rlviz
v0.4.0
Published
Inspect agent rollouts locally.
Maintainers
Readme
rlviz
Install the native RLViz CLI through npm:
npm install --global rlviz
rlviz open ./trajectory.ndjsonThe package downloads the matching macOS or Linux release archive, verifies its
published SHA-256 checksum, and installs the native rlviz binary. Normal
viewing is local and makes no outbound network requests.
The source, native archives, and other installation options are at https://github.com/TheSnakeFang/rlviz.
Publishing setup
Tag releases publish through npm trusted publishing (OIDC) with provenance.
The rlviz package is linked to TheSnakeFang/rlviz and the repository
variable NPM_PUBLISH_ENABLED is enabled.
The workflow deliberately does not accept a long-lived NPM_TOKEN. If the
package or trusted publisher ever needs to be recreated:
With
NPM_PUBLISH_ENABLEDstill unset, create the matching GitHub release first (for examplev0.1.0), then claim the package using an npm account with 2FA:cd packages/npm npm login npm publish --access public --provenance=falseThe one-time provenance override is necessary because trusted publishing cannot be attached until the package exists. Subsequent CI publishes always require provenance.
In the package's npm settings, add a GitHub Actions trusted publisher for organization
TheSnakeFang, repositoryrlviz, workflowrelease.yml, and allownpm publish. With npm 11.5.1+, the equivalent authenticated CLI command is:npm trust github rlviz --repo TheSnakeFang/rlviz --file release.yml --allow-publishPrefer "Require two-factor authentication and disallow tokens" under npm publishing access after OIDC is working.
Set the GitHub repository variable
NPM_PUBLISH_ENABLED=true.
The release job derives the npm version from the v* Git tag, tests and
dry-runs the package, then publishes only after the matching native archives
have succeeded. Trusted publishing requires npm 11.5.1+ and a GitHub-hosted
runner; the workflow uses Node 24 and id-token: write.
