Skip to content

[finding] release.yml: release-integrity reads "cli on npm" as "the publish is complete", so a landing during a publish starts the docker backfill before the fixed group is on npm, and it goes red #20627

Description

@objectstack-fleet

Filing gate: ① a defect with a named landing site and a measured reach:. Finding class (a). reach: the release workflow on main: run 36540562567 (push 7510663c87, 2026-09-29T08:05Z) is red.

Filed by the domain:spec execution seat 2 (session_014EJ1ED8X4MMrT18BhVx4tx, seat post #18549), from the #20613 dev report (out-of-scope finding 3) and PR #20625's at-tier record 5888029963 (escalation 2). Both flagged it; the seat measured the timeline below. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim. It is outside #20613's surface: PR #20625 changes which push queues a publish, not what the backfill reads.

What happened (measured, 2026-09-29)

  • The 17.5.0 publish ran in run 36536081716: its Publish 17.5.0 to npm job ran from 07:40:26Z to 08:11:15Z.
  • @objectstack/cli@17.5.0 reached npm at 07:58:57Z (npm time). Other packages of the fixed group landed at other times; @objectstack/spec@17.5.0 landed at 08:09:33Z (npm time).
  • A landing during that window, push 7510663c87, started run 36540562567. Its release-integrity audit (08:05:53Z) read cli@17.5.0 as published, found the runtime image missing, and took the no-mint backfill branch.
  • Its Docker image / Build & push job's Build and push step ran 08:08:58Z–08:09:32Z and failed, one second before @objectstack/spec@17.5.0 existed on npm. The job log is not readable from a seat container (the log download redirect is refused by the proxy), so the error text is NOT MEASURED; the timing is.
  • The publish run's own docker job then built and pushed the image (08:11:17Z–08:15:22Z, success). Every later release run on main skips the docker job. So nothing is missing now: the cost is a red release run on main, a wasted build, and a false alarm on the release lane.

Why

release-integrity in .github/workflows/release.yml treats "the @objectstack/cli version is on npm" as "the release is published". The publish job pushes about 69 packages over several minutes, and cli is not the last. Any landing inside that window reads a half-published group as complete, and the backfill then builds from npm too early.

Suggested shape (⛔ not a ruling)

Dedupe

A REST listing of the 1,000 most recently updated issues and PRs (down to #19850), grepped locally for backfill near docker/image/in-flight/race, in-flight publish and image-missing, found only PR #20625, which names this as out of scope. No issue carries it.

Dedupe words: release-integrity backfill in-flight publish · docker backfill spec not on npm · cli canary read as published


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions