v0.2.2 shipped a tarball with a correct README.md inside and a package
page that still read "This package does not have a README". npmjs.com
does not read the README out of the tarball — it renders the `readme`
field of the manifest, which the publishing client attaches. pnpm does
not attach it.
Captured both clients against a local registry to be sure:
pnpm publish readme absent, workspace:* rewritten to 0.0.0
npm publish readme 18732 bytes, workspace:* left as-is
Neither does both halves, so: pack with pnpm, publish that tarball with
npm. npm takes the non-directory path through #getManifest, which reads
it with fullReadJson and picks the readme up out of the tarball; the
deps are already rewritten by then. Provenance is unaffected — it is
computed from the tarball bytes, not the spec type.
verify-tarball.sh now takes the tarball to inspect, so CI asserts the
exact bytes it publishes rather than a second one packed for the check,
and packs with pnpm when called bare so a local run matches CI.
verify-published-readme.sh is the guard that would have caught this:
it asks the registry, after publishing, whether the page has a README.
The tarball was never the problem, so no amount of looking inside it
would have helped.