ci: keep a 2.x release from moving the latest tag - #77
Merged
Merged
Conversation
The 2.x line is still documented as receiving fixes, but the release workflow on this branch dates from before the current line and would ship a 2.x patch in a way nobody wants: - `npm publish` ran without `--tag`, so npm would move `latest` to the 2.x patch and `npm install vscode-ext-kit` would install it. - The publish job had no environment, so nothing stood between pushing the tag and the registry. The current line goes through the `npm-publish` approval gate, whose tag policy (`v*`) admits 2.x tags too. - `gh release create` left "Latest" to GitHub, which could hand the label to the 2.x release. - CI ran only for `main`, so a pull request into this branch was never checked. The publish job now uses the `npm-publish` environment, publishes under the `maintenance-2x` dist-tag, and creates the GitHub Release with `--latest=false`. CI runs for pushes and pull requests on this branch as well as `main`. The dist-tag avoids a leading digit or `v`, because npm rejects tags that read as semver ranges (`v2` reads as `>=2.0.0 <3.0.0-0`). Nothing is released by this change; it only affects the next 2.x tag. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Makes the 2.x release path safe to use: an approval gate, its own dist-tag, and no "Latest" label, plus CI on this branch.
Why
README, SECURITY.md and CONTRIBUTING.md say 2.1.x still receives fixes from
v2-maintenance, but the release workflow on this branch predates the current line:npm publishruns without--tag, so a 2.x patch would become npm'slatestand whatnpm install vscode-ext-kitinstalls.npm-publishapproval gate, whose tag policy (v*) admits 2.x tags as well.gh release createleaves "Latest" to GitHub.main, so pull requests into this branch are not checked.What changed
release.yml: the publish job uses thenpm-publishenvironment;npm publishpasses--tag maintenance-2x;gh release createpasses--latest=false.ci.yml: runs on pushes and pull requests forv2-maintenanceas well asmain.The dist-tag does not start with a digit or
v, because npm rejects dist-tags that read as semver ranges (npm dist-tag);v2would read as>=2.0.0 <3.0.0-0.Verification
environment: npm-publishwith the two changed commands.npm-publishenvironment's deployment policy is the tag patternv*, so av2.x.ytag can use it.🤖 Generated with Claude Code