← ClaudeAtlas

npm-publishlisted

Use when publishing or releasing a new version of an npm/pnpm/yarn/bun package to the registry. Covers package-manager detection, semver bump selection, tagging, pushing, scoped-package access, authentication, and one-time passwords (OTP).
LandonSchropp/agent-toolkit · ★ 1 · AI & Automation · score 62
Install: claude install-skill LandonSchropp/agent-toolkit
## Pre-flight checks Do these BEFORE bumping the version — fail before creating a commit and tag, not after. 1. **Authenticated.** Run `npm whoami`. A `401` means you're not logged in: STOP and resolve it before anything else. `npm login` is interactive (browser-based), so you cannot run it for the user — ask them to (in Claude Code, `! npm login`), then re-check `npm whoami`. Don't bump or commit until this passes. 2. **Clean working tree.** Run `git status`. Commit or stash changes first. 3. **Tests and lint pass.** Run the project's test and lint scripts. NEVER publish a red build. 4. **Right branch, up to date.** Releases normally happen from `main`. ## Package manager Detect from the lockfile (first match wins) and use that row's commands: | Lockfile | Bump | Publish | | ----------------------------- | ----------------------- | -------------- | | `yarn.lock` | `yarn version --<bump>` | `yarn publish` | | `pnpm-lock.yaml` | `pnpm version <bump>` | `pnpm publish` | | `bun.lock` / `bunfig.toml` | `npm version <bump>` | `bun publish` | | `package-lock.json` (or none) | `npm version <bump>` | `npm publish` | Both steps only touch `package.json` and the registry, so `npm version` / `npm publish` are safe fallbacks when a manager's syntax differs (e.g. Yarn Berry publishes with `yarn npm publish`). ## Bump, push, and publish 1. **Bump.** Pick the level — major (breaking), minor (n