Repository navigation
Migrate to pnpm, upgrade Changesets to v3, and gate the publish step - #13
Merged
Merged
Conversation
Every push to main without a pending changeset failed the Release workflow. changesets invoked publish, `npm info` returned stale data and reported the current version as unpublished, the publish was retried, and npm rejected it with "cannot publish over the previously published versions". This is what made the run for "chore: version packages" (#8) red in May; 0.3.0 was then published by the next unrelated merge (#9). changesets 2.x anticipates stale `npm info` and has a graceful path for it, but gates that path on `json.error.code === "E403"`. Modern npm reports no code for this error, so the guard never matches and the run fails instead of skipping. No 2.x release fixes this; 2.31.1 still has the gate. Changesets v3 drops the code check and routes already-published to a non-failure result that exits 0. v3 refuses to run under Yarn Classic ("Yarn Classic is not supported"), so adopting it means leaving Yarn 1. This moves the repo to pnpm, which v3 supports (engines: pnpm >=10). pnpm 10.x is also a known-good line for npm OIDC trusted publishing; the OIDC regression was in 11.0.8, fixed in 11.1.3. Three layers now have to fail before a release breaks: - the gate skips changesets entirely when there is nothing to release - v3 treats an already-published version as success, not failure - tests, typecheck, and build run on the PR before any of this Also removes the global `npm install -g npm@latest` step: pnpm performs the OIDC publish itself, and pulling a moving npm is what drifted the error shape that broke the 2.x guard in the first place. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (5)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the Release workflow failing on every push to
mainthat carries no changeset.Root cause
changeset publishran,npm inforeturned stale data reporting the current version as unpublished, the publish was retried, and npm rejected it:Changesets 2.x anticipates exactly this — there is a comment in its source saying "
npm infocan return stale data at times so we need to gracefully handle this situation" — but the graceful path is gated on the error code:Modern npm reports no code for this error (note the literal
undefinedin the log above), so the guard never matches and the run fails instead of skipping. No 2.x release fixes this — 2.31.1, the newest, still has the gate.This is not new. It is what made the run for
chore: version packages(#8) red in May:0.3.0was not published by its own version PR, it was published by the next unrelated merge (#9). Timings confirm it — run #8 failed at 21:05, run #9 succeeded at 21:48, and0.3.0landed on npm at 21:48:50.Why this also means leaving Yarn
Changesets v3.0.3 fixes it properly: it drops the
E403check and routes already-published to a result that is excluded from the failure list, so the command exits 0. Verified in both the sequential and bulk publish paths.But v3 hard-refuses Yarn Classic:
So v3 requires leaving Yarn 1. This moves to pnpm, which v3 supports (
engines: pnpm >=10).Defence in depth
Three independent layers now have to fail before a release breaks:
Decide whether changesets has work to do) skips changesets entirely when there are no pending changesets and the current version is already on npm. This alone fixes the reported failure.npm info, the run stays green.The gate's three branches were tested directly:
run=false— skiprun=true— publishrun=true— version PROIDC trusted publishing
Publishing moves from
npm publishtopnpm publish, so this matters. pnpm 10.x is a known-good line for npm OIDC trusted publishing — the OIDC regression was in pnpm 11.0.8 (pnpm#11513), fixed in 11.1.3+.packageManagerpins pnpm@10.34.5.The
npm install -g npm@lateststep is removed: pnpm performs the OIDC publish itself, and pulling a moving npm is what drifted the error shape that broke the 2.x guard to begin with.Other changes
.gitignoreno longer ignorespnpm-lock.yaml. The old comment described the stray-lockfile hazard from Remove stray pnpm-lock.yaml that breaks npm publish #9 — that is resolved by pnpm genuinely being the tool now, rather than being mistakenly detected.package.json:build/prepackcallpnpm runinstead ofyarn;pnpm.ignoredBuiltDependencies: ["esbuild"]records that esbuild's install script is intentionally not run (it ships prebuilt binaries — build verified working without it).AGENTS.mddocuments the pnpm requirement.Verification
On a clean
rm -rf node_modules && pnpm install:pnpm install --frozen-lockfile— reproducible, no warningspnpm run typecheck— cleanpnpm run test— 72/72 passingpnpm run build— succeedspnpm pack— exercisesprepack; tarball contains exactlyLICENSE,README.md,package.json,server,shared,src(no lockfile, nodist)No changeset
Intentionally omitted — tooling only, nothing in the published package changes behaviour, so this is not a releasable change under AGENTS.md. With the new gate, merging this will correctly report
0.3.1 is already on npm -> nothing to releaseand skip.What cannot be verified until the next real release
The OIDC publish through
pnpm publishonly exercises on an actual release. Everything up to that point is tested here. If it does fail, the fallback is to restore theregistry-url-based npm path with anNPM_TOKENsecret.🤖 Generated with Claude Code