Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 9 additions & 5 deletions .github/workflows/npmpublish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,13 +20,17 @@ jobs:
steps:
- uses: actions/setup-node@v7
with:
# OIDC trusted publishing needs npm >= 11.5.1, which requires
# Node >= 20.17.0. setup-node's `20` resolves to the latest
# 20.x, which satisfies that.
node-version: 25
# OIDC trusted publishing needs npm >= 11.5.1. Node 24 is an LTS
# line that every npm 11.x and 12.x supports; Node 25 is not —
# npm 12 requires ^22.22.2 || ^24.15.0 || >=26.0.0, so on Node 25
# the upgrade step below died with EBADENGINE and no plugin could
# publish.
node-version: 24
registry-url: https://registry.npmjs.org/
# Pinned to a range rather than @latest: the next npm major dropping
# this Node line would silently break publishing fleet-wide again.
- name: Upgrade npm to >=11.5.1 (required for trusted publishing)
run: npm install -g npm@latest
run: npm install -g npm@^11.5.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

1. Publishing can break unnoticed again 📘 Rule violation ▣ Testability

.github/workflows/npmpublish.yml changes the runtime to Node 24 and replaces npm@latest with
npm@^11.5.1, but this bug-fix changeset adds or modifies no automated test. A later edit that
restores an incompatible Node and npm pairing will not be caught before the publish workflow runs
and can again prevent every plugin from publishing.
Agent Prompt
## Issue description
The publish workflow fixes an incompatible Node and npm combination without adding an automated regression test that fails against the prior configuration.

## Fix Focus Areas
- .github/workflows/npmpublish.yml[28-33]

## Recommended Fix
Add an automated test in this changeset that parses or validates the publish workflow and rejects incompatible Node and npm combinations. Ensure it fails for Node 25 with `npm@latest`, passes for Node 24 with the bounded npm 11 range, and runs in the repository's normal continuous-integration checks.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

- name: Check out Etherpad core
uses: actions/checkout@v7
with:
Expand Down
Loading