Skip to content

ci: keep a 2.x release from moving the latest tag - #77

Merged
kkdev92 merged 1 commit into
v2-maintenancefrom
ci/v2-maintenance-release-guard
Sep 28, 2026
Merged

kkdev92 merged 1 commit into
v2-maintenancefrom
ci/v2-maintenance-release-guard

Conversation

@kkdev92

@kkdev92 kkdev92 commented Sep 28, 2026

Copy link
Copy Markdown
Owner

Makes the 2.x release path safe to use: an approval gate, its own dist-tag, and no "Latest" label, plus CI on this branch.

Why

README, SECURITY.md and CONTRIBUTING.md say 2.1.x still receives fixes from v2-maintenance, but the release workflow on this branch predates the current line:

  • npm publish runs without --tag, so a 2.x patch would become npm's latest and what npm install vscode-ext-kit installs.
  • The publish job has no environment, so nothing stands between pushing the tag and the registry. The current line's release goes through the npm-publish approval gate, whose tag policy (v*) admits 2.x tags as well.
  • gh release create leaves "Latest" to GitHub.
  • CI runs only for main, so pull requests into this branch are not checked.

What changed

  • release.yml: the publish job uses the npm-publish environment; npm publish passes --tag maintenance-2x; gh release create passes --latest=false.
  • ci.yml: runs on pushes and pull requests for v2-maintenance as well as main.

The dist-tag does not start with a digit or v, because npm rejects dist-tags that read as semver ranges (npm dist-tag); v2 would read as >=2.0.0 <3.0.0-0.

Verification

  • Both workflow files parse, and the publish job resolves to environment: npm-publish with the two changed commands.
  • The npm-publish environment's deployment policy is the tag pattern v*, so a v2.x.y tag can use it.
  • This pull request runs CI on the 2.x code for the first time since the branch was cut; the result is below.
  • Nothing is released by this change. It only affects the next 2.x tag.

🤖 Generated with Claude Code

The 2.x line is still documented as receiving fixes, but the release workflow
on this branch dates from before the current line and would ship a 2.x patch
in a way nobody wants:

- `npm publish` ran without `--tag`, so npm would move `latest` to the 2.x
  patch and `npm install vscode-ext-kit` would install it.
- The publish job had no environment, so nothing stood between pushing the tag
  and the registry. The current line goes through the `npm-publish` approval
  gate, whose tag policy (`v*`) admits 2.x tags too.
- `gh release create` left "Latest" to GitHub, which could hand the label to
  the 2.x release.
- CI ran only for `main`, so a pull request into this branch was never checked.

The publish job now uses the `npm-publish` environment, publishes under the
`maintenance-2x` dist-tag, and creates the GitHub Release with
`--latest=false`. CI runs for pushes and pull requests on this branch as well
as `main`. The dist-tag avoids a leading digit or `v`, because npm rejects tags
that read as semver ranges (`v2` reads as `>=2.0.0 <3.0.0-0`).

Nothing is released by this change; it only affects the next 2.x tag.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kkdev92
kkdev92 merged commit 65ad110 into v2-maintenance Sep 28, 2026
4 checks passed
@kkdev92
kkdev92 deleted the ci/v2-maintenance-release-guard branch September 28, 2026 01:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant