Skip to content

ci: publish on Node 24 with a pinned npm - #113

Merged
JohnMcLear merged 1 commit into
mainfrom
ci/fix-publish-node
Sep 21, 2026
Merged

JohnMcLear merged 1 commit into
mainfrom
ci/fix-publish-node

Conversation

@JohnMcLear

Copy link
Copy Markdown
Member

.github/workflows/npmpublish.yml ran the publish job on Node 25 and then upgraded the global npm with npm install -g npm@latest. Since npm 12 shipped, @latest resolves to a release that requires Node ^22.22.2 || ^24.15.0 || >=26.0.0 — Node 25 is excluded — so the upgrade step dies with EBADENGINE and this plugin cannot publish at all:

npm error code EBADENGINE
npm error Not compatible with your version of node/npm: npm@12.0.2
npm error Required: {"node":"^22.22.2 || ^24.15.0 || >=26.0.0"}
npm error Actual:   {"node":"v25.9.0","npm":"11.12.1"}

This moves the job to Node 24 — an LTS line supported by every npm 11.x and 12.x — and pins the upgrade to npm@^11.5.1 (the floor for OIDC trusted publishing) rather than @latest, so the next npm major dropping this Node line cannot silently break publishing fleet-wide again.

Same change as the already-merged pilot, ether/ep_align#227.

🤖 Generated with Claude Code

https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw

The publish workflow ran on Node 25 and then upgraded the global npm with
`npm install -g npm@latest`. Since npm 12 shipped, `@latest` resolves to a
release that requires Node `^22.22.2 || ^24.15.0 || >=26.0.0` — Node 25 is
excluded — so the upgrade step died with EBADENGINE and publishing was
impossible:

    npm error code EBADENGINE
    npm error Not compatible with your version of node/npm: npm@12.0.2
    npm error Required: {"node":"^22.22.2 || ^24.15.0 || >=26.0.0"}
    npm error Actual:   {"node":"v25.9.0","npm":"11.12.1"}

Move to Node 24, an LTS line supported by every npm 11.x and 12.x, and pin
the upgrade to `npm@^11.5.1` — a range rather than `@latest`, so the next
npm major dropping this Node line cannot silently break publishing again.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Restore npm publishing with Node 24 and pinned npm 11

🐞 Bug fix ⚙️ Configuration changes 🕐 Less than 5 minutes

Grey Divider

AI Description

• Moves publishing from unsupported Node 25 to the Node 24 LTS line.
• Pins npm to major version 11 while retaining trusted publishing support.
• Prevents future npm major releases from silently breaking package publication.
Diagram

graph TD
  W["Publish workflow"] --> N["Node 24 LTS"] --> P["npm 11 range"] --> O["OIDC publishing"] --> R["npm registry"]
Loading
High-Level Assessment

The selected approach is appropriate: Node 24 is an LTS runtime compatible with npm 11 and 12, while constraining npm to ^11.5.1 meets OIDC requirements without inheriting breaking engine constraints from future majors. Using Node 22 or pinning one exact npm patch would provide less forward flexibility without improving reliability.

Files changed (1) +9 / -5

Other (1) +9 / -5
npmpublish.ymlUse Node 24 and constrain npm to version 11 +9/-5

Use Node 24 and constrain npm to version 11

• Changes the publishing runtime from Node 25 to Node 24 to restore npm engine compatibility. Replaces npm@latest with npm@^11.5.1 and documents why the runtime and major version are constrained.

.github/workflows/npmpublish.yml

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

@JohnMcLear
JohnMcLear merged commit c8c90ee into main Sep 21, 2026
3 checks passed
@JohnMcLear
JohnMcLear deleted the ci/fix-publish-node branch September 21, 2026 09:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant