Skip to content

fix(release): the npm registry check outlasts the registry's cache; npm trust needs --allow-publish and real 2FA - #95

Merged
krzysztof-smartdataengines merged 1 commit into
mainfrom
fix/npm-verify-outlasts-registry-cache
Sep 27, 2026
Merged

krzysztof-smartdataengines merged 1 commit into
mainfrom
fix/npm-verify-outlasts-registry-cache

Conversation

@krzysztof-smartdataengines

Copy link
Copy Markdown
Contributor

Summary

Two things measured on the first npm publish, the hand-made 0.1.0-dev.0 bootstrap on 27 September:

  • The registry caches the package document for five minutes. It is served with
    cache-control: public, max-age=300. The bootstrap was published at 17:57:51Z (its
    last-modified) and answered 404 until 18:02:58Z. The release workflow's build job fetches that
    document to choose the dist-tag (fix(release): npm needs an explicit dist-tag for a prerelease, chosen from what the registry holds #93). The publishing job's last step then checked for the new
    version for about a minute (10 tries, 6 s apart), so the first candidate through the workflow
    would have been reported as failed after a successful publish.
  • The runbook's npm trust command could not have worked.
    • npm 11.15.0 stops with "At least one permission flag is required (--allow-publish,
      --allow-stage-publish)" (lib/trust-cmd.js).
    • The registry refuses the call from a granular token that bypasses 2FA: E403 "Granular access
      tokens that bypass two-factor authentication may not perform this action". Such a token can
      publish the bootstrap, but configuring the trust needs a session with real 2FA, or the
      package's settings page.

What changed

  • release.yml: the registry check makes 40 tries, 10 s apart, which outlasts the cache. It is still
    bounded, and it still ends only when both the version and its dist-tag are visible.
  • test_release.py: the check's tries times its pause must exceed the 300 s cache plus a minute.
  • docs/publishing.md §5.3 and §5.5 changes:
    • the trust command has --allow-publish --yes;
    • it records the two refusals and the five-minute appearance;
    • it quotes npm's notice that tokens bypassing 2FA are being restricted for direct publishing too,
      so a later hand-made publish should use npm login.

Tests

  • The new test goes red when the loop is cut to 6 tries or the pause to 6 s. A control, a comment
    edit, survives.
  • check_contexts.py: nothing changed in the publishing job's shape: no checkout, id-token behind
    the environment, and every action pinned.
  • make check on the head b9f915e with both live engines: ruff, mypy, Python 2100 passed and 10
    skipped (the orderbook slice), TypeScript 999 passed.

🤖 Generated with Claude Code

…; npm trust needs --allow-publish and real 2FA

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@krzysztof-smartdataengines
krzysztof-smartdataengines merged commit 1ec940f into main Sep 27, 2026
14 checks passed
@krzysztof-smartdataengines
krzysztof-smartdataengines deleted the fix/npm-verify-outlasts-registry-cache branch September 27, 2026 18:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant