Skip to content

fix(ci): create the pack destination before npm pack in the release workflow - #213

Merged
PrzemekGalarowicz merged 1 commit into
mainfrom
claude/optimistic-heisenberg-8rw8ke
Sep 24, 2026
Merged

PrzemekGalarowicz merged 1 commit into
mainfrom
claude/optimistic-heisenberg-8rw8ke

Conversation

@PrzemekGalarowicz

Copy link
Copy Markdown
Contributor

What this changes

publish.yml's build job ran npm pack --pack-destination "$RUNNER_TEMP/pkg" without creating pkg/. npm does not create the destination directory: this fails with ENOENT on npm 10.9.7 and 11.20.0 (reproduced locally). So every Release run would have failed at Pack, and the publish job would never have run.

The bug came in with the build/publish split (#201). PR CI never caught it because publish.yml only runs on a published Release.

  • .github/workflows/publish.yml: the Pack step now runs mkdir -p "$RUNNER_TEMP/pkg" before npm pack.
  • .dev/floor/check-run-pins.test.mjs: new live test. It checks that every npm pack --pack-destination directory in every workflow is either the runner temp root or created by a mkdir -p earlier in the same job. A mkdir in another job runs on a different runner, so it doesn't count. The test also folds together the different spellings of the runner temp dir ($RUNNER_TEMP, ${RUNNER_TEMP}, ${{ runner.temp }}) and ignores quoting. A positive control deletes the mkdir line from the live publish.yml text and checks that the test flags it. floor.yml runs this file on every PR.
  • CHANGELOG.md: [Unreleased] → Fixed.
  • .dev/features/publish-pack-destination/: the pharn-dev-ship artifacts (plan, grill, regression and verify reports, review, ship roll-up).

This is the first of four fixes from the review of the last 18 commits on main. The next three will come as separate PRs.

Type of change

  • feat — new stack option, wizard step, or command capability
  • fix — bug fix
  • docs — docs-only change
  • chore / refactor — tooling or internal restructure, no behavior change

Area(s) touched

repo tooling (release workflow + floor test), CHANGELOG

Checklist

  • Read the existing file(s) before editing; followed the ESM .js-extension import convention.
  • Updated the matching tests (the new pin lives beside PHARN-07's other live publish.yml pins).
  • Updated the relevant docs: no docs/ change needed. docs/RELEASING.md already describes the pack → smoke → upload flow this change makes work.
  • Security invariants untouched: no remote-input handling changed.

Quality gates

  • npm run check passes locally (format:check + lint + typecheck + test).
  • npm run build succeeds.
  • npm run test:coverage passes (coverage thresholds met).

Floor workflow tests: 754/754 passed. validate.mjs: GREEN. Pharn-dev verdicts: regress no-regressions, verify PASS, review GREEN (3 minor advisory findings).

The sandbox runs as root, so I ran the gates as root with the permission-override capabilities (CAP_DAC_OVERRIDE, CAP_DAC_READ_SEARCH, CAP_FOWNER) dropped, and with the proxy variables unset. That matches CI. Under plain root, 4 existing chmod-based tests in update.test.ts fail; they fail the same way on main.

Notes for the reviewer

🤖 Generated with Claude Code

https://claude.ai/code/session_0199owRmYfskqYQVQrVP679o


Generated by Claude Code

… workflow

publish.yml's build job ran `npm pack --pack-destination "$RUNNER_TEMP/pkg"`
without creating `pkg/`, and npm does not create the destination (ENOENT on
npm 10.9.7 and 11.20.0). Every Release run would fail at Pack and never reach
the publish job. The defect came in with the build/publish split (#201) and
was invisible to PR CI, because publish.yml only runs on a published Release.

The Pack step now runs `mkdir -p` first. A live test in
check-run-pins.test.mjs pins that every workflow's pack destination is either
the runner temp root or created earlier in the same job, with a positive
control against the live publish.yml.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0199owRmYfskqYQVQrVP679o
@coderabbitai

coderabbitai Bot commented Sep 24, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 33f85f24-81a7-4a63-980c-c4c0d1a73d92


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants