From 4cb6726ee3d179d3d506c913cdafa519ab4dd55e Mon Sep 17 00:00:00 2001 From: Chukwuemeka Date: Thu, 24 Sep 2026 17:15:29 +0200 Subject: [PATCH] fix(ci): pin release npm to 11.x instead of `latest` The release job installs `npm@latest`, which now resolves to 12.1.0: npm error code EBADENGINE npm error Required: {"node":"^22.22.2 || ^24.15.0 || >=26.0.0"} npm error Actual: {"npm":"10.9.2","node":"v22.14.0"} .nvmrc pins Node 22.14.0, so the step fails and the whole Release workflow aborts before changesets runs -- which is why 8.3.1 was never published and the version PR stopped being regenerated. Pin to the 11.x line: every 11.x release declares `^20.17.0 || >=22.9.0`, satisfied by 22.14.0, and it resolves to 11.20.0, well past the 11.5.1 that introduced OIDC trusted publishing. Same failure mode as the `platform-sdk: latest` range removed earlier: an unpinned `latest` silently crossing a major boundary. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/release.yml | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8b87beb..12f9650 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -43,8 +43,12 @@ jobs: - name: Setup uses: ./.github/actions/ci + # Pinned to the 11.x line rather than `latest`: npm 12 requires + # Node ^22.22.2 || ^24.15.0 || >=26, which the version in .nvmrc + # (22.14.0) does not satisfy, so `latest` broke the release. + # 11.x supports OIDC trusted publishing and runs on Node >=22.9.0. - name: Update npm - run: npm install -g npm@latest + run: npm install -g npm@11 - name: Creating .npmrc run: |