Repository navigation
ci: validate the npm tarball with pack instead of a publish dry run - #129
Merged
Merged
Conversation
Since npm 12, `npm publish --dry-run` checks the registry first and refuses a version that is already published. The publish job upgrades to npm@latest, so every workflow_dispatch rehearsal on a released version now fails at that step even though nothing is wrong with the package. `npm pack --dry-run` prints the same tarball listing without talking to the registry; the real publish still refuses a duplicate.
JeanExtreme002
force-pushed
the
ci/publish-dry-run-pack
branch
from
October 9, 2026 19:22
4153837 to
c1f7286
Compare
Owner
Author
|
Dry run from this branch, all four jobs green: https://github.com/JeanExtreme002/FlightRadarAPI/actions/runs/37979810482
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The
workflow_dispatchdry run of the publish workflow now fails on the npm side whenever the declared version is already on the registry, which is every rehearsal except the one right before a release. Run 37978908688 is an example:The publish job upgrades to
npm@latestfor trusted publishing, and since npm 12npm publish --dry-runasks the registry whether the version exists before doing anything else. Locally, on npm 10, the same command passes. So the step stopped being a content check and became a duplicate of the real publish's own guard.What
The
Validate package contentsstep runsnpm pack --dry-runinstead. It prints the same tarball listing (name, version, file list, sizes) without contacting the registry. The realnpm publishon release still refuses a duplicate version on its own, so nothing is lost on that path.Verification
A fresh
workflow_dispatchdry run from this branch is linked in the comments.