publish-harness
Codex skill that runs the full smoke-test → witness-sign → npm publish pipeline for a generated harness.
What it does
- Builds the harness with
npm run build - Runs
npm testto confirm green tests - Calls
harness signto produce a fresh witness manifest (requiresWITNESS_SIGNING_KEYenv) - Confirms
harness verifyaccepts the freshly signed manifest - Either:
dry_run=true(default): runsnpm publish --dry-runand reports tarball statsdry_run=false: runs the realnpm publish --provenance --access public
Usage from Codex
/publish-harness path=./my-harness
/publish-harness path=./my-harness dry_run=false
Equivalent CLI
cd ./my-harness
npm run build
npm test
harness sign
harness verify
npm publish --provenance --access public
Required env
WITNESS_SIGNING_KEY— 64-hex-char ed25519 seed (fetch from GCP Secret Manager viaharness secrets fetch WITNESS_SIGNING_KEY)NPM_TOKEN— npm registry credential (Codex skill assumes the host has it set, or fetches viaharness secrets fetch NPM_TOKEN)
See also
validate-harness— release-readiness gate (run this FIRST)harness-secrets— manage GCP-stored signing/publishing tokens