fix(react-kratos): recover existing npm release - #161
Merged
Merged
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Task
@atls/react-kratos@0.1.0as a GitHub Release and committed the version change, but npm rejected the direct publish. At recovery start, the public registry still served0.0.2.0.1.0package. It checks out the exact version commit, verifies the manifest and that the version is absent from npm, then uses the existing Yarn workspace publisher and the orgNPM_TOKEN. It does not create another version, tag, or GitHub Release and does not publish other workspaces.How to verify
Before fix
masterat version commit9bc23729472414c56d1a0a2d67f423dec0f05cfcafter the failed publish run. Action: inspect Raijin workspace selection with and without the original GitHub PR event. Expected result: a local invocation without event context selects no workspaces; CI with the original PR event can select the changed packages again and defer another version bump. The recovery job therefore publishes the pinned existing version directly.After fix
NPM_TOKENhas direct publish permission. Action: dispatchPublish to registrymanually. Expected result: the recovery job checks out9bc2372, verifies package version0.1.0and registry absence, installs immutably, then publishes only@atls/react-kratos@0.1.0. Confirm the registry version, packed exports, and consumer installation from npm rather than inferring success from the workflow exit code.0.1.0is already available from npm. Action: dispatch the same recovery job again. Expected result: the registry guard fails before the publish step; no new version or tag is created.Proofs
403 E_STAGE_REQUIREDat the first changed workspace. This recovery does not claim to fix the separate shared changelog command.actionlintandyarn install --immutablepassed.yarn workspace @atls/react-kratos packproduced a0.1.0tarball withdist/index.jsanddist/index.d.ts; SHA-2564e09d42e6f82714fdd8d082a243e9dea3a188f5bd79a54edaddb3c8b8574712c.@atls/react-kratos@0.1.0withgitHead9bc23729472414c56d1a0a2d67f423dec0f05cfc.