Skip to content

Derive npm dist-tag from package major in publish workflow - #79

Merged
vigneshwerv merged 3 commits into
devfrom
fix/publish-dist-tag
Sep 25, 2026
Merged

vigneshwerv merged 3 commits into
devfrom
fix/publish-dist-tag

Conversation

@vigneshwerv

Copy link
Copy Markdown
Contributor

publish.yml ran a bare npm publish, which always moves the latest dist-tag to whatever version is being published.

That is wrong for maintenance releases on an older major: publishing 1.5.1 from the v1 line would point latest at it, pulling every npm install @fragment-dev/node-client back from 2.1.0 to 1.5.1.

This compares the package major against the current latest major and publishes older majors under a v<major> tag instead.

Verified against the live registry:

package version resolved dist-tag
1.5.1 v1
2.2.0 latest
3.0.0 latest

Needed by the pending v1.5.1 backport release (branch release/v1.5.1).

publish.yml ran a bare `npm publish`, which always moves the 'latest' dist-tag
to whatever version is being published. That is wrong for maintenance releases
on an older major: publishing 1.5.1 would have pointed 'latest' at it and
pulled every `npm install @fragment-dev/node-client` back to the v1 line.

Compare the package major against the current 'latest' major and publish older
majors under a 'v<major>' tag instead.
npm rejects dist-tags that parse as SemVer ranges, so the "v$MAJOR" form
this branch originally used fails outright:

  npm error Tag name must not be a valid SemVer range: v1

"v1" parses as ">=1.0.0 <2.0.0". So do "1.x" and "v1.x". Suffixing with
"-legacy" keeps the tag readable while remaining a valid tag name, and
matches the tag 1.5.0 was published under.

Claude-Session: https://claude.ai/code/session_01XAMVwbhshgNFmGj4sL18x7
@vigneshwerv

Copy link
Copy Markdown
Contributor Author

Corrected — the original logic would have failed at the publish step.

npm rejects dist-tags that parse as SemVer ranges:

npm error Tag name must not be a valid SemVer range: v1

v1 parses as >=1.0.0 <2.0.0, and so do 1.x and v1.x. Switched to v${MAJOR}-legacy, which matches the tag 1.5.0 was actually published under.

Verified against the live registry:

version resolved tag npm
1.5.1 v1-legacy accepts
1.6.0 v1-legacy accepts
2.4.0 latest accepts
3.0.0 latest accepts

Context: 1.5.0 shipped from the new v1 branch (#92) and is on npm under v1-legacy, with latest still 2.3.0. That publish was run from the command line, so this workflow path is still unexercised — worth having correct before the next older-major release goes through CI.

https://claude.ai/code/session_01XAMVwbhshgNFmGj4sL18x7

@vigneshwerv
vigneshwerv enabled auto-merge (squash) September 25, 2026 20:37
@vigneshwerv
vigneshwerv merged commit 02c2d5b into dev Sep 25, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants