From 50f97513e8ccbb5e9e8363051dcc46b01ab03398 Mon Sep 17 00:00:00 2001 From: Lilleman auf Larv Date: Mon, 28 Sep 2026 03:56:16 +0200 Subject: [PATCH] 36b - review: publish entry matches publish.sh --- docs/decisions.md | 13 ++++++------- publish.sh | 1 - 2 files changed, 6 insertions(+), 8 deletions(-) diff --git a/docs/decisions.md b/docs/decisions.md index 3af8f1b..8321bd6 100644 --- a/docs/decisions.md +++ b/docs/decisions.md @@ -210,8 +210,8 @@ switches on `code` with no `default`. `unsupported-node-shape` — since a code no input reaches is one no consumer can switch on (2026-09-20). - A refusal no spelling recovers from is a gap in the flavour rather than a code: give the flavour - the spelling and the code goes (`unspellable-link`, 2026-09-13). A cause the carry answers gets no code: a mark no spelling writes rides the carry - with its node. + the spelling and the code goes (`unspellable-link`, 2026-09-13). A cause the carry answers gets + no code: a mark no spelling writes rides the carry with its node. ## Which code a cause takes @@ -265,12 +265,11 @@ input reads `message`. 2026-08-23, converging 2026-09-03, the maintainer. Goal 7. Valid while CI on `main` holds the npm token. -`package.json` version on `main` is the source of truth. CI on `main`: tests green and version -differs from npm → publish and tag `vX.Y.Z`. No bump, no deploy; the bump is each shipping PR's -deliberate semver judgment. `publish.sh` is that job. +`package.json` version on `main` is the source of truth. CI on `main`: tests green and the version +not yet on npm → publish and tag `vX.Y.Z`. No bump, no deploy. `publish.sh` is that job. -The publish and the tag each observe their own end state — the version on npm, the tag on the -remote — and neither gates the other, so a run that dies between them converges on the next push +The publish and the tag each check their own end state — the version on npm, the tag on the +remote — so a run that dies between them converges on the next push to `main` rather than leaving npm ahead of the tags. An unanswered registry reads the same as an unpublished version, which npm's own duplicate rejection is what catches. The job rebuilds rather than taking the gate's `dist`: the lockfile is committed, the image is patch-pinned and `tsc` is diff --git a/publish.sh b/publish.sh index 9f4ec89..352d13b 100755 --- a/publish.sh +++ b/publish.sh @@ -30,7 +30,6 @@ fi published=$(leg "ask npmjs for $name@$version ($node_image)" published_version "$name" "$version") tagged=$(leg "ask origin for v$version" git ls-remote --tags origin "v$version") -# Both steps observe their own end state, so a partial run converges on the next push to main. if [ -z "$published" ]; then : "${NPM_TOKEN:?the publish needs NPM_TOKEN}" leg "install ($node_image)" in_image "$node_image" npm ci