Repository navigation
feat: promote npm edge tag to latest when prerelease is promoted #48
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -4,10 +4,32 @@ on: | |
| release: | ||
| types: | ||
| - published | ||
| - edited | ||
|
|
||
| - released | ||
| jobs: | ||
| # When a prerelease is promoted to a full release, update the npm latest tag | ||
| promote: | ||
| if: github.event.action == 'released' | ||
| runs-on: ubuntu-24.04 | ||
| steps: | ||
| - name: Checkout code | ||
| uses: actions/checkout@v6 | ||
| - name: Install node 20 | ||
| uses: actions/setup-node@v6 | ||
| with: | ||
| node-version: '20' | ||
| registry-url: https://registry.npmjs.org | ||
| - name: Promote edge to latest | ||
| run: | | ||
| VERSION=$(echo "$TAG_NAME" | sed 's/^v//') | ||
| PACKAGE=$(node -p "require('./package.json').name") | ||
| npm dist-tag add "$PACKAGE@$VERSION" latest | ||
| echo "::notice title=Promoted $VERSION to latest::The latest tag now points to $VERSION (was edge-only)" | ||
| env: | ||
| TAG_NAME: ${{ github.event.release.tag_name }} | ||
| NODE_AUTH_TOKEN: ${{secrets.NPM_DEPLOY_TOKEN}} | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Race condition: promote job runs before deploy publishesMedium Severity When a fresh non-prerelease is published, both Additional Locations (1) |
||
|
|
||
| deploy: | ||
| if: github.event.action == 'published' | ||
| runs-on: ${{ matrix.os }} | ||
| env: | ||
| TERM: xterm | ||
|
|
||


There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Inconsistent action versions across jobs in same workflow
Low Severity
The new
promotejob usesactions/checkout@v6andactions/setup-node@v6, while thedeployjob in the same file and every other workflow in the repo consistently uses@v4. Mixing major versions within the same workflow file is surprising and increases maintenance burden.checkout@v6also introduced credential-handling changes with known compatibility caveats, andsetup-node@v6enables npm caching by default (unnecessary here since nonpm installruns).