You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
EQL 3.0.6 reached npm and crates.io from stack on 2 October 2026, but its GitHub release and Docker image were never built. This issue builds them, and fixes the two faults in release.yml that skipped them. Do it after the cutover of the stack crates import, so that stack main does not move on freeze day.
The release published every package, but skipped the EQL assets
Version Packages PR #938 merged at 07:27 UTC on 2 October 2026. Its Release JS run, 36978691809, published 15 npm packages, all with provenance that names cipherstash/stack and release.yml. Release eql-bindings published eql-bindings 3.0.6 to crates.io.
Three jobs in the Release JS run were skipped:
Build and attach the EQL SQL release, which creates the eql-3.0.6 tag and GitHub release with the SQL assets;
Build and attach the EQL docs bundle;
Dispatch the Postgres + EQL image build, which builds ghcr.io/cipherstash/postgres-eql for 3.0.6.
So there is no eql-3.0.6 tag, no GitHub release with the SQL and docs, and no 3.0.6 image. stash eql install is not affected, because it reads the SQL from the @cipherstash/eql npm package.
Two faults caused it
changeset publishraces the FFI publish. The publish-ffi job published all seven @cipherstash/protect-ffi packages at 0.33.0. npm answered that each one "may take a few minutes to become available". About a minute later, the release job's changeset publish could not yet see the wrapper or the musl package, so it tried to publish them again. npm refused both with E402 Payment Required, because changeset publish uses restricted access for them. Nothing was published twice, but the release job failed.
The publish-auth job has the same shape. Since ci: arm publishing for @cipherstash/auth and the stack-* crates #1009 merged on 2 October 2026, it publishes the seven @cipherstash/auth packages with npm publish. The release job, which needs it, then runs changeset publish over the same packages. So an auth release can fail in the same way.
The EQL jobs depend on thereleasejob succeeding. They run only when the release job's eql_published output is true. A step after changeset publish sets that output from publishedPackages. When changeset publish fails, that step never runs. A re-run cannot fix it either: a re-run finds nothing left to publish, so eql_published stays false.
Fix both in release.yml
Wait for the FFI and auth packages beforechangeset publish. Poll npm until every version in the published.txt of publish-ffi and of publish-auth is visible, with a timeout. Then changeset publish skips them as already published.
Work outeql_publishedfrom the registry and the tags, not from this run. Treat EQL as needing its assets when @cipherstash/eql at the tree's version is on npm, but the eql-<version> tag does not exist. Compute it in a step that runs even when changeset publish fails.
With the second change, the next push to main after the fix builds the missing 3.0.6 release and image by itself.
Done when
The fix merges to main, with tests that cover a failed changeset publish, an already-published EQL version, and the wait for both the FFI and the auth packages.
The eql-3.0.6 tag and GitHub release exist, with the SQL and docs assets.
ghcr.io/cipherstash/postgres-eql has its 3.0.6 tags.
A check of the eql-3.0.6 release against the EQL plan's "verify at one version V" item passes: the npm tarball, the crate, the SQL and docs assets and the image tags all name 3.0.6.
#1026 merged on 3 October 2026. It fixed both faults, and a third that it found:
The release job now waits for npm to list every package that publish-ffi and publish-auth published, before changeset publish runs.
A new eql-assets job decides from npm and the git tags whether EQL needs its assets. It runs even when changeset publish fails.
The EQL asset jobs had a hidden success() condition, which skipped them whenever any job up their needs: chain was skipped. They now use !cancelled() and check results explicitly.
The release run on #1026's merge built the missing assets at 23e9af3f, the commit that published 3.0.6:
the eql-3.0.6 tag and GitHub release, with cipherstash-encrypt.sql, cipherstash-encrypt-uninstall.sql and both docs bundles;
ghcr.io/cipherstash/postgres-eql with tags 14-3.0.6, 15-3.0.6, 16-3.0.6 and 17-3.0.6, plus 17, 3.0.6 and latest.
On 2 October 2026, the auth packages hit the same race: in the release of @cipherstash/auth 0.44.1, changeset publish got E402 on three of them. No package was lost.
EQL 3.0.6 reached npm and crates.io from stack on 2 October 2026, but its GitHub release and Docker image were never built. This issue builds them, and fixes the two faults in
release.ymlthat skipped them. Do it after the cutover of the stack crates import, so that stack main does not move on freeze day.The release published every package, but skipped the EQL assets
Version Packages PR #938 merged at 07:27 UTC on 2 October 2026. Its
Release JSrun, 36978691809, published 15 npm packages, all with provenance that namescipherstash/stackandrelease.yml.Release eql-bindingspublishedeql-bindings3.0.6 to crates.io.Three jobs in the
Release JSrun were skipped:Build and attach the EQL SQL release, which creates theeql-3.0.6tag and GitHub release with the SQL assets;Build and attach the EQL docs bundle;Dispatch the Postgres + EQL image build, which buildsghcr.io/cipherstash/postgres-eqlfor 3.0.6.So there is no
eql-3.0.6tag, no GitHub release with the SQL and docs, and no 3.0.6 image.stash eql installis not affected, because it reads the SQL from the@cipherstash/eqlnpm package.Two faults caused it
changeset publishraces the FFI publish. Thepublish-ffijob published all seven@cipherstash/protect-ffipackages at 0.33.0. npm answered that each one "may take a few minutes to become available". About a minute later, thereleasejob'schangeset publishcould not yet see the wrapper or the musl package, so it tried to publish them again. npm refused both withE402 Payment Required, becausechangeset publishuses restricted access for them. Nothing was published twice, but thereleasejob failed.The
publish-authjob has the same shape. Since ci: arm publishing for @cipherstash/auth and the stack-* crates #1009 merged on 2 October 2026, it publishes the seven@cipherstash/authpackages withnpm publish. Thereleasejob, whichneedsit, then runschangeset publishover the same packages. So an auth release can fail in the same way.The EQL jobs depend on the
releasejob succeeding. They run only when thereleasejob'seql_publishedoutput istrue. A step afterchangeset publishsets that output frompublishedPackages. Whenchangeset publishfails, that step never runs. A re-run cannot fix it either: a re-run finds nothing left to publish, soeql_publishedstays false.Fix both in
release.ymlchangeset publish. Poll npm until every version in thepublished.txtofpublish-ffiand ofpublish-authis visible, with a timeout. Thenchangeset publishskips them as already published.eql_publishedfrom the registry and the tags, not from this run. Treat EQL as needing its assets when@cipherstash/eqlat the tree's version is on npm, but theeql-<version>tag does not exist. Compute it in a step that runs even whenchangeset publishfails.With the second change, the next push to main after the fix builds the missing 3.0.6 release and image by itself.
Done when
changeset publish, an already-published EQL version, and the wait for both the FFI and the auth packages.eql-3.0.6tag and GitHub release exist, with the SQL and docs assets.ghcr.io/cipherstash/postgres-eqlhas its 3.0.6 tags.eql-3.0.6release against the EQL plan's "verify at one version V" item passes: the npm tarball, the crate, the SQL and docs assets and the image tags all name 3.0.6.Fixed by #1026
#1026 merged on 3 October 2026. It fixed both faults, and a third that it found:
releasejob now waits for npm to list every package thatpublish-ffiandpublish-authpublished, beforechangeset publishruns.eql-assetsjob decides from npm and the git tags whether EQL needs its assets. It runs even whenchangeset publishfails.success()condition, which skipped them whenever any job up theirneeds:chain was skipped. They now use!cancelled()and check results explicitly.The release run on #1026's merge built the missing assets at
23e9af3f, the commit that published 3.0.6:eql-3.0.6tag and GitHub release, withcipherstash-encrypt.sql,cipherstash-encrypt-uninstall.sqland both docs bundles;ghcr.io/cipherstash/postgres-eqlwith tags14-3.0.6,15-3.0.6,16-3.0.6and17-3.0.6, plus17,3.0.6andlatest.On 2 October 2026, the auth packages hit the same race: in the release of
@cipherstash/auth0.44.1,changeset publishgotE402on three of them. No package was lost.