Skip to content

chore(release): merge v2/main into main for the v2.9.0 re-release (publish fix) - #2553

Merged
cliffhall merged 3 commits into
mainfrom
v2/chore/milestone-merge-v2.9.0-publish-fix
Sep 30, 2026
Merged

cliffhall merged 3 commits into
mainfrom
v2/chore/milestone-merge-v2.9.0-publish-fix

Conversation

@cliffhall

Copy link
Copy Markdown
Member

Closes #2551

Re-release merge for v2.9.0. The first 2.9.0 release run failed at publish (#2551), so 2.9.0 never reached npm. A release runs the workflow from the tag's commit, so the fix has to be on main before 2.9.0 is re-cut.

What this carries

Exactly one change relative to the main that was tagged 2.9.0 (e0e2cb59):

$ git diff --name-only e0e2cb59 HEAD
.github/workflows/main.yml

That change is #2552: set -- ./release-tarball/*.tgz, so npm publish reads the tarball as a local file rather than as a GitHub owner/repo shorthand. The package contents are unchanged from the smoke-tested tree in #2536 (fa73c594).

Pure merge

$ git rev-list HEAD --not origin/main origin/v2/main
6858a0f6 chore: merge v2/main into main for the v2.9.0 re-release (publish fix #2551)

origin/v2/main^{tree}  6ed97cd97cd9c9167ae6a0a102e190773b4ed70a
HEAD^{tree}            6ed97cd97cd9c9167ae6a0a102e190773b4ed70a

The tree is identical to v2/main, and to #2552's head, which passed npm run local:gate (exit 0, 5m05s). Version: 2.9.0.

After merge

  1. Delete the stale 2.9.0 tag, which still points at e0e2cb59. The Release itself is already deleted.
  2. Recreate the 2.9.0 Release at the new main merge commit with the original notes.
  3. Publishing fires package → publish (npm, with provenance) and the GHCR image.

🤖 Generated with Claude Code

cliffhall and others added 3 commits September 30, 2026 17:51
The release publish job did `set -- release-tarball/*.tgz` and passed
that bare relative path to `npm publish`. npm reads a `dir/file`
argument as GitHub `owner/repo` shorthand, so it ran
`git ls-remote ssh://git@github.com/release-tarball/…` and failed with
Permission denied: 2.9.0 never reached npm. This is the #2483 job split
running for the first time; it can only be exercised by a real release.

Prefix the glob with ./ so npm treats it as a local file. Reproduced and
verified with the pinned npm@11.20.0: the bare path fails with the same
git error, and the ./ path dry-runs a publish of the tarball.

Closes #2551

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
…h-local-tarball-path

fix(ci): publish the tarball by a ./ path so npm reads it as a file
Copilot AI balanced review requested due to automatic review settings September 30, 2026 22:10
@cliffhall cliffhall added the v2 Issues and PRs for v2 label Sep 30, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused change correctly resolves the reported publish failure without altering package contents.

Review effort: Balanced
Findings: None

What changed in this PR

Fixes the v2.9.0 npm re-release workflow by ensuring npm treats the tarball argument as a local file.

Changes:

  • Prefixes the tarball path with ./.
  • Documents why the prefix is required.
File Description
.github/​workflows/​main.yml Corrects the tarball path passed to npm publish.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@cliffhall
cliffhall merged commit ae865a1 into main Sep 30, 2026
9 checks passed
@cliffhall
cliffhall deleted the v2/chore/milestone-merge-v2.9.0-publish-fix branch September 30, 2026 22:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

v2 Issues and PRs for v2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release publish job passes a bare relative tarball path, which npm reads as a GitHub repo: 2.9.0 never reached npm

2 participants