chore(release): merge v2/main into main for the v2.9.0 re-release (publish fix) - #2553
Merged
Merged
Conversation
The release publish job did `set -- release-tarball/*.tgz` and passed that bare relative path to `npm publish`. npm reads a `dir/file` argument as GitHub `owner/repo` shorthand, so it ran `git ls-remote ssh://git@github.com/release-tarball/…` and failed with Permission denied: 2.9.0 never reached npm. This is the #2483 job split running for the first time; it can only be exercised by a real release. Prefix the glob with ./ so npm treats it as a local file. Reproduced and verified with the pinned npm@11.20.0: the bare path fails with the same git error, and the ./ path dry-runs a publish of the tarball. Closes #2551 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
…h-local-tarball-path fix(ci): publish the tarball by a ./ path so npm reads it as a file
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The focused change correctly resolves the reported publish failure without altering package contents.
Review effort: Balanced
Findings: None
What changed in this PR
Fixes the v2.9.0 npm re-release workflow by ensuring npm treats the tarball argument as a local file.
Changes:
- Prefixes the tarball path with
./. - Documents why the prefix is required.
| File | Description |
|---|---|
.github/workflows/main.yml |
Corrects the tarball path passed to npm publish. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #2551
Re-release merge for v2.9.0. The first 2.9.0 release run failed at
publish(#2551), so 2.9.0 never reached npm. A release runs the workflow from the tag's commit, so the fix has to be onmainbefore 2.9.0 is re-cut.What this carries
Exactly one change relative to the
mainthat was tagged2.9.0(e0e2cb59):That change is #2552:
set -- ./release-tarball/*.tgz, sonpm publishreads the tarball as a local file rather than as a GitHubowner/reposhorthand. The package contents are unchanged from the smoke-tested tree in #2536 (fa73c594).Pure merge
The tree is identical to
v2/main, and to #2552's head, which passednpm run local:gate(exit 0, 5m05s). Version:2.9.0.After merge
2.9.0tag, which still points ate0e2cb59. The Release itself is already deleted.mainmerge commit with the original notes.package→publish(npm, with provenance) and the GHCR image.🤖 Generated with Claude Code