Repository navigation
ci(release): stage and prod catch up on every version dev released before - #9
Merged
Merged
Conversation
…fore A fast-forward promotes the commits in between too, but stage and prod published only the version the commit carries: release twice on dev, promote once, and the first never reached stage's or prod's CodeArtifact, so an estate that pinned it on dev could not install it there. scripts/release/catch-up-codeartifact.sh publishes, before the commit's own version, every earlier version dev released (in GitHub Packages, lower by SemVer) that the environment's CodeArtifact lacks: the bytes dev published, oldest first, under a temporary `catch-up` dist-tag so `latest` never moves back. A version the registry refuses is a warning the next promotion retries. prod makes their GitHub Releases full releases, never marked latest. main is unchanged. The release workflow stays this repository's own; it follows what beplus/setup-beplus's library-publish does for the libraries. Co-Authored-By: Igor Lamos <igor@be.plus>
igorlamos
previously approved these changes
Oct 8, 2026
…ehind Removing a dist-tag needs codeartifact:PutPackageMetadata, which the npm-publishing roles lack (beplus/ai's first stage promotion left its tag), so a run that caught up could leave `catch-up` behind, and the next one, with nothing to catch up, did not look for it. The script now reads the tag up front and removes it whether this run set it or not; the warning names the missing permission. Co-Authored-By: Igor Lamos <igor@be.plus>
igorlamos
approved these changes
Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release twice on dev, promote once, and the first version never reached stage's or prod's CodeArtifact. The promote job published only the version the commit carries, but a fast-forward promotes the commits in between too, so an estate that pinned the skipped version on dev could not install it there.
The change
scripts/release/catch-up-codeartifact.sh <version>publishes every earlier version dev released (in GitHub Packages, lower by SemVer) that this environment's CodeArtifact lacks. These are the bytes dev published, oldest first, under a temporarycatch-updist-tag that is removed afterwards, solatestis only ever the commit's version. A version the registry refuses is a warning, and the next promotion tries it again.catch-uptag is removed too, whether this run set it or an earlier one couldn't remove it. Removing a dist-tag needscodeartifact:PutPackageMetadata, which thenpm-publishingroles lack today (beplus/ai's first stage promotion left its tag). Without it, the run stays green with a warning naming the permission, and the next promotion tries again.--latest=false. This version's goes last and is marked latest, as before.mainis unchanged. The public registry gets only the version its commit carries.docs/releasing.mdupdated.The release workflow stays this repository's own. This mirrors what beplus/setup-beplus#15 does for the libraries.
No version bump:
bin/bedoesn't change, so merging releases nothing.Before the first promotion
Add
codeartifact:PutPackageMetadatatoCodeArtifactPolicyin bepluscloud/monorepo'sGitHubOIDCStack.ts, the policy everynpm-publishingrole shares.Tested
npm run lintpasses. Locally, the script ran against stubbedbeplusandnpm:Not run on GitHub yet; the next fast-forward of
stageorprodis the first real run.