fix: correct bundled sigstore from dev dependency conflict - #9740
Merged
Conversation
reggi
approved these changes
Jul 10, 2026
Contributor
|
Thanks for your help on this, we need a check to make sure this doesn't happen again 😢 |
Merged
This was referenced Jul 10, 2026
yihui
added a commit
to yihui/lite.js
that referenced
this pull request
Jul 11, 2026
willem445
added a commit
to willem445/loomux
that referenced
this pull request
Jul 14, 2026
…ug (#275, #186) (#277) Create the tauri-action release as a draft; add a promote job (needs: build) that flips it public only once every matrix leg has uploaded, so `latest` can never resolve to a partial release. publish-npm now waits on promote (not just build), since GitHub won't serve assets off a draft release to anonymous downloads and the npm launcher fetches them at runtime. Un-pin npm past npm@^11: npm/cli#9722 (missing sigstore, breaking provenance publish) was fixed by npm/cli#9740 and shipped in npm 12.0.1 (2026-07-10) — verified by extracting the published tarball and confirming node_modules/sigstore is bundled again. ^12.0.1 tracks future 12.x patches while excluding the broken 12.0.0.
thekevinbot
added a commit
to thekevinscott/putitoutthere
that referenced
this pull request
Jul 16, 2026
npm 12.0.0's published bundle omitted libnpmpublish's unscoped `sigstore` dependency, so every `npm publish --provenance` in the e2e fixture job died at module load (npm/cli#9722). #438/#439 pinned `npm install -g npm@11` as a workaround, with #440 tracking the unpin. npm/cli#9740 fixed the packing bug and shipped in npm 12.0.1 (2026-07-10); the packed tarball again contains `node_modules/sigstore`. `latest` now resolves to 12.0.1. Verified locally with a fresh `npm install -g npm@latest` (→ 12.0.1) that `require.resolve('sigstore', { paths: [libnpmpublish/lib] })` resolves — the exact check that failed on 12.0.0. Kept as an explicit major (npm@12), never floating `npm@latest`, per the #438/#439 contract. The e2e fixture suite going green on this PR is the end-to-end verification. skip-changelog: CI-internal harness pin; no consumer surface Claude-Session: https://claude.ai/code/session_0131HkmhYCFEQCJ4wZcGWABJ Co-authored-by: Claude <noreply@anthropic.com>
github-actions Bot
added a commit
to thekevinscott/putitoutthere
that referenced
this pull request
Jul 16, 2026
ci: unpin e2e npm CLI from npm@11 to npm@12 (closes #440) (#535) npm 12.0.0's published bundle omitted libnpmpublish's unscoped `sigstore` dependency, so every `npm publish --provenance` in the e2e fixture job died at module load (npm/cli#9722). #438/#439 pinned `npm install -g npm@11` as a workaround, with #440 tracking the unpin. npm/cli#9740 fixed the packing bug and shipped in npm 12.0.1 (2026-07-10); the packed tarball again contains `node_modules/sigstore`. `latest` now resolves to 12.0.1. Verified locally with a fresh `npm install -g npm@latest` (→ 12.0.1) that `require.resolve('sigstore', { paths: [libnpmpublish/lib] })` resolves — the exact check that failed on 12.0.0. Kept as an explicit major (npm@12), never floating `npm@latest`, per the #438/#439 contract. The e2e fixture suite going green on this PR is the end-to-end verification. skip-changelog: CI-internal harness pin; no consumer surface Claude-Session: https://claude.ai/code/session_0131HkmhYCFEQCJ4wZcGWABJ Co-authored-by: Claude <noreply@anthropic.com>
This was referenced Jul 20, 2026
VID-20260720-WA0028.mp4 |
Grinv
added a commit
to Grinv/anilist-mcp-server
that referenced
this pull request
Jul 29, 2026
…audit Compared this repo's release.yml/sync-version.mjs against the 3 sibling MCP server repos (tmdb-mcp, steam-games-mcp, mal-mcp) — each had independently invented a different subset of fixes for the same problems. Converging on the best-of-four here: - Add a hard fail-fast gate in release.yml: if CHANGELOG.md's extracted section for this version comes back empty, the workflow now errors instead of silently shipping a blank GitHub Release body. - Pin npm to an exact, verified-good version (12.0.1) before `npm publish --provenance`, instead of relying on whatever ships bundled with actions/setup-node — matches every other tool in this workflow already being pinned to an exact commit/tag. npm 12.0.0 shipped a broken provenance path (npm/cli#9722, "Cannot find module 'sigstore'"), fixed in 12.0.1 (npm/cli#9740). The existing npm-publish idempotency guard (this repo's own invention) is untouched. - Rewrite sync-version.mjs's CHANGELOG-dating logic as a pure, exported, unit-tested function (renderChangelogRelease) instead of an untested inline script — same "is [Unreleased] actually empty" bullet check as before, just extracted so it's independently testable. - scripts/sync-version.d.mts: a hand-written .d.ts for the newly exported function, needed because tsc's Node16 module resolution can't infer types across the src/ project boundary into scripts/ without one.
Grinv
added a commit
to Grinv/mal-mcp
that referenced
this pull request
Jul 29, 2026
A re-run tag push or a manually-bootstrapped version would make npm
publish hard-fail on a duplicate version and abort the job before the
MCP Registry steps ever ran. Add a check-if-published step and gate
the publish step on it.
npm 12.0.0's provenance bug ("Cannot find module 'sigstore'",
npm/cli#9722) is fixed in 12.0.1 (npm/cli#9740, released 2026-07-10),
now npm's current latest — bump the pin and correct the stale comment.
Grinv
added a commit
to Grinv/tmdb-mcp
that referenced
this pull request
Jul 30, 2026
…repo audit Compared this repo's release.yml/sync-version.mjs against the 3 sibling MCP server repos (steam-games-mcp, mal-mcp, anilist-mcp-server) — each had independently invented a different subset of fixes for the same problems, at different times. Converging on the best-of-four here: - Add a hard fail-fast gate in release.yml: if CHANGELOG.md's extracted section for this version comes back empty, the workflow now errors instead of silently shipping a blank GitHub Release body (mal-mcp already had this after its own 2026-07-29 incident; the other 3 repos, including this one, didn't). - Add an npm-publish idempotency guard: skip (not fail) `npm publish` if this version is already on npm, so a tag re-run doesn't abort the job before the MCP Registry publish steps run (anilist-mcp-server's own fix, otherwise unique to it). - Pin npm to an exact, verified-good version (12.0.1) instead of a stale defensive pin (11.18.0) or a floating `@latest` — matches every other tool in this workflow already being pinned to an exact commit/tag (actions/checkout, actions/setup-node, gh-release). Verified live: npm/cli#9722 (the "Cannot find module 'sigstore'" provenance bug in 12.0.0) was fixed in 12.0.1 (npm/cli#9740, 2026-07-10), which is npm's current `latest` dist-tag. - Rewrite sync-version.mjs's CHANGELOG-dating logic as a pure, exported, unit-tested function (renderChangelogRelease, mirroring mal-mcp's design) instead of an untested inline script — and make its "is [Unreleased] actually empty" check robust to stray blank lines (checks for a real `- ` bullet, per anilist-mcp-server's more careful version, instead of just "a heading immediately follows"). - scripts/sync-version.d.mts: a hand-written .d.ts for the newly exported function, needed because tsc's Node16 module resolution can't infer types across the src/ project boundary into scripts/ without one (mal-mcp already needed and has this same file).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR fixes #9722.
mock-registrypinned@npmcli/arborist@^9.1.2, which meant the local workspace version wasn't linked and the dependency was pulled from the registry instead.sigstore@^4got installed at the root node_modules and^5was put intoworkspaces/libnpmpublish/node_modules. The dev-only^4was then excluded when npm was packed.Fix:
mock-registry: arborist^9.1.2->^10.0.0workspaces/arborist: validate-npm-package-name^7.0.2->^8.0.0(need to release a patch for arborist)node . run dependenciesThe packed tarball now contains
package/node_modules/sigstoreandpublish --dry-runfrom the extracted tarball succeeds.