Skip to content

fix(ci): pin release npm to 11.x instead of latest - #64

Merged
ajimae merged 1 commit into
mainfrom
fix/pin-npm-release
Sep 24, 2026
Merged

ajimae merged 1 commit into
mainfrom
fix/pin-npm-release

Conversation

@ajimae

@ajimae ajimae commented Sep 24, 2026

Copy link
Copy Markdown
Member

The failure

The Release workflow on main is red, aborting at the Update npm step (run 36014474353):

npm error code EBADENGINE
npm error engine Unsupported engine
npm error Not compatible with your version of node/npm: npm@12.1.0
npm error Required: {"node":"^22.22.2 || ^24.15.0 || >=26.0.0"}
npm error Actual:   {"npm":"10.9.2","node":"v22.14.0"}

release.yml:47 runs npm install -g npm@latest. latest now resolves to 12.1.0, which refuses to install on the Node version .nvmrc pins (22.14.0).

Impact

The step runs before changesets/action, so the job aborts and nothing publishes. This is why @commercetools/sync-actions 8.3.1 was never released and why the "Version Packages" PR (#61) stopped being regenerated.

The fix

Pin the major:

- run: npm install -g npm@latest
+ run: npm install -g npm@11

Why 11.x is safe:

  • Every one of the 34 published 11.x releases declares engines.node as ^20.17.0 || >=22.9.0. Node 22.14.0 satisfies all of them, so the pin holds regardless of which 11.x resolves.
  • npm@11 currently resolves to 11.20.0, comfortably past 11.5.1, which introduced OIDC trusted publishing — the reason this step exists at all (see the id-token: write permission).

Pinning npm rather than bumping .nvmrc keeps the change to one line and avoids moving the Node version every other workflow also builds and tests against.

Note

This is the same failure mode as the "@commercetools/platform-sdk": "latest" range removed in #62 — an unpinned latest silently crossing a major boundary. Worth a scan for any other @latest left in CI.

Verification

  • Workflow YAML parses; the step resolves to npm install -g npm@11
  • npm view npm@11 engines.node confirms ^20.17.0 || >=22.9.0 across the entire 11.x line

The Release workflow only runs on push to main, so it cannot be exercised from a PR — the real check is the next push to main after this merges.

🤖 Generated with Claude Code

The release job installs `npm@latest`, which now resolves to 12.1.0:

    npm error code EBADENGINE
    npm error Required: {"node":"^22.22.2 || ^24.15.0 || >=26.0.0"}
    npm error Actual:   {"npm":"10.9.2","node":"v22.14.0"}

.nvmrc pins Node 22.14.0, so the step fails and the whole Release
workflow aborts before changesets runs -- which is why 8.3.1 was never
published and the version PR stopped being regenerated.

Pin to the 11.x line: every 11.x release declares
`^20.17.0 || >=22.9.0`, satisfied by 22.14.0, and it resolves to
11.20.0, well past the 11.5.1 that introduced OIDC trusted publishing.

Same failure mode as the `platform-sdk: latest` range removed earlier:
an unpinned `latest` silently crossing a major boundary.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@ajimae
ajimae requested a review from a team as a code owner September 24, 2026 15:15
@changeset-bot

changeset-bot Bot commented Sep 24, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 4cb6726

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@ajimae
ajimae merged commit 96dc336 into main Sep 24, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant