package-publishing

v2026.09.24

npm package publishing patterns for modern TypeScript libraries. Use when configuring package.json exports, setting up dual ESM/CJS builds, or publishing to npm. Use for npm-publish, package-json, exports, main, module, types, dual-package, provenance, prepublishOnly.

GitHub
Install command
npx skhub add oakoss/package-publishing
Markdown
SKILL.md

Package Publishing

Overview

Covers modern npm package authoring: package.json configuration with the exports field, dual ESM/CJS builds, TypeScript type declarations, and secure publishing workflows with provenance.

When to use: Configuring package entry points, setting up conditional exports, building dual-format packages, publishing scoped packages, or troubleshooting module resolution.

When NOT to use: Application-level bundling (Vite/webpack app configs), monorepo workspace orchestration (Turborepo/Nx), private registry setup (Verdaccio/Artifactory).

Quick Reference

PatternField / CommandKey Points
Entry pointexports in package.jsonReplaces main/module; encapsulates internals
CJS fallbackmainLegacy consumers without exports support
ESM entrymoduleBundler convention; not used by Node.js
Type declarationstypes condition in exportsMust be listed first in each condition block
Subpath exports"./utils": { ... }Clean public API; blocks deep imports
Conditional exportsimport/require conditionsToggle ESM vs CJS per consumer
Package type"type": "module"Makes .js files ESM; use .cjs for CommonJS
Side effects"sideEffects": falseEnables tree-shaking in bundlers
Peer depspeerDependenciesShared runtime deps (React, Vue, etc.)
Engine constraints"engines": { "node": ">=18" }Document minimum Node.js version
Files allowlist"files": ["dist"]Controls what gets published to npm
Prepublish check"prepublishOnly": "npm run build"Ensure build runs before publish
Dry runnpm pack --dry-runPreview package contents before publishing
Provenance--provenance flag or trusted publishersCryptographic build attestation
Scoped publish--access publicRequired for first publish of scoped packages

Common Mistakes

MistakeCorrect Pattern
Putting types after default in exportstypes must be the first condition in every export block
Missing "./package.json" in exportsInclude "./package.json": "./package.json" for tooling compatibility
Different APIs for import vs requireSame API surface; write ESM source, transpile to CJS
Using main without exports for new packagesUse exports as the primary entry point definition
Forgetting "type": "module" with .js ESM outputSet "type": "module" or use .mjs extension explicitly
Publishing src/ or node_modules/Use "files" allowlist to include only dist/
No prepublishOnly scriptAdd build step to prevent publishing stale artifacts
Using default export for librariesPrefer named exports for consistent cross-tooling behavior
Not testing with npm pack before publishAlways dry-run to verify package contents and size
Omitting peerDependencies for framework pluginsDeclare shared runtime dependencies as peers
Publishing without provenanceEnable provenance for supply-chain transparency
Using .d.ts for CJS when package is "type": "module"Use .d.cts for CJS type declarations, .d.ts or .d.mts for ESM

Delegation

  • Build tooling setup: Use Explore agent to examine tsup/unbuild/rollup configs
  • Type resolution debugging: Use Task agent with "Are the Types Wrong?" (attw)
  • Publish pipeline review: Delegate to code-reviewer agent

References

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

Not specified

Source path

skills/package-publishing

Default branch

main

Latest commit

85e3a39

Tree SHA

a4c9e7b