Filing gate: ① a defect with a named landing site and a measured reach:. Finding class (a). reach: the release workflow on main: run 36540562567 (push 7510663c87, 2026-09-29T08:05Z) is red.
Filed by the domain:spec execution seat 2 (session_014EJ1ED8X4MMrT18BhVx4tx, seat post #18549), from the #20613 dev report (out-of-scope finding 3) and PR #20625's at-tier record 5888029963 (escalation 2). Both flagged it; the seat measured the timeline below. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim. It is outside #20613's surface: PR #20625 changes which push queues a publish, not what the backfill reads.
What happened (measured, 2026-09-29)
- The 17.5.0 publish ran in run
36536081716: its Publish 17.5.0 to npm job ran from 07:40:26Z to 08:11:15Z.
@objectstack/cli@17.5.0 reached npm at 07:58:57Z (npm time). Other packages of the fixed group landed at other times; @objectstack/spec@17.5.0 landed at 08:09:33Z (npm time).
- A landing during that window, push
7510663c87, started run 36540562567. Its release-integrity audit (08:05:53Z) read cli@17.5.0 as published, found the runtime image missing, and took the no-mint backfill branch.
- Its
Docker image / Build & push job's Build and push step ran 08:08:58Z–08:09:32Z and failed, one second before @objectstack/spec@17.5.0 existed on npm. The job log is not readable from a seat container (the log download redirect is refused by the proxy), so the error text is NOT MEASURED; the timing is.
- The publish run's own docker job then built and pushed the image (08:11:17Z–08:15:22Z, success). Every later release run on
main skips the docker job. So nothing is missing now: the cost is a red release run on main, a wasted build, and a false alarm on the release lane.
Why
release-integrity in .github/workflows/release.yml treats "the @objectstack/cli version is on npm" as "the release is published". The publish job pushes about 69 packages over several minutes, and cli is not the last. Any landing inside that window reads a half-published group as complete, and the backfill then builds from npm too early.
Suggested shape (⛔ not a ruling)
Dedupe
A REST listing of the 1,000 most recently updated issues and PRs (down to #19850), grepped locally for backfill near docker/image/in-flight/race, in-flight publish and image-missing, found only PR #20625, which names this as out of scope. No issue carries it.
Dedupe words: release-integrity backfill in-flight publish · docker backfill spec not on npm · cli canary read as published
Generated by Claude Code
Filing gate: ① a defect with a named landing site and a measured
reach:. Finding class (a).reach:the release workflow onmain: run36540562567(push7510663c87, 2026-09-29T08:05Z) is red.Filed by the
domain:specexecution seat 2 (session_014EJ1ED8X4MMrT18BhVx4tx, seat post #18549), from the #20613 dev report (out-of-scope finding 3) and PR #20625's at-tier record5888029963(escalation 2). Both flagged it; the seat measured the timeline below. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim. It is outside #20613's surface: PR #20625 changes which push queues a publish, not what the backfill reads.What happened (measured, 2026-09-29)
36536081716: itsPublish 17.5.0 to npmjob ran from 07:40:26Z to 08:11:15Z.@objectstack/cli@17.5.0reached npm at 07:58:57Z (npmtime). Other packages of the fixed group landed at other times;@objectstack/spec@17.5.0landed at 08:09:33Z (npmtime).7510663c87, started run36540562567. Itsrelease-integrityaudit (08:05:53Z) readcli@17.5.0as published, found the runtime image missing, and took the no-mint backfill branch.Docker image / Build & pushjob'sBuild and pushstep ran 08:08:58Z–08:09:32Z and failed, one second before@objectstack/spec@17.5.0existed on npm. The job log is not readable from a seat container (the log download redirect is refused by the proxy), so the error text is NOT MEASURED; the timing is.mainskips the docker job. So nothing is missing now: the cost is a red release run onmain, a wasted build, and a false alarm on the release lane.Why
release-integrityin.github/workflows/release.ymltreats "the@objectstack/cliversion is on npm" as "the release is published". The publish job pushes about 69 packages over several minutes, andcliis not the last. Any landing inside that window reads a half-published group as complete, and the backfill then builds from npm too early.Suggested shape (⛔ not a ruling)
release-verify-npm.mjsruns after publish), not theclicanary; or it stands down while arelease-publish-*job is in progress.cliis on npm andspecis not answers "not yet published", with the all-published control.release-integrity, so the race stays until this is fixed.Dedupe
A REST listing of the 1,000 most recently updated issues and PRs (down to #19850), grepped locally for
backfillneardocker/image/in-flight/race,in-flight publishandimage-missing, found only PR #20625, which names this as out of scope. No issue carries it.Dedupe words:
release-integrity backfill in-flight publish·docker backfill spec not on npm·cli canary read as publishedGenerated by Claude Code