From 68e19d7d1723594828a84df5d5aac3bac66e3dec Mon Sep 17 00:00:00 2001 From: kkdev92 <112151103+kkdev92@users.noreply.github.com> Date: Mon, 28 Sep 2026 10:07:07 +0900 Subject: [PATCH] ci: keep a 2.x release from moving the latest tag The 2.x line is still documented as receiving fixes, but the release workflow on this branch dates from before the current line and would ship a 2.x patch in a way nobody wants: - `npm publish` ran without `--tag`, so npm would move `latest` to the 2.x patch and `npm install vscode-ext-kit` would install it. - The publish job had no environment, so nothing stood between pushing the tag and the registry. The current line goes through the `npm-publish` approval gate, whose tag policy (`v*`) admits 2.x tags too. - `gh release create` left "Latest" to GitHub, which could hand the label to the 2.x release. - CI ran only for `main`, so a pull request into this branch was never checked. The publish job now uses the `npm-publish` environment, publishes under the `maintenance-2x` dist-tag, and creates the GitHub Release with `--latest=false`. CI runs for pushes and pull requests on this branch as well as `main`. The dist-tag avoids a leading digit or `v`, because npm rejects tags that read as semver ranges (`v2` reads as `>=2.0.0 <3.0.0-0`). Nothing is released by this change; it only affects the next 2.x tag. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/ci.yml | 4 ++-- .github/workflows/release.yml | 14 ++++++++++++-- 2 files changed, 14 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 900da95..ee097c9 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -2,9 +2,9 @@ name: CI on: push: - branches: [main] + branches: [main, v2-maintenance] pull_request: - branches: [main] + branches: [main, v2-maintenance] permissions: contents: read diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f416906..8821006 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -12,6 +12,10 @@ permissions: jobs: publish: runs-on: ubuntu-latest + # The same approval gate the current line's release goes through. A 2.x + # patch is published by hand, rarely, and nothing else stands between the + # tag and the registry. + environment: npm-publish steps: - name: Checkout repository @@ -45,10 +49,16 @@ jobs: # Auth comes from npm trusted publishing (OIDC) via id-token: write — # there is no NODE_AUTH_TOKEN. The registry-url above is still required # so npm targets registry.npmjs.org when exchanging the OIDC token. + # + # Published under its own dist-tag. Without --tag, npm moves `latest` to + # whatever was published last, so a 2.x patch would become what + # `npm install vscode-ext-kit` installs. The tag must not read as a semver + # range, so it does not start with a digit or `v`. - name: Publish to npm - run: npm publish --provenance --access public + run: npm publish --provenance --access public --tag maintenance-2x + # Not marked "Latest": the current line's release keeps that label. - name: Create GitHub Release - run: gh release create "$GITHUB_REF_NAME" --generate-notes + run: gh release create "$GITHUB_REF_NAME" --generate-notes --latest=false env: GH_TOKEN: ${{ github.token }}