Build Stories
Developer ExperienceSFAS

Shipping seven SFAS packages without shipping the repository

How the SFAS release pipeline moved from workspace builds to audited tarballs, checksums, a clean consumer smoke test and a controlled GitHub Packages prerelease.

PackagesReleaseSFASGitHub Packages
01

Constraint

The package surface had to be installable without exposing repository internals or raw licensed upstream source. Seven packages also needed one exact version so dependency drift could not hide inside the workspace.

02

Implementation

Each manifest uses an explicit files whitelist. The release dry run builds tarballs, produces a package manifest and SHA-256 checksums, then installs all seven tarballs into a fresh temporary consumer and imports representative runtime surfaces.

03

Outcome

Version 0.2.0-alpha.12 was published to the private GitHub Packages registry with dist-tag next. The first controlled publication and real-registry clean install/import both passed.