Repository navigation
fix(release): skip versions whose release tag exists while npm stages them - #373
Merged
Merged
Conversation
Collaborator
Author
How to use the Graphite Merge QueueAdd either label to this PR to merge it via the merge queue:
You must have a Graphite account in order to use the merge queue. Sign up using this link. An organization admin has enabled the Graphite Merge Queue in this repository. Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue. This stack of pull requests is managed by Graphite. Learn more about stacking. |
anandpant
force-pushed
the
fix/release-staged-publish-race
branch
from
October 10, 2026 21:38
c2ff654 to
194300c
Compare
anandpant
marked this pull request as ready for review
October 10, 2026 21:39
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
Contributor
Sketchi Web PreviewStatus:
|
Contributor
Sketchi Icons PreviewStatus:
|
Contributor
Sketchi Playground / Studio PreviewStatus:
|
Contributor
Sketchi Excalidraw Workspace PreviewStatus:
|
Contributor
Sketchi Eval Harness PreviewStatus:
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What changed
.github/workflows/release.yml): before asking npm, the guard checks whether thecli-v<version>tag already exists, and skips the release if it does. The tag job runs only after a successful publish, so the tag is the authoritative "already released" signal. Ifgit ls-remotefails, the job fails rather than guessing.npm publishfails with exactlyE409 … Cannot publish over previously staged version "<this version>", it treats the version as published and continues to the tag and GitHub Release jobs. That covers a rerun after npm staged the publish but a later job failed. Any other error, including an E409 for a different version, still fails. The publish log goes to$RUNNER_TEMP, outside the package directory being published.scripts/lib/release-workflow.test.mjs): runs the guard and publish steps exactly as written in the workflow, withgitandnpmstubbed. The cases cover a tag that exists while npm still reports 404, an untagged version missing from npm, a version npm already serves, both lookups failing closed, the staged E409 for this version, and other failures that must still fail. Run against the old workflow, the tag and staged-E409 tests fail; the other four pass.Why
npm now stages trusted publishes: they wait for 2FA approval, then process. During that window,
npm view sketchi@<version>returns 404. Run 38086249637 published 0.9.0 and pushedcli-v0.9.0. The next push tomain(run 38086346671, for #368) saw the 404, tried to republish, and failed withE409 Cannot publish over previously staged version "0.9.0".npm view sketchi@0.9.0still returns 404 while the tag exists. Releases are serialized by thereleaseconcurrency group, so a later run's guard always sees the earlier run's tag.How it was verified
pnpm run test:deploy-scripts(the new release tests included)actionlintonrelease.ymlpnpm run format:checkNo changeset: this changes the release workflow, not the CLI.