01 package
Package identity is boring and exact.
package.jsonhas name, version, description, repository, license, and executable bin.- The package is published before registry metadata is published.
- The install command shown in README is the same one reviewers can run.
- Release provenance is visible when your registry and CI support it.