing. An unresolved workspace dependency stops packing:\n\n```\nERR_PNPM_CANNOT_RESOLVE_WORKSPACE_PROTOCOL\n```\n\nInstall with the layout described above, then retry.\n\n## Pick your setup\n\n### Publishing a public package from CI\n\nConfigure an npm trusted publisher for your repository and workflow filename, with\npermission for direct `npm publish`. In the publish job, grant `id-token: write` so npm\ncan authenticate through GitHub OIDC without an npm token. Run tests in a separate job\nand make the publish job depend on their success.\n\n```yaml\n# Inside the publish job, after its required check jobs have passed:\npermissions:\n  contents: read\n  id-token: write\nsteps:\n  - uses: actions/checkout@v7\n  - uses: pnpm/action-setup@v6\n    # Set packageManager in package.json to select your pnpm version.\n  - uses: actions/setup-node@v7\n    with:\n      node-version: \"24\"\n      registry-url: https://registry.npmjs.org\n  - run: pnpm install --frozen-lockfile\n  - run: pnpm run build\n  - run: pnpm exec publish-clean -- --access public --tag latest --provenance\n```\n\nUse `--tag latest` for stable releases and `--tag next` for prereleases. npm defaults\nto `latest`, so omitting the tag can give ordinary installs a prerelease.\n\nFor a new package name, follow the [first-publish setup](https://github.com/Anizoptera/publish-clean/blob/main/docs/first-publish.md).\n\nTo block direct publication from your source directory, add this hook. Publishing a\ntarball does not run it:\n\n```json\n{\n  \"scripts\": {\n    \"prepublishOnly\": \"node -e \\\"console.error('Publish with publish-clean.'); process.exit(1)\\\"\"\n  }\n}\n```\n\n### Checking every pull request\n\n`verify` needs no registry, no credentials and no npm, so it runs in ordinary PR CI next to your\ntests:\n\n```yaml\n- run: pnpm exec publish-clean verify\n```\n\nA packaging defect then shows up in the change that caused it, instead of on release day with\neveryone waiting. Most of what this tool finds is introduced by an edit to `package.json` or to the\nfile layout, so the PR that made the edit is where the answer is cheapest.\n\n`--strict` is worth considering here even if you do not use it when publishing: a warning that fails\na PR costs a rerun, while the same warning at release costs a version number.\n\n### Keeping your existing release tool\n\nIf your release tool supports a custom upload command, use `publish-clean` there.\nFor a preview check only, add:\n\n```json\n{\n  \"scripts\": {\n    \"prepublishOnly\": \"publish-clean verify\"\n  }\n}\n```\n\nIt checks a pnpm-produced preview and exits without publishing. Your release tool still\ncreates and uploads its own artifact, which may differ: this gate does not validate those\nuploaded bytes or clean their manifest. To publish the checked bytes, configure that tool\nto invoke `publish-clean` for the upload instead.\n\n### Looking at what would be published\n\n```bash\npnpm exec publish-clean --dry-run\n```\n\nPrints the checked file list and cleaned `package.json`. Add `--tarball-out DIR` to keep\nthe tarball; otherwise temporary files are removed.\n\n### Publishing a restricted package\n\n```bash\npublish-clean -- --access restricted --tag latest\n```\n\nOmit provenance for restricted packages. Leave `private: true` unset: it prohibits\npublication, even to a private registry.\n\n### Adding it to a package that already exists\n\nA package published for years will usually report several findings the first time. You do not have\nto clear them all before you can publish again.\n\nRun `verify` first: it shows the whole list and cannot publish anything. Then decide per finding.\nThe judgement calls have opt-outs, one per rule, so you can disagree with one and keep shipping:\n`--allow-suspicious` for development files you ship on purpose, `allowUnreferenced` for files\nnothing imports by design, `--skip-file-check` for a package with no `files` array.\n\nWhat has no opt-out is a leaked credential, a packed `node_modules` or `.git`, and a defect that\nbreaks a consumer. Those are the ones worth stopping for.\n\n### Publishing one package out of a monorepo\n\n```bash\npublish-clean packages/my-lib -- --access public --tag next\n```\n\n## How it works\n\n```mermaid\nflowchart TD\n  A[Your package directory] -->|pnpm pack| B[Tarball, file set chosen by pnpm]\n  B --> C[Rewrite only package.json inside]\n  C --> D[Final tarball]\n  D --> E{Checks, all reading this tarball}\n  E -->|any fails| F[Exit non-zero, publish nothing]\n  E -->|all pass| G[npm publish this same tarball]\n```\n\nExit code is 0 when nothing stopped the run, 1 when something did, and 130 or 143 when a SIGINT or\nSIGTERM cancelled it. A CI job can tell a real failure from a cancelled runner by that alone.\nFindings and the verdict go to stderr; `--dry-run` prints the file list and the cleaned manifest on\nstdout, so you can read one without the other.\n\n`verify` and `--dry-run` validate the artifact, but skip publication preflight.\nNeither proves that registry access, credentials, provenance requirements or repository\nidentity are correct. Pack hooks still run, including any network operations they perform.\n\n## Why it works this way\n\n### Why cleaning happens in the tarball\n\nCleaning stays out of the source tree so an interrupted publish cannot leave your\n`package.json` half-edited. Pack hooks still run in the source directory and may change it.\n\n### Why the tarball is edited instead of packed again\n\nUploading the checked tarball prevents npm from choosing files again.\nCleaning removes `files` from its manifest because installation no longer needs that\npacking instruction. Repacking the cleaned directory could then fall back to ignore rules\nand drop files the first pack included.\n\nOnly `package/package.json` is replaced. Other archive entries retain their bytes,\norder and metadata, including pnpm's owner `0:0`, fixed timestamps and file modes.\nThe reader resolves USTAR, PAX and GNU long-name paths before checking files and rejects\nmalformed or unsupported path metadata. A path too long for a plain tar name is stated by a\nheader in front of the entry it names, so every guard judges the path the archive actually\nextracts to rather than the placeholder in the entry's own header.\n\n`pnpm pack` runs pack hooks, including `prepare` and `prepack`. npm runs no package\nlifecycle scripts when uploading a tarball, so those hooks cannot change the checked\nartifact during upload.\n\n### What this buys for provenance\n\nnpm builds a provenance attestation from the SHA-512 of the file it uploads. A pipeline that checks\none artifact and then repacks signs bytes that nothing verified, and the attestation still looks\nperfectly valid. Uploading the checked file is what makes the signature cover what the checks\nactually passed.\n\n## What it checks\n\nEvery finding prints as `publish-clean [severity] rule-id at where`. The id in brackets below is\nthat id. Search this file for the one in your output.\n\nTwo rules cover the whole output:\n\n- **`[warning]` never stops the run.** Wasted bytes, nothing a consumer can trip over. `--strict`\n  turns these into errors.\n- **`[error]` stops the run, unless the finding says it was repaired.** A repair fixed the\n  published tarball, not your source, so it still prints as an error and you still have something\n  to fix. It does not stop the publish, because the artifact going up is correct. `--strict` never\n  changes that.\n\nA leaked credential or a packed `node_modules`/`.git` always stops the run, and no flag waives it.\nEvery run ends with a verdict line, so a pass is never silent.\n\nPublication stops when:\n\n- the package is marked `private: true`\n- the working tree has uncommitted changes (`--no-git-checks` to allow it). A directory under no\n  version control has no commit to differ from, so it warns and continues instead\n- the package has no non-empty `files` array (`--skip-file-check` to allow it)\n- the tarball contains a recognised test, CI, lockfile or `tsconfig` path\n  (`--allow-suspicious` to allow it) [`suspicious-file`]\n- a filename matches the protected rules for environment files, npm credentials [`secret-file`],\n  or Git internals and `node_modules` [`internal-file`]; these checks cannot be disabled\n- a dependency is still written as `catalog:`, `workspace:`, `link:` or `portal:`, or a local\n  dependency points outside the shipped files [`monorepo-only-spec`]\n- a declared entry point cannot resolve against the shipped files; checks account for\n  extension lookup, conditions and fallbacks. A declared path no consumer can resolve — an object\n  `browser`, `sideEffects`, an internal `#` import, a `*` pattern matching no packed file — reports\n  and continues instead [`declared-path-inert`], and `--strict` refuses it\n- rewriting the manifest changed anything else in the tarball\n- GitHub trusted publishing or provenance is enabled, but the `repository` in your manifest\n  is not the repository the workflow is running in\n- a `require` condition resolves to an ES module [`require-branch-is-esm`]. Node can require one\n  only from 20.19 and 22.12 onward, a consumer can switch that off, and top-level await fails on\n  every version. Point `require` at a CommonJS build, or add a `module-sync` branch\n- a condition sits out of canonical order where reordering it would change what somebody resolves,\n  and a consumer really loses its target: a runtime-specific build shadowed by a generic one. The\n  tool will not guess here, so it reports and stops instead [`exports-condition-order-unsafe`]\n- two packed names differ only in letter case or Unicode form [`packed-name-collision`]. They\n  collapse onto one path on macOS and Windows, which ignore both by default. Two files means one\n  silently overwrites the other and the install still reports success; a file colliding with a\n  directory means the install fails outright. Only a case-sensitive filesystem can produce the\n  pair, which is why the author never sees it\n- a packed name Windows cannot create [`packed-name-unportable`]: a path component named after a\n  DOS device (`aux`, `con`, `nul`, `com1`…, with or without an extension), a character such as `:`\n  or `?`, a trailing dot or space. Declare `\"os\": [\"!win32\"]` if the package genuinely does not run\n  there and this stops applying. A path component over 255 bytes is refused regardless, because no\n  filesystem accepts one\n- a `bin` file has no shebang [`bin-no-shebang`], or its shebang ends in CR\n  [`shebang-carriage-return`]. An installer symlinks the file and the command is executed directly,\n  so without that first line Linux and macOS fail with `exec format error` and npm has no\n  interpreter for its Windows shim. A trailing CR is invisible in an editor and makes the kernel\n  look for an interpreter literally named `node\\r`. A `bin` file holding a NUL byte in its first\n  512 bytes is exempt: it is a compiled binary\n- a shipped file imports another by the wrong letter case [`import-case-mismatch`], so it works on\n  the author's macOS and fails on a consumer's Linux\n- the package imports itself by name through a subpath its `exports` does not expose\n  [`self-import-not-exported`], which resolves for nobody, and looks fine in your own repository,\n  where it resolves by path\n- the tarball holds a file nothing in the package reaches [`unreferenced-file`]: no entry point,\n  no import from a reached file, no script. Declare the ones that are deliberate:\n  `\"publish-clean\": { \"allowUnreferenced\": [\"assets\"] }`, matched as a prefix, so naming a directory\n  covers everything under it. This check only runs when the package has an `exports` field, because\n  that is what makes unlisted paths unimportable. Without it every shipped file is reachable and\n  none is dead.\n\nA malformed registry URL [`registry-not-a-url`], or one carrying a password\n[`registry-credentials`], also stops the run. Treat such a password as compromised: it is in your\n`package.json` and was about to be published inside the tarball's manifest.\n\nFile guards match paths, not file contents. A credential hardcoded inside an otherwise allowed\nsource file is published and nothing here reports it.\n\n## What it repairs\n\nAn `exports` map is order-sensitive: a consumer activates a whole set of conditions at once and\ntakes the first key in that set, so the order you wrote picks the winner. `publish-clean`\nflattens the map into the resolution it produces for every possible consumer, and rewrites it\nonly when the result is provably identical: dropping a `node` branch that repeats `default`\n[`exports-inert-condition`], collapsing `{\"default\": \"./x.js\"}` [`exports-redundant-default`], and\nputting keys that real resolvers require in a fixed order into it [`exports-condition-order`].\nA branch no consumer reaches [`exports-unreachable-branch`], a consumer no branch serves\n[`exports-unresolvable`] and a condition name no known runtime or bundler activates\n[`exports-unknown-condition`] are reported, never guessed at. Every repair is\nreported, lands only in the published manifest, and never touches your source. `--no-heal`, or\n`\"publish-clean\": { \"heal\": false }`, reports without rewriting.\n\n`types` is the one exception, and the only rewrite here that changes what somebody resolves. Only\na type checker activates it, so nothing that runs your package can tell the difference:\n\n- a `types` branch pointing at JavaScript with no declaration file beside it is **removed**\n  [`types-branch-not-declarations`]. It promised an API the package does not carry, and a checker\n  was reading that JavaScript as your declarations and typing everything `any`.\n- declarations hidden behind a key that leads a checker nowhere are **moved to the front**\n  [`types-branch-unreachable`], where every checker looks first.\n\nBoth print as errors — fix your source — and neither stops the publish, because the published\nartifact is correct. Under `--no-heal` neither rewrite is applied, and then both defects stop it.\n\nAnything the archive cannot settle is left exactly as you wrote it: a `types` target the package\ndoes not ship is a missing file and keeps that report, and nothing is moved across a condition this\ntool does not recognise, since a private name may be meant for a consumer configured to take it.\n\nStill reported and left alone: anything inside a fallback array [`exports-fallback-array`], because\nBun resolves those differently from Node and Deno and no rewrite is safe for everyone, and any map\ntoo large to enumerate [`exports-too-complex`]. [`docs/exports.md`](https://github.com/Anizoptera/publish-clean/blob/main/docs/exports.md) has\nthe measured condition sets behind these rules.\n\n## What the cleaned manifest keeps\n\nThe cleaner preserves consumer and registry fields: `name`, `version`, `license`,\n`dependencies`, `peerDependencies` and their meta, `exports`, `main`, `module`, `types`,\n`bin`, `engines`, `os`, `cpu`, `sideEffects` and `publishConfig`, among others.\n\nIt removes `files` after packing; installers extract the tarball without using that field.\n\nIt also removes `devDependencies`, `workspaces`, `pnpm`, `packageManager`, `overrides`,\n`resolutions`, and the config blocks belonging to test runners, linters, formatters,\ncoverage tools, build systems and release tools. When `preinstall`, `install`, `postinstall`,\n`prepare` or `uninstall` exists, the complete scripts block survives: a lifecycle may call\nany helper script. Otherwise the development-only scripts block is removed.\n\nUnknown fields are kept and reported:\n\n```\npublish-clean [warning] unrecognized-field at 1 manifest field\nThese manifest fields are not recognised and are retained as-is:\n  \"someToolConfig\"\nStrip the ones consumers do not read, and acknowledge the ones they do:\n  \"publish-clean\": { \"devFields\": [\"someToolConfig\"] }\n  \"publish-clean\": { \"keepFields\": [\"someToolConfig\"] }\n```\n\nUnknown fields stay because removing an unfamiliar field can break a consumer's build.\nUse `devFields` to remove a field you know is development-only, or `keepFields` to suppress\nits report. `--strict` promotes this warning to an error like any other. Inspect the result\nwith `--dry-run`.\n\n## Options and config\n\n```bash\npublish-clean [options] [package-dir] [-- npm-publish-args]\n```\n\nSet project defaults in `package.json`. A CLI registry overrides the configured registry;\nboolean flags enable their setting. Pass per-release npm options, such as dist-tags, after `--`:\n\n```json\n{\n  \"publish-clean\": {\n    \"registry\": \"https://registry.npmjs.org\",\n    \"skipFileCheck\": false,\n    \"allowSuspicious\": false,\n    \"noGitChecks\": false,\n    \"devFields\": [\"customBuildOnlyField\"],\n    \"keepFields\": [\"contributes\"]\n  }\n}\n```\n\n| Flag                 | `package.json`    | What it does                                                                               |\n| -------------------- | ----------------- | ------------------------------------------------------------------------------------------ |\n| `verify [dir]`       | -                 | Run every check and publish nothing. Works on a `private: true` package. |\n| `--verify-only`      | -                 | The `verify` subcommand, for scripts that can only pass flags. |\n| `--strict`           | -                 | Treat warnings as errors. Never makes an already-applied repair fatal. |\n| `--no-heal`          | `heal: false`     | Report repairable `exports`/`imports` defects without repairing them. |\n| `--dry-run`          | -                 | Validate a preview artifact and print its file list and cleaned `package.json`. |\n| `--guard-only`       | -                 | Deprecated alias for `verify`; fails on a `private: true` package. |\n| `--tarball-out DIR`  | -                 | Copy the final tarball into `DIR` before publishing.                                       |\n| `--registry URL`     | `registry`        | Set `publishConfig.registry` on the cleaned manifest, and publish to it.                   |\n| `--skip-file-check`  | `skipFileCheck`   | Allow a manifest with no `files` array.                                                    |\n| `--allow-suspicious` | `allowSuspicious` | Allow tests, CI config, lockfiles or `tsconfig` in the artifact.                           |\n| `--no-git-checks`    | `noGitChecks`     | Allow publishing from a dirty working tree.                                                |\n| -                    | `devFields`       | Extra manifest fields to strip.                                                            |\n| -                    | `keepFields`      | Fields that belong in the published package, so stop reporting them.                       |\n| -                    | `allowUnreferenced` | Shipped paths nothing imports, on purpose. Matched as a prefix, so a directory name covers everything under it. |\n| -                    | [`validateArtifact`](#validate-the-final-artifact) | Run your checks on the cleaned tarball before copying or publishing it. |\n| `-h`, `--help`       | -                 | Print usage, every flag, and the config keys.                                              |\n| `-v`, `--version`    | -                 | Print the installed version.                                                               |\n\nArguments after `--` accept publication options only; `--help` lists them. Extra package\noperands, workspace selectors, unknown options and values starting with `-` are rejected\nso npm cannot substitute an unchecked package. For a filename starting with `-`, use `./`.\nPass the dist-tag explicitly: `--tag latest` for a normal public release.\n\n`--tarball-out` saves the checked bytes in every mode, before any upload. You can inspect\nthem, attach them to a release or attest them, even if publication fails.\n\n`registry` sets both the general and package-scope destination in the cleaned manifest.\nRegistry URLs must not contain usernames or passwords, including scoped destinations in\n`publishConfig`. Configure npm authentication in npm configuration instead.\n\n`skipFileCheck` waives the manifest's `files` requirement. `allowSuspicious` permits the\nlisted development files. Neither disables the protected filename checks.\n\nUse `noGitChecks` to publish from a checkout whose working tree is dirty. A directory outside any\nGit repository does not need it: there is no commit there for a tree to differ from, so the check\nreports that it was skipped and the run continues.\n\n`devFields` refuses known consumer fields such as `exports`, `bin`, `engines` and dependency\nmaps to prevent accidental removal.\n\nUse `keepFields` for consumer fields the tool does not recognise, such as a VS Code\nextension's `contributes` and `publisher`. It suppresses reports; it does not restore stripped fields.\n\n### Validate the final artifact\n\nUse `validateArtifact` to check what users will install, such as package imports or type declarations. Add the command to your `package.json`:\n\n```json\n{\n  \"publish-clean\": {\n    \"validateArtifact\": [\"node\", \"scripts/check-artifact.mjs\"]\n  }\n}\n```\n\nThis runs `node scripts/check-artifact.mjs /absolute/path/to/package.tgz` from your package directory. Read the tarball path from `process.argv.at(-1)`; configured arguments come before it.\n\nThe command runs once after built-in checks and before publication or a `--tarball-out` copy. It also runs in `verify` and `--dry-run` modes. The config is removed from the published manifest.\n\nThe first item must name an executable on `PATH` or by its path. Use `node` or `bun` to run scripts, including on Windows; `.cmd` shims are not supported. Arguments are passed literally, without a shell: no pipes, redirection or environment assignments. Relative paths start at your package directory.\n\nExit with code 0 to pass or a nonzero code to reject the package. A failed launch, failed check, or changed or deleted tarball stops publication and copying. Output is hidden on success and shown on failure, with a capture limit to bound memory use. Cancellation stops the command and its child processes before removing temporary files.\n\nYour script runs with your permissions. Keep it read-only and wait for its child processes to finish; publish-clean does not sandbox it or protect other project files.\n\nCheck the supplied tarball. Packing again checks different bytes; calling publish-clean from the script runs the same hook again.\n\n## What it does not do\n\nUse your release tool for versions, changelogs, tags and GitHub releases. Configure trusted\npublishing separately. Built-in checks verify declared paths. To test package imports or\ntype declarations, supply a [validation command](#validate-the-final-artifact).\n\nBundled `node_modules` are not allowed. pnpm may first reject `bundleDependencies` with:\n\n```\nAdd \"nodeLinker: hoisted\" to pnpm-workspace.yaml or delete bundleDependencies\n```\n\nA hoisted layout can make pnpm pack them, but the resulting `node_modules` entries still\nfail this tool's file checks. Use another publication path if you need to ship them.\n\n## Related tools\n\n[`clean-publish`](https://github.com/shashkovdanil/clean-publish) cleans a temporary copy\nof the source tree before publishing. `publish-clean` instead cleans a pnpm-produced tarball.\n\nThat preserves pnpm's file selection and workspace resolution, and lets the checks read\nthe same bytes npm uploads.\n\nRelease tools such as [Changesets](https://github.com/changesets/changesets),\n[semantic-release](https://github.com/semantic-release/semantic-release),\n[release-please](https://github.com/googleapis/release-please),\n[release-it](https://github.com/release-it/release-it) and [np](https://github.com/sindresorhus/np)\nhandle release tasks. See [integration](#keeping-your-existing-release-tool) for the\ndifference between a preview check and publishing through this CLI.\n\n[`publint`](https://publint.dev) and\n[`@arethetypeswrong/cli`](https://github.com/arethetypeswrong/arethetypeswrong.github.io)\ncheck package entry points and TypeScript compatibility. Run them alongside this tool. They only\nreport: they do not clean the manifest, repair anything, or publish. They also cover what this tool\ndeliberately leaves out of scope: type resolution and module-format analysis. Neither replaces the\nother, and no check here is skipped on the grounds that publint reports it too.\n\n`npm publish --dry-run` previews npm's publication. It does not clean the manifest or apply\nthis tool's protected filename rules.\n\n[npm trusted publishing](https://docs.npmjs.com/trusted-publishers/) authorises a CI\nworkflow to publish. Provenance links a release to its source and build; it does not\ncheck package contents for you.\n\n[`pkg-pr-new`](https://github.com/stackblitz-labs/pkg.pr.new) publishes preview builds\nper commit without publishing a version to npm.\n\nUnderlying behaviour is defined by [`npm-packlist`](https://github.com/npm/npm-packlist),\n[`npm pack`](https://docs.npmjs.com/cli/v11/commands/npm-pack/),\n[`npm publish`](https://docs.npmjs.com/cli/v11/commands/npm-publish/),\n[`pnpm pack`](https://pnpm.io/cli/pack) and pnpm\n[`publishConfig`](https://pnpm.io/package_json#publishconfig).\n\n## Contributing\n\n```bash\nbun install --frozen-lockfile\nbun run check\n```\n\n[CONTRIBUTING.md](https://github.com/Anizoptera/publish-clean/blob/main/CONTRIBUTING.md) has the rest. Security problems go through private\nreporting, not public issues: see [SECURITY.md](https://github.com/Anizoptera/publish-clean/blob/main/SECURITY.md).\n\n## License\n\nApache-2.0. Copyright 2026 Anizoptera and Art Shendrik.\n","readmeFilename":"README.md"}