You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Release workflow reports a green npm publish that never happens #51
publish.yml runs on every published GitHub release. Its last step skips npm publish with exit 0 when NODE_AUTH_TOKEN is unset, so the run shows green even though nothing was published. The v0.1.4 run did exactly that ("NODE_AUTH_TOKEN is not configured; skipping npm publish.").
npm can never be this package's channel:
The unscoped npm name pi-apply-patch belongs to an unrelated project.
A step that looks like a publish and silently skips misleads anyone reading the run.
Expected
A release run states what a release is: a verified tag distributed via git.
It has no npm step and no id-token permission it doesn't use.
It fails, rather than passes, when the release tag doesn't match package.json (the one release mistake that would ship a wrong version through git installs).
Acceptance
publish.yml has no npm publish step and no id-token permission.
A release run's summary says "distributed via git".
A tag that doesn't match package.json fails the run.
Fixed by #52, merged as 21760de. The release workflow no longer has an npm publish step; a release is the version tag.
The unscoped npm name:pi-apply-patch belongs to another account, so this repository could never have published it. A run that "succeeded" past the publish step proved nothing.
What the workflow does now: it checks that the tag matches package.json's version, and its summary says the package is distributed via git.
Consumers: senpi pins it by version from git (external-versions.json, 0.1.4, merged in senpi#2639).
Summary
publish.ymlruns on every published GitHub release. Its last step skipsnpm publishwith exit 0 whenNODE_AUTH_TOKENis unset, so the run shows green even though nothing was published. The v0.1.4 run did exactly that ("NODE_AUTH_TOKEN is not configured; skipping npm publish.").npm can never be this package's channel:
pi-apply-patchbelongs to an unrelated project.pi install git:github.com/code-yeongyu/pi-apply-patch, which resolves the release tag.A step that looks like a publish and silently skips misleads anyone reading the run.
Expected
id-tokenpermission it doesn't use.package.json(the one release mistake that would ship a wrong version through git installs).Acceptance
publish.ymlhas no npm publish step and noid-tokenpermission.package.jsonfails the run.