maintain-packaging

작성자: nvidia

NeMo Fabric의 Rust 및 Python 종속성, 패키지 메타데이터, 모듈 경로, 네이티브 아티팩트, 잠금 파일, 라이선스 증거 및 릴리스 관련 빌드를 유지 관리합니다…

npx skills add https://github.com/nvidia/nemo-fabric --skill maintain-packaging

Maintain Release And Packaging Surfaces

Companion Guidance

Use karpathy-guidelines alongside this skill for implementation or review work. Keep changes scoped, surface assumptions, and define focused validation before editing.

Use this skill when a change affects how NeMo Fabric is built, packaged, named, or consumed outside the source tree.

Audit Areas

  • Rust Cargo.toml package names and workspace metadata
  • Root development coordination in pyproject.toml
  • Published Python package metadata under sdk/python/ and adapter-contract/python/
  • Native extension naming and placement under sdk/python/nemo-fabric-runtime/src/nemo_fabric
  • Dependency resolution in Cargo.lock and uv.lock
  • TypeScript adapter-contract metadata and dependency resolution in adapter-contract/typescript/package.json and package-lock.json
  • Documentation tooling metadata in docs/package.json and docs/package-lock.json
  • CI workflows, install commands, and example commands
  • npm trusted publishing through .github/workflows/publish_typescript.yml and the protected npmjs environment
  • justfile build, test, clean, and documentation recipes
  • Release tags, registry publication, and release-facing documentation in RELEASING.md

Dependency Selection

Treat every direct dependency as a long-lived API, supply-chain, and licensing commitment.

  • Keep nemo-fabric as a metapackage that unconditionally installs the exact-version nemo-fabric-runtime distribution. Its harness extras delegate to version-matched leaf adapter harness extras. Hermes Agent is the sole exception: its root extra delegates to the bare adapter because Hermes Agent 0.20 and later is not installable from PyPI. Do not add other adapter-only aliases.

  • Keep leaf adapters adapter-only by default. Every leaf provides full, and every package-installable harness provides harness. The Hermes adapter omits harness because users install Hermes Agent separately from source. Provide relay only when the adapter imports the NeMo Relay Python package. For adapters that launch the Relay CLI, both harness and full install the version-matched nemo-relay-cli-bin package and remain equivalent.

  • First prefer the standard library, an existing dependency, or a small local implementation when it keeps the behavior clear and maintainable.

  • When multiple dependencies satisfy the technical requirement, prefer the maintained OSS option with clear SPDX metadata, a smaller transitive graph, and permissive terms such as Apache-2.0, MIT, BSD, or ISC.

  • Inspect the resolved transitive graph, not only the direct package license.

  • Treat UNKNOWN, non-SPDX/custom, proprietary or source-available terms, and copyleft or network-copyleft terms as explicit review points. Do not silently accept or reject them; route them to the dependency approvers with the distribution and linkage context.

  • Record the functional need, viable alternatives considered, why the selected dependency is the narrowest fit, and any unresolved licensing question.

  • Run uv run --no-project python scripts/licensing/license_diff.py --base-ref origin/main after updating manifests and lockfiles, then review added packages and license changes.

  • For adapter-contract/typescript/package-lock.json, inspect the resolved package entries and their license fields. The adapter-contract package must keep an empty production dependency graph; build-only dependencies still require permissive, recorded license evidence.

  • Regenerate the attribution files with the named pre-commit hooks instead of editing generated output:

    uv run pre-commit run --all-files attributions-rust
    uv run pre-commit run --all-files attributions-python
    uv run pre-commit run --all-files attributions-node
    

The license diff is evidence for reviewers. Dependency approvers make compatibility decisions using the distribution and linkage context.

Checklist

  • Package names, import paths, and module names are internally consistent
  • Generated artifacts still land where downstream consumers expect
  • Docs and examples use the current install/import/build commands
  • CI references the same package names as local workflows
  • Public packaging changes are reflected in release-facing docs
  • Workspace, Python, and lockfile versions remain aligned where required
  • The TypeScript adapter-contract package version follows the workspace release version without changing its independent wire contract version
  • The editable maturin build still produces nemo_fabric._native
  • New dependencies are necessary, maintained, and narrower than the viable alternatives
  • Direct and transitive license changes were reviewed from the resolved lockfiles
  • Licensing uncertainties are called out for dependency approver review
  • Changed attribution files are regenerated and included

References

  • pyproject.toml
  • RELEASING.md
  • sdk/python/nemo-fabric/pyproject.toml
  • sdk/python/nemo-fabric-runtime/pyproject.toml
  • adapter-contract/python/pyproject.toml
  • Cargo.toml
  • Cargo.lock
  • uv.lock
  • docs/package.json
  • docs/package-lock.json
  • adapter-contract/typescript/package.json
  • adapter-contract/typescript/package-lock.json
  • .github/workflows/ci_typescript.yml
  • .github/workflows/publish_typescript.yml
  • scripts/ci/publish_typescript_package.py
  • .github/workflows/ci_python.yml
  • .github/workflows/ci_rust.yml
  • .pre-commit-config.yaml
  • scripts/licensing/license_diff.py
  • justfile

nvidia의 다른 스킬

compileiq-debug
nvidia
무언가 잘못되었을 때 사용: Search()가 멈추거나, 모든 평가가 INVALID_SCORE를 반환하거나, 점수가 개선되지 않거나, 모든 설정이 동일한 숫자를 반환하거나, ptxas 오류 등이 발생할 때
create-github-pr
nvidia
gh CLI를 사용하여 GitHub 풀 리퀘스트를 생성합니다. 사용자가 새 PR을 만들거나, 코드 리뷰를 제출하거나, 풀 리퀘스트를 열고자 할 때 사용합니다. 트리거 키워드 -…
nemoclaw-maintainer-cross-issue-sweep
nvidia
다른 열린 이슈들을 스캔하여 주어진 PR이 함께 수정하거나 실수로 망가뜨릴 수 있는 이슈를 찾습니다. 인접 수정 기회와 모순 위험을 file:line…과 함께 출력합니다.
fhir-basics
nvidia
에이전트에게 FHIR R4 API의 작동 방식, 사용 가능한 리소스, 검색 매개변수를 사용한 쿼리 방법, 모든 응답 형식을 올바르게 파싱하는 방법을 가르칩니다…
compileiq-validate-result
nvidia
검색이 완료된 후, 속도 향상을 청구하거나 ACF를 발송하기 전에 사용합니다. dump_results CSV를 로드하고, 상위 K개 후보(단일 목표)를 추출합니다…
changelog-audit
nvidia
릴리스 전에 Warp CHANGELOG.md를 감사합니다: 누락된 항목 복구, 사용자 영향별 정렬, 항목 언어 다듬기, 줄 바꿈, (릴리스 브랜치 모드) 비교 업데이트…
maintain-dynamic-plugins
nvidia
NeMo Relay 동적 플러그인 로더, 매니페스트, Rust 네이티브 SDK, gRPC 워커 프로토콜, Python 워커 SDK, 문서, 테스트 및 릴리스 워크플로 커버리지를 유지 관리합니다.
dgx-diagnose
nvidia
일반적인 DGX Station GB300 문제 진단 — CUDA 충돌, 잘못된 GPU 타겟팅, vLLM/SGLang 컨테이너 버그, MIG 상태 문제, NVLink/Fabric Manager 오류,…