---
title: "The README on npm, and releases you can verify"
url: "https://mira.omrajguru.site/changelog/v0-1-2/"
description: "The npm page now carries the full README with MCP and deploy guides, and each npm release is verified against its source and approved with 2FA."
date: "2026-10-08"
---

# The README on npm, and releases you can verify

### Documentation

- The npm page for `@miraframework/mira` shows the full README. It now explains how to connect `mira mcp` to an MCP client, with the three tools it offers, and how to deploy to each supported host.
- Links and images in the npm README point at this release's tag on GitHub, so the page always matches the version you install.

### Security

- npm packages are released with trusted publishing. npm checks each release against the repository's release workflow through GitHub's OIDC token, and no npm token is stored anywhere.
- Every version is staged first and goes live only after a maintainer approves it on npmjs.com with two-factor authentication.
- Each package carries a provenance statement that links it to the exact commit and workflow run that built it.

### Maintenance

- The release and CI workflows use the current versions of the GitHub actions they depend on, each pinned to a commit SHA.
