Skip to content

Release workflow reports a green npm publish that never happens #51

Description

@code-yeongyu

Summary

publish.yml runs on every published GitHub release. Its last step skips npm publish with exit 0 when NODE_AUTH_TOKEN is unset, so the run shows green even though nothing was published. The v0.1.4 run did exactly that ("NODE_AUTH_TOKEN is not configured; skipping npm publish.").

npm can never be this package's channel:

  • The unscoped npm name pi-apply-patch belongs to an unrelated project.
  • docs: install from GitHub instead of npm #42 made git the documented distribution: pi install git:github.com/code-yeongyu/pi-apply-patch, which resolves the release tag.

A step that looks like a publish and silently skips misleads anyone reading the run.

Expected

  • A release run states what a release is: a verified tag distributed via git.
  • It has no npm step and no id-token permission it doesn't use.
  • It fails, rather than passes, when the release tag doesn't match package.json (the one release mistake that would ship a wrong version through git installs).

Acceptance

  • publish.yml has no npm publish step and no id-token permission.
  • A release run's summary says "distributed via git".
  • A tag that doesn't match package.json fails the run.

Activity

  1. code-yeongyu commented on Oct 3, 2026

    @code-yeongyu
    OwnerAuthor

    Fixed by #52, merged as 21760de. The release workflow no longer has an npm publish step; a release is the version tag.

    • The unscoped npm name: pi-apply-patch belongs to another account, so this repository could never have published it. A run that "succeeded" past the publish step proved nothing.
    • What the workflow does now: it checks that the tag matches package.json's version, and its summary says the package is distributed via git.
    • Consumers: senpi pins it by version from git (external-versions.json, 0.1.4, merged in senpi#2639).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions