* fix(#623): make release Verify-publish tolerant of npm propagation lag
The rc and latest Verify-publish steps used a single `sleep 10` + one
`npm view`, which false-failed the whole release job when npm's registry
read lagged the publish write — observed on the v1.3.0-rc.1 RC run, where
publish/tag/GitHub-release all succeeded but verification reported NOT_FOUND.
Extract the check into scripts/verify-npm-publish.cjs: a testable module
with a bounded retry/poll loop, a frozen REASON enum, and a --json mode
(mirrors verify-reapply-patches.cjs). Both workflow steps now call it.
dist-tag reporting stays informational and never fails the step, matching
prior behavior. Adds tests/verify-npm-publish.test.cjs covering retry,
exhaustion, and dist-tag reporting via injected lookups (no network).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* chore(#623): allowlist verify-npm-publish.test.cjs in the verify cluster
The test-file-count linter groups test files by production-module prefix.
scripts/verify-npm-publish.cjs lives under scripts/ (not a scanned prod
dir), so its test collapses into the existing `verify` module via the
startsWith(prefix + '-') rule — same as scripts/verify-reapply-patches.cjs,
whose tests are already allowlisted under `verify`. Add the new test to that
cluster's allowlisted set to satisfy the identity ratchet.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>