fix(ci): pin release npm to 11.x instead of latest - #64
Merged
Merged
Conversation
The release job installs `npm@latest`, which now resolves to 12.1.0:
npm error code EBADENGINE
npm error Required: {"node":"^22.22.2 || ^24.15.0 || >=26.0.0"}
npm error Actual: {"npm":"10.9.2","node":"v22.14.0"}
.nvmrc pins Node 22.14.0, so the step fails and the whole Release
workflow aborts before changesets runs -- which is why 8.3.1 was never
published and the version PR stopped being regenerated.
Pin to the 11.x line: every 11.x release declares
`^20.17.0 || >=22.9.0`, satisfied by 22.14.0, and it resolves to
11.20.0, well past the 11.5.1 that introduced OIDC trusted publishing.
Same failure mode as the `platform-sdk: latest` range removed earlier:
an unpinned `latest` silently crossing a major boundary.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The failure
The
Releaseworkflow onmainis red, aborting at theUpdate npmstep (run 36014474353):release.yml:47runsnpm install -g npm@latest.latestnow resolves to 12.1.0, which refuses to install on the Node version.nvmrcpins (22.14.0).Impact
The step runs before
changesets/action, so the job aborts and nothing publishes. This is why@commercetools/sync-actions8.3.1 was never released and why the "Version Packages" PR (#61) stopped being regenerated.The fix
Pin the major:
Why 11.x is safe:
11.xreleases declaresengines.nodeas^20.17.0 || >=22.9.0. Node 22.14.0 satisfies all of them, so the pin holds regardless of which 11.x resolves.npm@11currently resolves to 11.20.0, comfortably past 11.5.1, which introduced OIDC trusted publishing — the reason this step exists at all (see theid-token: writepermission).Pinning npm rather than bumping
.nvmrckeeps the change to one line and avoids moving the Node version every other workflow also builds and tests against.Note
This is the same failure mode as the
"@commercetools/platform-sdk": "latest"range removed in #62 — an unpinnedlatestsilently crossing a major boundary. Worth a scan for any other@latestleft in CI.Verification
npm install -g npm@11npm view npm@11 engines.nodeconfirms^20.17.0 || >=22.9.0across the entire 11.x lineThe Release workflow only runs on push to
main, so it cannot be exercised from a PR — the real check is the next push to main after this merges.🤖 Generated with Claude Code