Skip to content

fix(ci): stop Release from painting main red after version PRs - #38

Merged
cavewebs merged 1 commit into
mainfrom
cursor/skip-actions-npm-publish-13d4
Oct 7, 2026
Merged

cavewebs merged 1 commit into
mainfrom
cursor/skip-actions-npm-publish-13d4

Conversation

@cavewebs

@cavewebs cavewebs commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Why

After Version Packages #37 (@dashcommerce/core@0.2.2), CI is green on main but Release is red. npm is shipped locally (npm publish --access public from packages/core); Actions is not a working publisher.

Verified on Release run 37460919491 (and the same pattern on #27):

  1. No pending changesets after the version PR merge.
  2. changesets/action logs No changesets found. Attempting to publish any unpublished packages to npm.
  3. It writes .npmrc from NPM_TOKEN and runs bun run release → changeset publish.
  4. npm returns E404 Not Found - PUT https://registry.npmjs.org/@dashcommerce%2fcore — the usual failure when the token cannot publish the scope. The secret is present but unusable, not missing (so an if: secrets.NPM_TOKEN != '' skip would still run and fail).

Pushes that only open/update a Version Packages PR stay green. Merging that PR is what turns main red.

Change

Small, reversible cut of the broken Actions publish path:

  • Keep Release on push to main.
  • Keep changesets/action without publish:, so it still opens/updates Version Packages PRs and exits 0 when there is nothing to version.
  • Drop NPM_TOKEN, NPM_CONFIG_PROVENANCE, id-token: write, registry-url, and createGithubReleases (all publish-only).
  • Document local publish in .changeset/README.md.

bun run release in root package.json is unchanged for anyone who wants to publish from a logged-in machine.

Not in this PR

  • No NPM_TOKEN refresh/rotation.
  • No changes to Sync starter token handling.
  • Does not claim Actions published anything.

Reverse

Restore publish: bun run release, NPM_TOKEN, and provenance on the changesets/action step if Actions npm auth is ever wired up for real.

After merge

The next main push runs Release without changeset publish, so the default branch check should go green. Version Packages PRs keep working the same way; npm still ships locally.

Open in Web Open in Cursor 

The Release workflow still ran changeset publish after Version Packages
merges. Actions NPM_TOKEN cannot publish @dashcommerce/* (npm E404), so
main showed red even when CI was green.

Keep Changesets Version Packages PRs; ship npm locally.

Co-authored-by: Timchosen Uzua <timchosen@gmail.com>
@cavewebs
cavewebs marked this pull request as ready for review October 7, 2026 11:28
@cavewebs
cavewebs merged commit 09fe7ce into main Oct 7, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants