Skip to content

fix(nightly): skip a superseded publish, and stamp the version from the commit - #476

Merged
theCodeDrift merged 1 commit into
mainfrom
fix/nightly-superseded-skip
Oct 6, 2026
Merged

theCodeDrift merged 1 commit into
mainfrom
fix/nightly-superseded-skip

Conversation

@theCodeDrift

Copy link
Copy Markdown
Member

A nightly run can be held in waiting on the npm-autopublish environment while a newer commit lands. On 2026-10-06 the run for e8b2153 sat there for 19 minutes with nothing anyone could approve, and de43cf6 landed during the wait. If GitHub had released it, it would have published with --tag latest after the newer nightly, and npm i @taskless/cli-nightly would have installed older code.

What changes

  • Superseded check in the publish step. Right before npm publish, the run reads the published versions and skips if any nightly has a later timestamp, since the newer nightly already contains this commit. Only timestamps are compared, because n.m.k can go down when a changeset is removed. If npm can't be read, the step fails instead of assuming there is nothing newer. The check sits here and not in the gate job because the gate answers before the environment wait, which is when the newer commit arrived.
  • The version is stamped from the commit, not the clock. The old stamp was read after the environment wait, so a stalled run would have stamped itself the newest nightly and passed the check. --print-version now requires --date (git log -1 --format=%cI). Since main is rebase-merge only, stamps follow the order of main. Re-running a commit now produces the same version.
  • The breadcrumb job only runs when a version was actually published, using the new published output. Its label changes from "Built at" to "Committed at". Its existing ordering check now orders by commit as well.
  • OpenSpec nightly-superseded-skip, archived. It adds "A superseded nightly is not published" and restates the version, gate, and announcement requirements in full. I dry-ran the archive first: every prior scenario survives and six are added.

There's still no concurrency group: one with cancel-in-progress could cancel a running publish. A stalled run still shows as waiting until GitHub releases it, but it then publishes nothing, so nobody has to cancel it by hand.

Verification

  • pnpm test:scripts (508 pass), pnpm typecheck, pnpm lint.
  • Ran the publish-step shell locally against the real registry: an older stamp skipped with published=false, a future stamp would have published.
  • hasNewerNightly reads all 180 currently published versions without throwing.

No changeset: CI only.

Fixes #474

…he commit

A nightly run held in `waiting` on npm-autopublish could be released after a
newer commit's nightly published, and its `--tag latest` would roll installers
back to older code. The publish step now asks npm, immediately before
publishing, whether a nightly with a later timestamp exists, and skips if so.

That check is only sound with a commit-date stamp: the old stamp read the clock
after the environment wait, so a stalled run would have minted the newest
timestamp on npm. `--print-version` now requires `--date` (the committer date);
`main` is rebase-merge only, so stamps follow the order of `main`.

The breadcrumb job is gated on the new `published` output, and labels the stamp
as the commit time.
@theCodeDrift
theCodeDrift merged commit c17db89 into main Oct 6, 2026
8 checks passed
@theCodeDrift
theCodeDrift deleted the fix/nightly-superseded-skip branch October 6, 2026 19:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Nightly: a superseded commit's publish still runs, and a stuck one holds nothing back

1 participant