fix(release): the npm registry check outlasts the registry's cache; npm trust needs --allow-publish and real 2FA - #95
Merged
krzysztof-smartdataengines merged 1 commit intoSep 27, 2026
Conversation
…; npm trust needs --allow-publish and real 2FA Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
krzysztof-smartdataengines
deleted the
fix/npm-verify-outlasts-registry-cache
branch
September 27, 2026 18:33
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two things measured on the first npm publish, the hand-made
0.1.0-dev.0bootstrap on 27 September:cache-control: public, max-age=300. The bootstrap was published at 17:57:51Z (itslast-modified) and answered 404 until 18:02:58Z. The release workflow's build job fetches thatdocument to choose the dist-tag (fix(release): npm needs an explicit dist-tag for a prerelease, chosen from what the registry holds #93). The publishing job's last step then checked for the new
version for about a minute (10 tries, 6 s apart), so the first candidate through the workflow
would have been reported as failed after a successful publish.
npm trustcommand could not have worked.--allow-stage-publish)" (
lib/trust-cmd.js).E403"Granular accesstokens that bypass two-factor authentication may not perform this action". Such a token can
publish the bootstrap, but configuring the trust needs a session with real 2FA, or the
package's settings page.
What changed
release.yml: the registry check makes 40 tries, 10 s apart, which outlasts the cache. It is stillbounded, and it still ends only when both the version and its dist-tag are visible.
test_release.py: the check's tries times its pause must exceed the 300 s cache plus a minute.docs/publishing.md§5.3 and §5.5 changes:--allow-publish --yes;so a later hand-made publish should use
npm login.Tests
edit, survives.
check_contexts.py: nothing changed in the publishing job's shape: no checkout,id-tokenbehindthe environment, and every action pinned.
make checkon the headb9f915ewith both live engines: ruff, mypy, Python 2100 passed and 10skipped (the orderbook slice), TypeScript 999 passed.
🤖 Generated with Claude Code