Point npm latest at @rc (local / no CI token)

SkillDev tools

Lets your agent move an npm package's 'latest' tag to its current RC version using your own logged-in npm account.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Point npm latest at @rc (local / no CI token) skill

About this skill

Point npm `latest` at the current `@rc` versions using local interactive npm auth (no GitHub `NPM_TOKEN`). Use when promoting RC to latest after publish, when CI promote_rc_to_latest 403s, when package Publishing access disallows tokens, or when the user asks to retag latest / run point-latest-at-rc

What this skill tells your AI

The instructions your AI receives, as published by yamcodes/arkenv in skills/point-latest-at-rc/SKILL.md and read by ahel’s review.

Maintainer break-glass alternative to the release workflow’s NPM_TOKEN path. The root script pnpm point-latest-at-rc runs scripts/point-latest-at-rc.js --from-rc --local so npm dist-tag uses your logged-in session. Write commands inherit stdin/stdout so npm can prompt for OTP when 2FA is on auth-and-writes (run from a real TTY). Prefer a single OTP for the whole run via --otp <code> or NPM_CONFIG_OTP — otherwise npm prompts once per package (~12 times). Trusted Publishing still covers publish; this skill only covers dist-tag.

Do not remove or disable the CI promote job. Prefer CI promote_rc_to_latest when secrets.NPM_TOKEN works; use this only when CI cannot (or as emergency retag).

Preconditions

  1. Repo root on a branch with .changeset/pre.json → "mode": "pre", "tag": "rc" (same gate as CI).
  2. Packages already published under @rc (e.g. 1.0.0-rc.1).
  3. npm user who can write dist-tags on @arkenv/* and arkenv (npm login if needed).

Steps

# 1. Confirm auth
npm whoami

# 2. Optional dry-run (lists dist-tag commands; still resolves @rc)
pnpm point-latest-at-rc --dry-run

# 3. Retag (no NPM_TOKEN) — preferred: one OTP for all packages
pnpm point-latest-at-rc -- --otp <code-from-authenticator>
# or: NPM_CONFIG_OTP=<code> pnpm point-latest-at-rc

Without --otp / NPM_CONFIG_OTP, run from a real TTY and expect one interactive OTP prompt per package.

Verify

npm view arkenv dist-tags
npm view @arkenv/core dist-tags
npm view @arkenv/agent-plugin dist-tags

Expect latest and rc both at the same 1.0.0-rc.n.

Smoke (after retag)

  • Bare npx arkenv init
  • @arkenv/core + arktype in a fresh Node app
  • One framework example if time allows

Failures

SymptomLikely cause
Soft-skip without --localMissing NPM_TOKEN — use pnpm point-latest-at-rc for this path
Local mode requires npm authNot logged in — npm login
EOTP / no OTP promptNot a TTY (piped/non-interactive) — pass --otp / NPM_CONFIG_OTP, or run from a real terminal
OTP prompt per packageExpected without --otp / NPM_CONFIG_OTP — pass one code for the whole run
E403 on dist-tagUser lacks write on that package
Gate skip (pre.json / not rc)Not in RC pre mode — do not force

Related

  • Docs: docs/RC_CHECKLIST.md §C (CI primary; local break-glass)
  • CI: .github/workflows/release.yml → promote_rc_to_latest (needs NPM_TOKEN; leave in place — primary path)
  • Script help: node scripts/point-latest-at-rc.js --help

Signals

GitHub stars
144
Forks
6
Last commit
Sep 2026
Advanced
Item type
skill
Key
point-latest-at-rc
Source
github.com/yamcodes/arkenv