fix(ci): pass the tarball to npm publish as an explicit file path - #230
Merged
Merged
Conversation
`npm publish "pkg/pharn-dev-pharn-${VERSION}.tgz"` matched npm's GitHub
`owner/repo` shorthand, so npm tried `git ls-remote
ssh://git@github.com/pkg/...` and the 0.6.0 publish job failed with
`Permission denied (publickey)`. Nothing reached the registry.
Prefix the path with `./` and pin every tarball argument in publish.yml
as an explicit file path in tests/publish-workflow.test.ts, since no PR
check ever executes that workflow.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YGD9yKFvXkXpZd3DdvdZmn
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
The 0.6.0 release run failed in the
publishjob.npm publish "pkg/pharn-dev-pharn-${VERSION}.tgz"has the shape of npm's GitHubowner/reposhorthand, so npm rangit ls-remote ssh://git@github.com/pkg/pharn-dev-pharn-0.6.0.tgz.gitand died onPermission denied (publickey). Nothing reached the registry (npm still lists 0.5.0 as latest)..github/workflows/publish.yml: publish./pkg/pharn-dev-pharn-${VERSION}.tgz(explicit file path), with a comment on why the./is load-bearing.tests/publish-workflow.test.ts: pins that every.tgzpassed tonpm publish/npm installin publish.yml is an explicit file path. publish.yml only runs on a Release, so no PR check ever executes it. The test fails on the old line and passes on the new one..dev/features/publish-tarball-path/PLAN.md: the file list used to set the writes-scope for this change.Type of change
fix— bug fixArea(s) touched
repo tooling (release workflow + its test)
Checklist
Quality gates
format:check,lint,lint:md,typecheck,buildpass locally.npm test: 6 tests inupdate.test.ts/bounded-read.test.tsfail locally, identically on the untouched tree. They rely on permission errors a root-run container can't produce. CI does not run as root, so they should pass there.Notes for the reviewer
After merge, to release 0.6.0 (not burned on npm): delete the
v0.6.0Release and tag, then recreate the Release with tagv0.6.0targetingmain. A re-run of the failed job would use the broken workflow file at the old tag.🤖 Generated with Claude Code
https://claude.ai/code/session_01YGD9yKFvXkXpZd3DdvdZmn
Generated by Claude Code