My npx-runnable CLIs, in one repository. Each directory in packages/ is its
own npm package with its own version, and every one runs with npx or bunx.
| Package | Run with | What it does |
|---|---|---|
| create-nocdn-app | npx create-nocdn-app |
Scaffold Next.js, Vite, TanStack Start, or Hono my preferred way |
| @nocdn/chat-export | npx @nocdn/chat-export |
Search and export a local Codex, OpenCode, or T3 Code chat as text, Markdown, or JSON |
| @nocdn/github-backup | npx @nocdn/github-backup |
Back up a whole GitHub personal profile |
| @nocdn/ingest | npx @nocdn/ingest |
Ingest a local folder or repository into an LLM-friendly digest |
| @nocdn/pastepatch | npx @nocdn/pastepatch |
Code with ChatGPT via clipboard tool plans or a remote MCP server |
| @nocdn/quick-repo | npx @nocdn/quick-repo |
Quickly create a new GitHub repository |
| @nocdn/record | npx @nocdn/record |
Record the Mac screen, system audio, and microphone from the command line |
packages/<name>/ one npm package per directory (npm workspaces)
scripts/smoke.js packs every package and runs it from a clean install
scripts/release-plan.js lists package versions that are not on npm yet
.github/workflows/
checks.yml lint, tests (Node 22 and 24, Linux and macOS), smoke test
publish.yml publishes changed packages with npm trusted publishing
record.yml builds, signs, notarizes and publishes @nocdn/record
templates.yml scaffolds and builds every create-nocdn-app template
Requires Node.js 22.13 or newer. The repository uses npm and a single root
package-lock.json.
npm install # install every workspace
npm run lint # ESLint and Prettier
npm test # every package's tests
npm run smoke # pack, install and run each CLI
npm run check # all of the above
npm run format # fix formatting and lint
npm test --workspace packages/quick-repo # one package
npm start --workspace packages/quick-repo -- --help
npm install some-dep --workspace packages/ingestReleases are driven by version in each package's package.json:
- Bump the version, e.g.
npm version patch --workspace packages/ingest --no-git-tag-version. - Merge or push the change to
main.
On every push to main, publish.yml runs
the checks, then publishes each package whose current version is not on npm
yet. A push without a version bump publishes nothing. Several packages can be
released in one push.
Publishing uses npm trusted publishing: GitHub Actions proves its identity to npm with OIDC, so there is no npm token in this repository, and every release gets a provenance attestation linking it to the commit and workflow run that built it. On npmjs.com each package trusts:
| Package | Repository | Workflow |
|---|---|---|
@nocdn/record |
nocdn/packages |
record.yml |
| every other package | nocdn/packages |
publish.yml |
Renaming either workflow file breaks publishing until the trusted publisher on npmjs.com is updated to match.
@nocdn/record ships a signed and notarized macOS helper, so it is released by
record.yml on a macOS runner instead. It
needs the Apple signing secrets listed in
its README.
npm can only attach a trusted publisher to a package that already exists, so the very first version of a new package is published from your machine. Each command opens an approval page in your browser; an agent can run them for you and you approve in the browser:
node scripts/npm-browser-auth.js login --auth-type=web # if `npm whoami` fails
node scripts/npm-browser-auth.js publish --workspace packages/<name> --access public
node scripts/npm-browser-auth.js trust github @nocdn/<name> \
--repo nocdn/packages --file publish.yml --allow-publish -yAfter that, releases go through publish.yml like every other package. See
AGENTS.md for how packages in this repository are put together.