Skip to content

ci: publish on Node 24 with a pinned npm - #46

Merged
JohnMcLear merged 1 commit into
mainfrom
ci/fix-publish-node
Sep 21, 2026
Merged

JohnMcLear merged 1 commit into
mainfrom
ci/fix-publish-node

Conversation

@JohnMcLear

Copy link
Copy Markdown
Member

.github/workflows/npmpublish.yml ran the publish job on Node 25 and then
did npm install -g npm@latest. npm 12 requires
^22.22.2 || ^24.15.0 || >=26.0.0 — Node 25 is excluded — so that step died
with EBADENGINE and the package could never be published:

npm error code EBADENGINE
npm error Not compatible with your version of node/npm: npm@12.0.2
npm error Required: {"node":"^22.22.2 || ^24.15.0 || >=26.0.0"}
npm error Actual:   {"node":"v25.9.0","npm":"11.12.1"}

Move the job to Node 24 (an LTS line supported by every npm 11.x and 12.x)
and pin the upgrade to npm@^11.5.1 — a range rather than @latest, so the
next npm major dropping this Node line can't silently break publishing
fleet-wide again. >=11.5.1 is what OIDC trusted publishing needs.

Same fix as ether/ep_align#227.

🤖 Generated with Claude Code

https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw

The publish job ran on Node 25 and then did `npm install -g npm@latest`.
npm 12 requires ^22.22.2 || ^24.15.0 || >=26.0.0 — Node 25 is excluded — so
the upgrade step died with EBADENGINE and the package could never publish:

    npm error code EBADENGINE
    npm error Not compatible with your version of node/npm: npm@12.0.2
    npm error Required: {"node":"^22.22.2 || ^24.15.0 || >=26.0.0"}
    npm error Actual:   {"node":"v25.9.0","npm":"11.12.1"}

Move to Node 24, an LTS line every npm 11.x and 12.x supports, and pin the
upgrade to npm@^11.5.1 rather than @latest so the next npm major dropping
this Node line cannot silently break publishing fleet-wide again.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Restore npm publishing with Node 24 and pinned npm 11

🐞 Bug fix ⚙️ Configuration changes 🕐 Less than 5 minutes

Grey Divider

AI Description

• Run npm publishing on Node 24 to restore CLI engine compatibility.
• Pin npm to compatible 11.x releases while meeting OIDC trusted publishing requirements.
Diagram

graph TD
  A["Publish Job"] -->|selects| B["Node 24"] -->|runs| C["npm 11.x"] -->|publishes via OIDC| D["npm Registry"]
Loading
High-Level Assessment

The chosen approach is appropriate: Node 24 provides an LTS runtime compatible with the required npm versions, while the npm 11 caret range receives compatible fixes without unexpectedly crossing into npm 12. Relying on bundled npm could violate the OIDC minimum, and an exact npm pin would unnecessarily exclude patch updates.

Files changed (1) +9 / -5

Bug fix (1) +9 / -5
npmpublish.ymlUse Node 24 with a constrained npm 11 upgrade +9/-5

Use Node 24 with a constrained npm 11 upgrade

• Moves the publishing job from unsupported Node 25 to the Node 24 LTS line. Replaces npm’s unbounded latest upgrade with 'npm@^11.5.1', preserving trusted publishing support while preventing incompatible major upgrades.

.github/workflows/npmpublish.yml

@JohnMcLear
JohnMcLear merged commit 525e551 into main Sep 21, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant