ci: publish on Node 24 with a pinned npm - #105
Conversation
The publish-npm job ran on `node-version: 25` and then did
`npm install -g npm@latest`. npm 12 requires
`^22.22.2 || ^24.15.0 || >=26.0.0`, which excludes Node 25, so the
upgrade step died with EBADENGINE and the package could never be
published:
npm error code EBADENGINE
npm error Not compatible with your version of node/npm: npm@12.0.2
npm error Required: {"node":"^22.22.2 || ^24.15.0 || >=26.0.0"}
npm error Actual: {"node":"v25.9.0","npm":"11.12.1"}
Move to Node 24, an LTS line supported by every npm 11.x and 12.x, and
pin the upgrade to `npm@^11.5.1` — a range rather than `@latest`, so the
next npm major dropping this Node line cannot silently break publishing
fleet-wide again. 11.5.1 is the minimum for OIDC trusted publishing.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
|
ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing |
PR Summary by QodoFix npm publishing with Node 24 and bounded npm 11
AI Description
Diagram
High-Level Assessment
Files changed (1)
|
Code Review by Qodo
1. Publishing remains unprotected by regression tests
|
| # OIDC trusted publishing needs npm >= 11.5.1. Node 24 is an LTS | ||
| # line that every npm 11.x and 12.x supports; Node 25 is not — | ||
| # npm 12 requires ^22.22.2 || ^24.15.0 || >=26.0.0, so on Node 25 | ||
| # the upgrade step below died with EBADENGINE and no plugin could | ||
| # publish. | ||
| node-version: 24 | ||
| registry-url: https://registry.npmjs.org/ | ||
| # Pinned to a range rather than @latest: the next npm major dropping | ||
| # this Node line would silently break publishing fleet-wide again. | ||
| - name: Upgrade npm to >=11.5.1 (required for trusted publishing) | ||
| run: npm install -g npm@latest | ||
| run: npm install -g npm@^11.5.1 |
There was a problem hiding this comment.
1. Publishing remains unprotected by regression tests 📘 Rule violation ▣ Testability
The workflow changes the Node.js version and npm upgrade range to fix a failed publishing path, but the pull request adds or updates no automated test for the incompatible-runtime scenario. A future Node or npm change can reintroduce the engine failure without a test exercising the publishing setup.
Agent Prompt
## Issue description
The publishing workflow fixes an npm and Node.js engine incompatibility, but no automated regression test covers the previously failing setup.
## Fix Focus Areas
- .github/workflows/npmpublish.yml[23-33]
## Recommended Fix
Add an appropriate automated workflow or configuration test that exercises the publishing job with the supported Node.js version and npm range, and asserts that the selected npm version is compatible with that runtime and the trusted-publishing requirement.
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
The bug
publish-npmran onnode-version: 25and thennpm install -g npm@latest.npm 12 requires
^22.22.2 || ^24.15.0 || >=26.0.0— Node 25 is excluded — sothe upgrade step died and this package could never be published:
The fix
node-version: 25→24(an LTS line every npm 11.x and 12.x supports).npm@latest→npm@^11.5.1— a range, not@latest, so the next npm majordropping this Node line can't silently break publishing fleet-wide again.
11.5.1 is the minimum for OIDC trusted publishing.
No other change. Same fix as the merged pilot, ether/ep_align#227.
🤖 Generated with Claude Code
https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw