Install
shipped 1.0.0npm i -g @xumana/cwp
cwp --version
cwp doctor
You install cwp globally, once per machine, not per project. There is
nothing to add to a project’s package.json, and no site pins a version of
cwp.
Project state lives in two files, both YAML, both maintained by
cwp init and
cwp config set rather than by hand:
cwp.ymlin the repository, committed;~/.config/cwp/config.ymlon your machine, never committed.
Environments and the two-layer config is the page about what goes in which.
Provenance
GitLab CI publishes the package through npm’s trusted publishing: it exchanges a short-lived OIDC token for a publish token, and npm generates a provenance attestation from it. No npm token exists anywhere in this project.
npm view @xumana/cwp
0.2.0 and 0.3.0 went out as @bernsteinkraft/cwp and carry a deprecation
notice pointing here. They stay published: a package somebody may have
installed does not get removed from under them.