一键导入
build-and-release
Use when changing tsdown config, Azure Pipelines, publishing flow, or version derivation.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Use when changing tsdown config, Azure Pipelines, publishing flow, or version derivation.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Use when making Safeguard API calls, wiring auth strategies, or following SDK request and response patterns.
Use when wiring certificate-based A2A retrieval, brokering, or related Safeguard event listeners in Node.js.
Use when changing module structure, auth internals, conditional exports, or the HTTP and storage layers.
Use when working on Vitest configuration, appliance-backed tests, fixtures, or debugging test failures.
| name | build-and-release |
| description | Use when changing tsdown config, Azure Pipelines, publishing flow, or version derivation. |
| trigger | Pipeline changes, publishing, versioning, build issues, tsdown config, npm pack |
tsdown (Rolldown/Rust, Vite team) — successor to tsup (deprecated May 2026).
// tsdown.config.ts
import { defineConfig } from 'tsdown';
export default defineConfig([
{
entry: { index: 'src/index.ts' },
format: ['esm', 'cjs'],
dts: true,
sourcemap: true,
clean: true,
target: 'es2022',
outDir: 'dist',
platform: 'neutral',
},
{
entry: { browser: 'src/browser.ts' },
format: ['esm'],
dts: true,
sourcemap: true,
target: 'es2022',
outDir: 'dist',
platform: 'browser',
},
]);
dist/
├── index.js # ESM (Node)
├── index.d.ts # Types (ESM)
├── index.cjs # CJS (Node)
├── index.d.cts # Types (CJS)
├── browser.js # ESM (Browser)
├── browser.d.ts # Types (Browser)
├── events.js # ESM (Events — opt-in subpath)
├── events.d.ts # Types (Events ESM)
├── events.cjs # CJS (Events)
└── events.d.cts # Types (Events CJS)
Note: events.d.ts is patched by scripts/fix-dts.mjs post-build to import SecretValue
from the main entry (avoids #private nominal type incompatibility between bundles).
azure-pipelines.yml # Root entry point
pipeline-templates/
├── global-variables.yml # isTagBuild detection
├── build-steps.yml # npm ci → lint → typecheck → test → audit → build
└── versionnumber.ps1 # Version stamping from git tag
v8.0.0): → PackageVersion = "8.0.0", ReleaseTag = "v8.0.0"PackageVersion = "8.0.0-pre{buildId}", ReleaseTag = "dev/v8.0.0-pre{buildId}"The versionnumber.ps1 script stamps package.json version via npm pkg set version=X.
main → pipeline builds, publishes 8.0.0-pre{N} to npm (pre tag), creates dev GitHub Releasev8.0.0 → pipeline detects tag → npm publish (no tag = latest) → stable GitHub ReleaseAzureKeyVault@2 with azureSubscription: 'SafeguardOpenSource', KeyVaultName: 'SafeguardBuildSecrets', SecretsFilter: 'NpmOrgApiKey'PangaeaBuild-GitHub connection{
"build": "tsdown",
"lint": "eslint src/ tests/",
"lint:fix": "eslint src/ tests/ --fix",
"format": "prettier --write src/ tests/",
"format:check": "prettier --check src/ tests/",
"typecheck": "tsc --noEmit",
"test": "vitest run",
"test:watch": "vitest",
"test:integration": "vitest run --config vitest.integration.config.ts",
"prepublishOnly": "npm run lint && npm run typecheck && npm run test && npm run build"
}
npm run build # Produces dist/
npm pack # Creates tarball
tar -tzf *.tgz # Inspect: should contain dist/, README, LICENSE, package.json only
node -e "const sg = require('./dist/index.cjs'); console.log(Object.keys(sg))" # CJS check
node --input-type=module -e "import('./dist/index.js').then(m => console.log(Object.keys(m)))" # ESM check
| Connection | Purpose | Used By |
|---|---|---|
SafeguardOpenSource | Azure subscription for Key Vault access | AzureKeyVault@2 task |
SafeguardBuildSecrets | Key Vault holding NpmOrgApiKey | AzureKeyVault@2 task |
PangaeaBuild-GitHub | GitHub Releases + repo access | GitHubRelease@1 task, pipeline source |
npm token rotation: The NpmOrgApiKey secret expires every 90 days (npm enforces this for Granular Access Tokens with 2FA bypass). Regenerate on npmjs.com and update the Key Vault secret before expiry.