Skip to content

fix(publish-npm)!: stop installing npm at runtime and default to node 24 - #184

Merged
PierreJeanjacquot merged 3 commits into
mainfrom
fix/drop-dynamic-npm-install
Oct 6, 2026
Merged

PierreJeanjacquot merged 3 commits into
mainfrom
fix/drop-dynamic-npm-install

Conversation

@PierreJeanjacquot

Copy link
Copy Markdown
Member

The workflow upgraded npm with an unpinned npm install -g npm@11 when the bundled npm was too old for OIDC trusted publishing. Node.js >= 24.5.0 ships npm >= 11.5.1, so the workflow now defaults to node 24 and fails early with an explicit message instead of installing npm. The semver check is also pinned to semver@7.8.5, which has no dependencies.

BREAKING CHANGE: the default node-version is now 24 instead of 20. Callers using OIDC trusted publishing must use Node.js >= 24.5.0: npm is no longer upgraded automatically.

PierreJeanjacquot added a commit that referenced this pull request Oct 5, 2026
The unpinned `npm install -g npm@11` is removed by #184, which is a breaking change shipped separately.
PierreJeanjacquot added a commit that referenced this pull request Oct 5, 2026
The unpinned `npm install -g npm@11` is removed by #184, which is a breaking change shipped separately.
PierreJeanjacquot added a commit that referenced this pull request Oct 5, 2026
The unpinned `npm install -g npm@11` is removed by #184, which is a breaking change shipped separately.
PierreJeanjacquot added a commit that referenced this pull request Oct 5, 2026
The unpinned `npm install -g npm@11` is removed by #184, which is a breaking change shipped separately.
PierreJeanjacquot added a commit that referenced this pull request Oct 5, 2026
The unpinned `npm install -g npm@11` is removed by #184, which is a breaking change shipped separately.
@PierreJeanjacquot
PierreJeanjacquot force-pushed the fix/drop-dynamic-npm-install branch from 705d36f to 0aac729 Compare October 5, 2026 15:40
@PierreJeanjacquot
PierreJeanjacquot marked this pull request as ready for review October 5, 2026 15:49
abbesBenayache
abbesBenayache previously approved these changes Oct 6, 2026
The workflow upgraded npm with an unpinned `npm install -g npm@11` when the bundled npm was too old for OIDC trusted publishing. Node.js >= 24.5.0 ships npm >= 11.5.1, so the workflow now defaults to node 24 and fails early with an explicit message instead of installing npm. The semver check is also pinned to semver@7.8.5, which has no dependencies.

BREAKING CHANGE: the default node-version is now 24 instead of 20. Callers using OIDC trusted publishing must use Node.js >= 24.5.0: npm is no longer upgraded automatically.
@PierreJeanjacquot
PierreJeanjacquot force-pushed the fix/drop-dynamic-npm-install branch from 0aac729 to 689ca63 Compare October 6, 2026 12:33
PierreJeanjacquot added a commit that referenced this pull request Oct 6, 2026
The unpinned `npm install -g npm@11` is removed by #184, which is a breaking change shipped separately.
The error now matches the README warning: it shows the current npm and Node.js versions, says how to fix it (use a compatible `node-version` or provide the `npm-token` secret), and appears as an error annotation on the workflow run.
jbern0rd
jbern0rd previously approved these changes Oct 6, 2026
@PierreJeanjacquot
PierreJeanjacquot merged commit 486fdd6 into main Oct 6, 2026
4 checks passed
@PierreJeanjacquot
PierreJeanjacquot deleted the fix/drop-dynamic-npm-install branch October 6, 2026 13:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants