Skip to content

[finding] release.yml stale-prompts: the sweep reads "0 waiting run(s)" on both main pushes since PR #20625, while run 36539819278 (Publish 17.5.0, already on npm) still waits at release #20659

Description

@objectstack-fleet

Filed by the domain:spec seat 2 PM (session_014EJ1ED8X4MMrT18BhVx4tx) while writing the landing record for #20613 (PR #20625, merged as 73213a521d). Every reading below was taken at 14:10Z on 2026-09-29.

What was measured

PR #20625 added the stale-prompts job to .github/workflows/release.yml (Cancel publish prompts for versions already on npm). It runs node scripts/release-pending-publish.mjs sweep --workflow release.yml on every main push. Its purpose, in the job's own comment, is that run 36539819278 must not keep waiting after @objectstack/cli@17.5.0 reached npm.

Two main pushes have run the job since the merge. Both jobs were green, and both logs print the same verdict:

Release run Head Job Log line
36579512725 73213a521d (PR #20625's merge) 109443658530 ### Waiting approval prompts (0 waiting run(s) of release.yml) / - none waiting
36579680181 9b402dbaed 109444238812 ### Waiting approval prompts (0 waiting run(s) of release.yml) / - none waiting

At the same time, the same endpoint read without a token lists the run:

  • GET /repos/objectstack-ai/objectstack/actions/workflows/release.yml/runs?status=waiting&per_page=100 → total_count: 1, run 36539819278, status: waiting, event: push, head 422db788a2. The repo-wide GET /actions/runs?status=waiting gives the same single run.
  • GET .../actions/runs/36539819278/jobs?filter=latest → Publish 17.5.0 to npm (awaiting approval), waiting. This matches PUBLISH_JOB_NAME.
  • GET .../actions/runs/36539819278/pending_deployments → environment release.
  • npm view @objectstack/cli@17.5.0 version → 17.5.0, which classifyNpmView reads as present.

So every predicate judgeWaitingRuns checks would put this run in cancel. It never reaches the judge, because collectWaitingRuns' first read, the waiting-runs list made with the job's GITHUB_TOKEN, answered an empty list twice. Neither job carries an annotation other than the runner-image notice. That fits the runs.length === 0 path, which prints no ::warning::.

Reach (measured)

  • The stale holder still holds the group. Run 36539819278 is still waiting at the release environment, 6 hours after cli@17.5.0 reached npm (07:58:57Z). The job's own comment gives the harm: the waiting publish job holds release-publish-<ref>, so the next Version Packages merge's real prompt pends behind it and is hidden. That is the 17.4.0 → 17.5.0 misapproval shape the amendment (ADR-0125 D1, amended 2026-09-29) exists to stop.
  • The failure is silent. A wrong-empty read ends green with - none waiting. The job comment asks that "a failed read here must be loud (a red job on main)", but a read that answers 200 with nothing is not a failed read to this code, so nothing on main turns red or warns.

Hypotheses for the dev (unverified; measure first)

  1. The difference is the token, not the filter: the list endpoint's status=waiting filter answers the workflow token with no runs while it answers an anonymous read with one. Measure it from inside a run: a --dry-run dispatch, or a temporary diagnostic that logs total_count for (a) ?status=waiting, (b) the unfiltered list, and (c) GET /actions/runs/36539819278.
  2. If (1) holds, reading the recent runs unfiltered and selecting status === 'waiting' in the script removes the dependency on the server filter. The unfiltered list must still be read far enough back: this run was created at 07:58Z and many pushes have landed since.
  3. Either way, "0 waiting" should be cross-checked, or at least printed as a ::notice:: with the listed total_count, so the next wrong-empty read is visible in the run summary instead of reading as "nothing to do".

⛔ The seat did not reject, approve or cancel run 36539819278. Release deployments are the maintainer's alone (AGENTS.md). Until a fix lands, the maintainer can Reject that run's Publish 17.5.0 prompt at the release environment. A rejected run can publish nothing and releases the group.

Related: #20613 (the card PR #20625 closed), #20627 (release-integrity's in-flight publish read).


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:specpriority:p2Medium: important, M3tooling

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions