@your-scope/your-package is a boilerplate repository for building and publishing TypeScript libraries to npm.
It includes a strict TypeScript setup, tsdown for bundling, Vitest for unit tests, Biome for linting and formatting, and GitHub Actions workflows for CI and tagged publishes.
The exported functions in src/index.ts are sample code. Replace them with your library API after you clone the template.
The package name in this repository is intentionally a placeholder. This repository is the template, not the final library.
- TypeScript with strict compiler settings
tsdownfor ESM builds and.d.tsgeneration- Vitest for unit tests
- Biome for linting and formatting
- GitHub Actions for CI and npm publish
prepublishOnlychecks to block broken releases
pnpm install
pnpm test
pnpm buildTo turn this repository into a real package, update these fields first:
- package name, description, keywords, repository URLs in
package.json - README package name and usage examples
- LICENSE copyright owner if needed
- sample exports in
src/index.ts - release details in
.changeset/config.jsonif your repository conventions differ
pnpm dev
pnpm lint
pnpm test
pnpm build
pnpm check
pnpm changeset
pnpm version-packages
pnpm releaseThe current sample API demonstrates a few pure utilities that are easy to test and replace.
import { chunk, clamp, uniqueBy } from "@your-scope/your-package";
const bounded = clamp(14, { min: 0, max: 10 });
const groups = chunk([1, 2, 3, 4, 5], 2);
const deduped = uniqueBy(
[
{ id: "a", group: "x" },
{ id: "b", group: "x" },
{ id: "c", group: "y" },
],
(item) => item.group,
);
console.log({ bounded, groups, deduped });This boilerplate uses Changesets for versioning and release PR management.
- Add a release note with
pnpm changeset. - Merge the feature PR into
main. - The
publish.ymlworkflow opens or updates a release PR. - Review and merge the release PR.
- The same
publish.ymlworkflow publishes the package frommain.
Because npm lets you attach a Trusted Publisher only after a package exists, there is still a one-time bootstrap step.
Recommended operation:
- Publish the package once from your local machine.
- Open the package settings on npmjs.com and add a Trusted Publisher.
- Set the GitHub repository and the workflow filename to
publish.yml. - Leave the environment name empty unless you intentionally protect the workflow with a GitHub Environment.
- Verify that the next publish works through GitHub Actions.
- After verification, disallow token-based publishing in npm package settings and revoke old publish tokens.
After bootstrap, later publishes should come from GitHub Actions with OIDC only.
- Trusted publishing works only on GitHub-hosted runners.
- The publish workflow must keep
id-token: write. - For public packages from public repositories, npm generates provenance automatically when trusted publishing is used.
- If CI needs private npm dependencies, use a read-only npm token only for install steps, not for
npm publish.
src/
index.ts
index.test.ts
.github/workflows/
ci.yml
publish.yml
.changeset/
docs/plans/
- The package is ESM-first.
- Build artifacts are emitted to
dist/. - Only
dist/,README.md,CHANGELOG.md, andLICENSEare published.