Skip to content

ci(release): stage and prod catch up on every version dev released before - #9

Merged
igorlamos merged 2 commits into
devfrom
ci/release-catch-up
Oct 8, 2026
Merged

igorlamos merged 2 commits into
devfrom
ci/release-catch-up

Conversation

@beplus-agent-claude

@beplus-agent-claude beplus-agent-claude Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Release twice on dev, promote once, and the first version never reached stage's or prod's CodeArtifact. The promote job published only the version the commit carries, but a fast-forward promotes the commits in between too, so an estate that pinned the skipped version on dev could not install it there.

The change

  • scripts/release/catch-up-codeartifact.sh <version> publishes every earlier version dev released (in GitHub Packages, lower by SemVer) that this environment's CodeArtifact lacks. These are the bytes dev published, oldest first, under a temporary catch-up dist-tag that is removed afterwards, so latest is only ever the commit's version. A version the registry refuses is a warning, and the next promotion tries it again.
  • The promote job runs it before publishing the commit's own version.
  • A leftover catch-up tag is removed too, whether this run set it or an earlier one couldn't remove it. Removing a dist-tag needs codeartifact:PutPackageMetadata, which the npm-publishing roles lack today (beplus/ai's first stage promotion left its tag). Without it, the run stays green with a warning naming the permission, and the next promotion tries again.
  • prod: the earlier versions' GitHub Releases become full releases too, with --latest=false. This version's goes last and is marked latest, as before.
  • The summary lists what was caught up.
  • main is unchanged. The public registry gets only the version its commit carries.
  • docs/releasing.md updated.

The release workflow stays this repository's own. This mirrors what beplus/setup-beplus#15 does for the libraries.

No version bump: bin/be doesn't change, so merging releases nothing.

Before the first promotion

Add codeartifact:PutPackageMetadata to CodeArtifactPolicy in bepluscloud/monorepo's GitHubOIDCStack.ts, the policy every npm-publishing role shares.

Tested

npm run lint passes. Locally, the script ran against stubbed beplus and npm:

  • a gap, with dev ahead of the promoted version
  • a refused version
  • a re-run
  • a registry error
  • a package with a single version
  • a leftover tag the role can't remove, then can

Not run on GitHub yet; the next fast-forward of stage or prod is the first real run.

…fore

A fast-forward promotes the commits in between too, but stage and prod published
only the version the commit carries: release twice on dev, promote once, and the
first never reached stage's or prod's CodeArtifact, so an estate that pinned it on
dev could not install it there.

scripts/release/catch-up-codeartifact.sh publishes, before the commit's own
version, every earlier version dev released (in GitHub Packages, lower by SemVer)
that the environment's CodeArtifact lacks: the bytes dev published, oldest first,
under a temporary `catch-up` dist-tag so `latest` never moves back. A version the
registry refuses is a warning the next promotion retries. prod makes their GitHub
Releases full releases, never marked latest. main is unchanged.

The release workflow stays this repository's own; it follows what
beplus/setup-beplus's library-publish does for the libraries.

Co-Authored-By: Igor Lamos <igor@be.plus>
igorlamos
igorlamos previously approved these changes Oct 8, 2026
…ehind

Removing a dist-tag needs codeartifact:PutPackageMetadata, which the
npm-publishing roles lack (beplus/ai's first stage promotion left its tag), so a
run that caught up could leave `catch-up` behind, and the next one, with nothing to
catch up, did not look for it. The script now reads the tag up front and removes
it whether this run set it or not; the warning names the missing permission.

Co-Authored-By: Igor Lamos <igor@be.plus>
@igorlamos
igorlamos merged commit 028b521 into dev Oct 8, 2026
4 checks passed
@igorlamos
igorlamos deleted the ci/release-catch-up branch October 8, 2026 16:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants