Repository navigation
fix(publish-npm)!: stop installing npm at runtime and default to node 24 - #184
Merged
Merged
Conversation
PierreJeanjacquot
added a commit
that referenced
this pull request
Oct 5, 2026
The unpinned `npm install -g npm@11` is removed by #184, which is a breaking change shipped separately.
PierreJeanjacquot
added a commit
that referenced
this pull request
Oct 5, 2026
The unpinned `npm install -g npm@11` is removed by #184, which is a breaking change shipped separately.
PierreJeanjacquot
added a commit
that referenced
this pull request
Oct 5, 2026
The unpinned `npm install -g npm@11` is removed by #184, which is a breaking change shipped separately.
PierreJeanjacquot
added a commit
that referenced
this pull request
Oct 5, 2026
The unpinned `npm install -g npm@11` is removed by #184, which is a breaking change shipped separately.
PierreJeanjacquot
added a commit
that referenced
this pull request
Oct 5, 2026
The unpinned `npm install -g npm@11` is removed by #184, which is a breaking change shipped separately.
PierreJeanjacquot
force-pushed
the
fix/drop-dynamic-npm-install
branch
from
October 5, 2026 15:40
705d36f to
0aac729
Compare
PierreJeanjacquot
marked this pull request as ready for review
October 5, 2026 15:49
abbesBenayache
previously approved these changes
Oct 6, 2026
The workflow upgraded npm with an unpinned `npm install -g npm@11` when the bundled npm was too old for OIDC trusted publishing. Node.js >= 24.5.0 ships npm >= 11.5.1, so the workflow now defaults to node 24 and fails early with an explicit message instead of installing npm. The semver check is also pinned to semver@7.8.5, which has no dependencies. BREAKING CHANGE: the default node-version is now 24 instead of 20. Callers using OIDC trusted publishing must use Node.js >= 24.5.0: npm is no longer upgraded automatically.
PierreJeanjacquot
force-pushed
the
fix/drop-dynamic-npm-install
branch
from
October 6, 2026 12:33
0aac729 to
689ca63
Compare
PierreJeanjacquot
added a commit
that referenced
this pull request
Oct 6, 2026
The unpinned `npm install -g npm@11` is removed by #184, which is a breaking change shipped separately.
The error now matches the README warning: it shows the current npm and Node.js versions, says how to fix it (use a compatible `node-version` or provide the `npm-token` secret), and appears as an error annotation on the workflow run.
jbern0rd
previously approved these changes
Oct 6, 2026
jbern0rd
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The workflow upgraded npm with an unpinned
npm install -g npm@11when the bundled npm was too old for OIDC trusted publishing. Node.js >= 24.5.0 ships npm >= 11.5.1, so the workflow now defaults to node 24 and fails early with an explicit message instead of installing npm. The semver check is also pinned to semver@7.8.5, which has no dependencies.BREAKING CHANGE: the default node-version is now 24 instead of 20. Callers using OIDC trusted publishing must use Node.js >= 24.5.0: npm is no longer upgraded automatically.