Documentation
- The npm page for
@miraframework/mirashows the full README. It now explains how to connectmira mcpto an MCP client, with the three tools it offers, and how to deploy to each supported host. - Links and images in the npm README point at this release’s tag on GitHub, so the page always matches the version you install.
Security
- npm packages are released with trusted publishing. npm checks each release against the repository’s release workflow through GitHub’s OIDC token, and no npm token is stored anywhere.
- Every version is staged first and goes live only after a maintainer approves it on npmjs.com with two-factor authentication.
- Each package carries a provenance statement that links it to the exact commit and workflow run that built it.
Maintenance
- The release and CI workflows use the current versions of the GitHub actions they depend on, each pinned to a commit SHA.