From 8ef1e5cfe96b07ea9c823276b07f437f85f75c15 Mon Sep 17 00:00:00 2001 From: John McLear Date: Mon, 21 Sep 2026 09:52:00 +0100 Subject: [PATCH] ci: publish on Node 24 with a pinned npm npm 12 requires Node ^22.22.2 || ^24.15.0 || >=26.0.0, so `npm install -g npm@latest` on Node 25 fails with EBADENGINE and the publish job dies before it can publish. Node 24 is supported by every npm 11.x and 12.x, and pinning the upgrade to ^11.5.1 (the floor for OIDC trusted publishing) stops the next npm major doing this again. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw --- .github/workflows/npmpublish.yml | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/.github/workflows/npmpublish.yml b/.github/workflows/npmpublish.yml index 2471127..cd7c09f 100644 --- a/.github/workflows/npmpublish.yml +++ b/.github/workflows/npmpublish.yml @@ -20,13 +20,17 @@ jobs: steps: - uses: actions/setup-node@v7 with: - # OIDC trusted publishing needs npm >= 11.5.1, which requires - # Node >= 20.17.0. setup-node's `20` resolves to the latest - # 20.x, which satisfies that. - node-version: 25 + # OIDC trusted publishing needs npm >= 11.5.1. Node 24 is an LTS + # line that every npm 11.x and 12.x supports; Node 25 is not — + # npm 12 requires ^22.22.2 || ^24.15.0 || >=26.0.0, so on Node 25 + # the upgrade step below died with EBADENGINE and no plugin could + # publish. + node-version: 24 registry-url: https://registry.npmjs.org/ + # Pinned to a range rather than @latest: the next npm major dropping + # this Node line would silently break publishing fleet-wide again. - name: Upgrade npm to >=11.5.1 (required for trusted publishing) - run: npm install -g npm@latest + run: npm install -g npm@^11.5.1 - name: Check out Etherpad core uses: actions/checkout@v7 with: