Skip to content

ci: publish on Node 24 with a pinned npm - #125

Merged
JohnMcLear merged 1 commit into
mainfrom
ci/fix-publish-node
Sep 21, 2026
Merged

JohnMcLear merged 1 commit into
mainfrom
ci/fix-publish-node

Conversation

@JohnMcLear

Copy link
Copy Markdown
Member

The bug

publish-npm ran on node-version: 25 and then npm install -g npm@latest.
npm 12 requires ^22.22.2 || ^24.15.0 || >=26.0.0 — Node 25 is excluded — so
the upgrade step died and this package could never be published:

npm error code EBADENGINE
npm error Not compatible with your version of node/npm: npm@12.0.2
npm error Required: {"node":"^22.22.2 || ^24.15.0 || >=26.0.0"}
npm error Actual:   {"node":"v25.9.0","npm":"11.12.1"}

The fix

  • node-version: 25 → 24 (an LTS line every npm 11.x and 12.x supports).
  • npm@latest → npm@^11.5.1 — a range, not @latest, so the next npm major
    dropping this Node line can't silently break publishing fleet-wide again.
    11.5.1 is the minimum for OIDC trusted publishing.
  • Replaced the stale comment that still described Node 20.x.

No other change. Same fix as the merged pilot, ether/ep_align#227.

🤖 Generated with Claude Code

https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw

The publish-npm job ran on `node-version: 25` and then did
`npm install -g npm@latest`. npm 12 requires
`^22.22.2 || ^24.15.0 || >=26.0.0`, which excludes Node 25, so the
upgrade step died with EBADENGINE and the package could never be
published:

    npm error code EBADENGINE
    npm error Not compatible with your version of node/npm: npm@12.0.2
    npm error Required: {"node":"^22.22.2 || ^24.15.0 || >=26.0.0"}
    npm error Actual:   {"node":"v25.9.0","npm":"11.12.1"}

Move to Node 24, an LTS line supported by every npm 11.x and 12.x, and
pin the upgrade to `npm@^11.5.1` — a range rather than `@latest`, so the
next npm major dropping this Node line cannot silently break publishing
fleet-wide again. 11.5.1 is the minimum for OIDC trusted publishing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Fix npm publishing with Node 24 and a compatible npm range

🐞 Bug fix ⚙️ Configuration changes 🕐 Less than 5 minutes

Grey Divider

AI Description

• Moves npm publishing from unsupported Node 25 to the Node 24 LTS line.
• Constrains npm upgrades to version 11 while preserving OIDC trusted publishing support.
Diagram

graph TD
  A["Publish workflow"] -->|selects| B["Node 24 LTS"] -->|supports| C["npm 11.x"] -->|OIDC publish| D["npm registry"]
Loading
High-Level Assessment

The chosen approach is appropriate: Node 24 is an LTS runtime compatible with the required npm versions, while npm@^11.5.1 prevents an incompatible future major from being installed. An exact npm patch would reduce exposure further but unnecessarily block compatible npm 11 fixes; retaining npm@latest would preserve the original failure mode.

Files changed (1) +9 / -5

Bug fix (1) +9 / -5
npmpublish.ymlUse compatible Node and npm versions for trusted publishing +9/-5

Use compatible Node and npm versions for trusted publishing

• Changes the publishing runtime from Node 25 to Node 24 LTS and constrains npm installation to '^11.5.1'. The comments now document the Node 25 engine incompatibility and explain why npm is major-version constrained.

.github/workflows/npmpublish.yml

@JohnMcLear
JohnMcLear merged commit 70ab519 into main Sep 21, 2026
4 checks passed
@JohnMcLear
JohnMcLear deleted the ci/fix-publish-node branch September 21, 2026 09:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant