CI/CD
Prepare#
Copy installer ZIP examples into scripts/vylocore/, or download below. npm omits examples. Set VYLOCORE_PROJECT, masked VYLOCORE_TOKEN and scripts/vylocore/protection.json.
Shell flow#
set -eu
node scripts/vylocore/install-release.mjs
npm ci
npm run build
VYLOCORE_SOURCE_DIR=dist \
VYLOCORE_POLICY_FILE=scripts/vylocore/protection.json \
sh scripts/vylocore/protect-release.sh
Use your build folder instead of dist. Scripts ZIP, upload, scan and protect the same revision. A conflicting scan stops the build. Save protected.zip, scan.json, build.json and report.json.
Provider templates#
Use the GitHub or GitLab examples. Store tokens as secrets, never YAML. Both build first; npm assumes dependencies are installed.
Deploy the protected download through your usual job. Shell examples need a POSIX shell and Node 22.12+.
Download the example files#
Keep these scripts together in scripts/vylocore/:
- Release helper
- CLI installer
- ZIP creator
- Example protection policy
- CLI project defaults
- GitHub Actions workflow
- GitLab CI job
- npm scripts
GitHub: .github/workflows/. GitLab: .gitlab-ci.yml. Adjust variables and configure secrets.