Skip to content

feat(library-publish): stage and prod catch up on every version dev released before - #15

Merged
igorlamos merged 1 commit into
mainfrom
feat/library-publish-catch-up
Oct 8, 2026
Merged

igorlamos merged 1 commit into
mainfrom
feat/library-publish-catch-up

Conversation

@beplus-agent-claude

@beplus-agent-claude beplus-agent-claude Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Release on dev three times, promote once, and stage and prod got only the third. The promote job published only the versions the promoted commit carries, but a fast-forward promotes the commits in between too, so an app whose lockfile pinned one of the skipped versions on dev could not install it on stage or prod.

The change (promote job)

  • Every earlier version dev released, too. For each package Rush publishes, every version GitHub Packages has that is lower (by semver) than the commit's own, and that this environment's CodeArtifact lacks, is fetched and published byte for byte. dev's newer releases wait for their own promotion.
  • latest never moves back. The earlier versions go out first, oldest first, under a temporary catch-up dist-tag that is removed afterwards. Only the commit's own version becomes latest.
  • A refused earlier version is a warning, not a failed run (one archived there on purpose, say), and the next promotion tries it again. The commit's own version failing still fails the run, as before, but only after every other package has had its turn.
  • prod: the caught-up versions' GitHub releases become full releases with --latest=false, and "Latest" is decided among the commit's own versions, as before. One gh release list finds the pre-releases.
  • The job summary lists what was published.

AWS auth now comes before the GitHub Packages read, because the job has to know what the CodeArtifact has before it knows what to fetch.

README updated.

Tested

Not run on GitHub yet. Locally, the new steps ran against stubbed npm and gh:

  • a gap, with dev ahead of the promoted commit
  • a prerelease line, where next.10 must come after next.3
  • a package already in sync
  • a refused earlier version, and a refused version of the commit itself
  • a re-run
  • a version dev never released
  • a registry error that isn't a 404

Companions

  • 25 library callers triggered only on dev, so fast-forwarding stage or prod never ran this job for them. Each now also triggers on stage and prod, as beplus/analytics already did: beplus/ai#22, beplus/api#4, beplus/auth#23, beplus/aws#6, beplus/billing#3, beplus/cdk#9, beplus/cms#45, beplus/config#6, beplus/data#15, beplus/database#9, beplus/docs#27, beplus/events#3, beplus/messaging#3, beplus/metering#3, beplus/mobile#4, beplus/npm#3, beplus/provisioning#3, beplus/pulse#3, beplus/rush#6, beplus/saas#12, beplus/schema#3, beplus/server#4, beplus/sync#3, beplus/uix#117, beplus/web#4.
  • ci(release): stage and prod catch up on every version dev released before be#9 does the same catch-up in its own release.yml.

After merge

  • Move v2 to the merge commit.
  • Promote each library once (a fast-forward, or Run workflow on stage/prod). The first run catches each registry up.

…eleased before

A fast-forward promotes the commits in between too, but the promote job published
only the versions the promoted commit carries: release on dev three times, promote
once, and stage and prod never got the first two. A lockfile that pinned one of them
on dev did not install there.

Each promotion now also publishes every earlier version dev released (in GitHub
Packages, lower by semver than the commit's own) that the environment's
CodeArtifact lacks, oldest first, under a temporary `catch-up` tag, so `latest`
never moves back. A refused earlier version is a warning the next promotion
retries; prod makes their GitHub releases full releases, never "Latest".

Co-Authored-By: Igor Lamos <igor@be.plus>
@igorlamos
igorlamos merged commit 13d3a57 into main Oct 8, 2026
@igorlamos
igorlamos deleted the feat/library-publish-catch-up branch October 8, 2026 15:42
igorlamos added a commit that referenced this pull request Oct 8, 2026
…test` tag (#17)

The first stage promotions after #15 refused aws, cdk, config and database: "is
not in GitHub Packages, so dev never released it", for versions dev's runs had
published there. Called with a bare name, `npm view` answers only for the
`latest` tag, and a package without one prints nothing, exit 0. dev publishes
with `--tag dev`, so every package dev first published that way (aws-core,
cdk-estate, cdk-release, config, the three database packages) has no `latest` in
GitHub Packages, and its versions read as none.

Each lookup now names a version: GitHub Packages is asked for the version the
commit carries, as the promote job did before #15; CodeArtifact for `latest`,
then that version, then each earlier one dev released, until one matches. A
package with `latest` still costs one call a registry.

Co-authored-by: bea-claude <bea+claude@be.plus>
Co-authored-by: Igor Lamos <igor@be.plus>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants