Skip to content

ci: validate the npm tarball with pack instead of a publish dry run - #129

Merged
JeanExtreme002 merged 1 commit into
mainfrom
ci/publish-dry-run-pack
Oct 9, 2026
Merged

JeanExtreme002 merged 1 commit into
mainfrom
ci/publish-dry-run-pack

Conversation

@JeanExtreme002

Copy link
Copy Markdown
Owner

Why

The workflow_dispatch dry run of the publish workflow now fails on the npm side whenever the declared version is already on the registry, which is every rehearsal except the one right before a release. Run 37978908688 is an example:

npm error You cannot publish over the previously published versions: 1.6.3.

The publish job upgrades to npm@latest for trusted publishing, and since npm 12 npm publish --dry-run asks the registry whether the version exists before doing anything else. Locally, on npm 10, the same command passes. So the step stopped being a content check and became a duplicate of the real publish's own guard.

What

The Validate package contents step runs npm pack --dry-run instead. It prints the same tarball listing (name, version, file list, sizes) without contacting the registry. The real npm publish on release still refuses a duplicate version on its own, so nothing is lost on that path.

Verification

A fresh workflow_dispatch dry run from this branch is linked in the comments.

Since npm 12, `npm publish --dry-run` checks the registry first and
refuses a version that is already published. The publish job upgrades
to npm@latest, so every workflow_dispatch rehearsal on a released
version now fails at that step even though nothing is wrong with the
package. `npm pack --dry-run` prints the same tarball listing without
talking to the registry; the real publish still refuses a duplicate.
@JeanExtreme002
JeanExtreme002 force-pushed the ci/publish-dry-run-pack branch from 4153837 to c1f7286 Compare October 9, 2026 19:22
@JeanExtreme002

Copy link
Copy Markdown
Owner Author

Dry run from this branch, all four jobs green: https://github.com/JeanExtreme002/FlightRadarAPI/actions/runs/37979810482

publish-npm now lists the 1.6.3 tarball (17 files) and stops there, as a rehearsal should. The Go tag job reports what it would tag and exits without writing.

@JeanExtreme002
JeanExtreme002 merged commit 971e212 into main Oct 9, 2026
2 checks passed
@github-actions
github-actions Bot deleted the ci/publish-dry-run-pack branch October 9, 2026 19:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant