ci: guard releases against duplicate versions and dead tags - #46
Merged
Conversation
Ported from opencode-litellm-pricing, where both earned their place while debugging a trusted-publisher misconfiguration that failed four releases. Reject a version already on npm before packing and signing, rather than after — npm refuses duplicates and the failure is otherwise late and noisy. Delete the tag when nothing was published. Such a tag cannot be re-pushed and blocks the retry. Guarded on the publish step's own outcome, so a tag whose package did go out is left alone: npm will not take the same version twice, and that release has to be finished by hand. Also align ci.yaml on npm ci --ignore-scripts, matching release.yaml.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ported from
opencode-litellm-pricing, where both guards earned their place while debugging a trusted-publisher misconfiguration that failed four consecutive releases.steps.publish.outcome != 'success', so a tag whose package did go out is left alone — npm won't take the same version twice, and that release has to be finished by hand.ci.yamlaligned onnpm ci --ignore-scripts, matchingrelease.yaml.Nothing about the existing publish path changes; this repo's releases already work.
Verification
The duplicate guard was extracted from the parsed YAML and run against the live registry: with
package.jsonat the published0.9.0it errors and exits 1. Workflow parses clean, step order otherwise unchanged.