Skip to content

fix(ci): publish the tarball by a ./ path so npm reads it as a file - #2552

Merged
cliffhall merged 1 commit into
v2/mainfrom
v2/fix/2551-publish-local-tarball-path
Sep 30, 2026
Merged

cliffhall merged 1 commit into
v2/mainfrom
v2/fix/2551-publish-local-tarball-path

Conversation

@cliffhall

Copy link
Copy Markdown
Member

Closes #2551

Problem

The v2.9.0 release run's publish job failed, and 2.9.0 never reached npm (latest is still 2.8.0). Job log:

npm error command git --no-replace-objects ls-remote ssh://git@github.com/release-tarball/modelcontextprotocol-inspector-2.9.0.tgz.git
npm error git@github.com: Permission denied (publickey).

set -- release-tarball/*.tgz passed a bare relative path to npm publish. npm reads dir/file as GitHub owner/repo shorthand and tried to clone it. This is the #2483 package / publish split running for the first time; only a real release can exercise it.

Fix

set -- ./release-tarball/*.tgz, with a comment on why the ./ matters. Nothing else in the step changes: the publishConfig refusal, the name and version re-assertion, and the pinned registry are all as before.

Verification

With the CI-pinned npm@11.20.0, on the real 2.9.0 tarball:

Argument Result
release-tarball/modelcontextprotocol-inspector-2.9.0.tgz reproduces the CI failure: git ls-remote ssh://git@github.com/release-tarball/…, Permission denied (publickey)
./release-tarball/modelcontextprotocol-inspector-2.9.0.tgz Publishing to https://registry.npmjs.org/ with tag latest and public access (dry-run), @modelcontextprotocol/inspector@2.9.0

npm run local:gate → green (exit 0, 5m05s), including verify:action-pins.

After merge

A release runs the workflow from the tag's commit, so this must reach main and the 2.9.0 Release must be re-cut at that commit (tracked on #2551).

🤖 Generated with Claude Code

The release publish job did `set -- release-tarball/*.tgz` and passed
that bare relative path to `npm publish`. npm reads a `dir/file`
argument as GitHub `owner/repo` shorthand, so it ran
`git ls-remote ssh://git@github.com/release-tarball/…` and failed with
Permission denied: 2.9.0 never reached npm. This is the #2483 job split
running for the first time; it can only be exercised by a real release.

Prefix the glob with ./ so npm treats it as a local file. Reproduced and
verified with the pinned npm@11.20.0: the bare path fails with the same
git error, and the ./ path dry-runs a publish of the tarball.

Closes #2551

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused path correction addresses the reported publish failure without changing the existing safeguards.

Review effort: Balanced
Findings: None

What changed in this PR

This PR fixes the release workflow so npm publishes the downloaded tarball as a local file.

Changes:

  • Prefixes the tarball path with ./ and documents why it matters.
File Description
.github/​workflows/​main.yml Passes a local tarball path to npm publish.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@cliffhall

Copy link
Copy Markdown
Member Author

Copilot review loop closed: round 1 was clean (approval recommended, no findings, no inline or suppressed comments), so no further round was requested.

@cliffhall
cliffhall merged commit 8996cc4 into v2/main Sep 30, 2026
6 checks passed
@cliffhall
cliffhall deleted the v2/fix/2551-publish-local-tarball-path branch September 30, 2026 22:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

v2 Issues and PRs for v2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release publish job passes a bare relative tarball path, which npm reads as a GitHub repo: 2.9.0 never reached npm

2 participants