ci: publish on Node 24 with a pinned npm - #94
Conversation
The publish job ran on Node 25 and then did `npm install -g npm@latest`.
npm 12 requires ^22.22.2 || ^24.15.0 || >=26.0.0 — Node 25 is excluded — so
the upgrade step died with EBADENGINE and the package could never publish:
npm error code EBADENGINE
npm error Not compatible with your version of node/npm: npm@12.0.2
npm error Required: {"node":"^22.22.2 || ^24.15.0 || >=26.0.0"}
npm error Actual: {"node":"v25.9.0","npm":"11.12.1"}
Move to Node 24, an LTS line every npm 11.x and 12.x supports, and pin the
upgrade to npm@^11.5.1 rather than @latest so the next npm major dropping
this Node line cannot silently break publishing fleet-wide again.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
|
ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing |
Code Review by Qodo
1. Publishing has no regression test
|
| # OIDC trusted publishing needs npm >= 11.5.1. Node 24 is an LTS | ||
| # line that every npm 11.x and 12.x supports; Node 25 is not — | ||
| # npm 12 requires ^22.22.2 || ^24.15.0 || >=26.0.0, so on Node 25 | ||
| # the upgrade step below died with EBADENGINE and no plugin could | ||
| # publish. | ||
| node-version: 24 | ||
| registry-url: https://registry.npmjs.org/ | ||
| # Pinned to a range rather than @latest: the next npm major dropping | ||
| # this Node line would silently break publishing fleet-wide again. | ||
| - name: Upgrade npm to >=11.5.1 (required for trusted publishing) | ||
| run: npm install -g npm@latest | ||
| run: npm install -g npm@^11.5.1 |
There was a problem hiding this comment.
1. Publishing has no regression test 📘 Rule violation ▣ Testability
The workflow changes the publish runtime and npm version range without adding or updating an automated test for the previously failing publish path. A future Node or npm compatibility change can therefore reintroduce the EBADENGINE failure without a test detecting it before publishing is blocked.
Agent Prompt
## Issue description
The publish workflow bug fix changes the Node and npm versions but adds no automated regression coverage for the compatibility failure described in the PR.
## Fix Focus Areas
- .github/workflows/npmpublish.yml[23-33]
## Recommended Fix
Add or update an automated workflow validation test that exercises the publish setup with Node 24 and verifies the configured npm range satisfies the trusted-publishing minimum without resolving to an incompatible npm major. Name the test after the Node/npm compatibility regression and ensure it would fail against the previous Node 25 plus `npm@latest` configuration.
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
PR Summary by QodoFix npm publishing with Node 24 and pinned npm 11
AI Description
Diagram
High-Level Assessment
Files changed (1)
|
.github/workflows/npmpublish.ymlran the publish job on Node 25 and thendid
npm install -g npm@latest. npm 12 requires^22.22.2 || ^24.15.0 || >=26.0.0— Node 25 is excluded — so that step diedwith
EBADENGINEand the package could never be published:Move the job to Node 24 (an LTS line supported by every npm 11.x and 12.x)
and pin the upgrade to
npm@^11.5.1— a range rather than@latest, so thenext npm major dropping this Node line can't silently break publishing
fleet-wide again.
>=11.5.1is what OIDC trusted publishing needs.Same fix as ether/ep_align#227.
🤖 Generated with Claude Code
https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw