Skip to content

fix(ci): pass the tarball to npm publish as an explicit file path - #230

Merged
PrzemekGalarowicz merged 1 commit into
mainfrom
claude/charming-allen-t8gbl2
Sep 25, 2026
Merged

PrzemekGalarowicz merged 1 commit into
mainfrom
claude/charming-allen-t8gbl2

Conversation

@PrzemekGalarowicz

Copy link
Copy Markdown
Contributor

What this changes

The 0.6.0 release run failed in the publish job. npm publish "pkg/pharn-dev-pharn-${VERSION}.tgz" has the shape of npm's GitHub owner/repo shorthand, so npm ran git ls-remote ssh://git@github.com/pkg/pharn-dev-pharn-0.6.0.tgz.git and died on Permission denied (publickey). Nothing reached the registry (npm still lists 0.5.0 as latest).

  • .github/workflows/publish.yml: publish ./pkg/pharn-dev-pharn-${VERSION}.tgz (explicit file path), with a comment on why the ./ is load-bearing.
  • tests/publish-workflow.test.ts: pins that every .tgz passed to npm publish / npm install in publish.yml is an explicit file path. publish.yml only runs on a Release, so no PR check ever executes it. The test fails on the old line and passes on the new one.
  • .dev/features/publish-tarball-path/PLAN.md: the file list used to set the writes-scope for this change.

Type of change

  • fix — bug fix

Area(s) touched

repo tooling (release workflow + its test)

Checklist

  • Read the existing file(s) before editing.
  • Added a matching test.
  • Docs: no user-facing behavior change.
  • Security invariants: not touched.

Quality gates

  • format:check, lint, lint:md, typecheck, build pass locally.
  • npm test: 6 tests in update.test.ts / bounded-read.test.ts fail locally, identically on the untouched tree. They rely on permission errors a root-run container can't produce. CI does not run as root, so they should pass there.

Notes for the reviewer

After merge, to release 0.6.0 (not burned on npm): delete the v0.6.0 Release and tag, then recreate the Release with tag v0.6.0 targeting main. A re-run of the failed job would use the broken workflow file at the old tag.

🤖 Generated with Claude Code

https://claude.ai/code/session_01YGD9yKFvXkXpZd3DdvdZmn


Generated by Claude Code

`npm publish "pkg/pharn-dev-pharn-${VERSION}.tgz"` matched npm's GitHub
`owner/repo` shorthand, so npm tried `git ls-remote
ssh://git@github.com/pkg/...` and the 0.6.0 publish job failed with
`Permission denied (publickey)`. Nothing reached the registry.

Prefix the path with `./` and pin every tarball argument in publish.yml
as an explicit file path in tests/publish-workflow.test.ts, since no PR
check ever executes that workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YGD9yKFvXkXpZd3DdvdZmn
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 71a9aeb9-d469-46b8-814b-a1124f8711f6


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@PrzemekGalarowicz
PrzemekGalarowicz merged commit c40a40c into main Sep 25, 2026
14 checks passed
@PrzemekGalarowicz
PrzemekGalarowicz deleted the claude/charming-allen-t8gbl2 branch September 25, 2026 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants