Skip to content

Fail the release workflow when npm stage publish fails - #19

Merged
ProgramComputer merged 1 commit into
mainfrom
programcomputer/release-stage-failures
Oct 11, 2026
Merged

ProgramComputer merged 1 commit into
mainfrom
programcomputer/release-stage-failures

Conversation

@ProgramComputer

Copy link
Copy Markdown
Owner

The Release workflow's staging step piped npm stage publish into tee under GitHub's default bash -e, which has no pipefail, so a failed publish still passed the step. This sets pipefail on that step, as the workflow's other multi-line steps already do.

What happened

The v1.3.1 Release workflow ran twice. The second run (38112041476) got E409 Conflict ... Cannot stage previously published version "1.3.1" from npm, but finished green, and its "Next steps" summary said the version was staged. Nothing was changed on npm: the first run's stage was the only one, and it was the one approved.

With this change, a failed npm stage publish fails the step, and the "Next steps" summary is skipped because it only runs after the earlier steps succeed.

Other piped commands

Every other piped command in release.yml already runs under set -euo pipefail. Every step in verify-release.yml either sets shell: bash, which GitHub runs with -eo pipefail, or sets pipefail itself. ci.yml has no piped commands.

Verification

  • The step's old and new forms, run under bash -e with a failing command in place of npm: the old form exits 0 and the new form exits 1. With a succeeding command, the new form exits 0.
  • release.yml parses as valid YAML, and the parsed step script starts with set -euo pipefail.
  • The Release workflow itself was not run, because it would stage a package.

@ProgramComputer
ProgramComputer merged commit b5d549e into main Oct 11, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant