From cc68631b68a66b5b257a229fc5f896ebaddcf51a Mon Sep 17 00:00:00 2001 From: elkaix Date: Thu, 24 Sep 2026 15:21:36 -0400 Subject: [PATCH] Wait for a local npm publish instead of racing it in publish.yml npm processes uploads asynchronously (PUT 202), so the tag workflow saw v0.18.0 and v0.18.1 as unpublished and failed with ENEEDAUTH, skipping the registry and GitHub release jobs until a manual rerun. Without an NPM_TOKEN, poll for the version for up to 10 minutes. --- .github/workflows/publish.yml | 17 +++++++++++++---- 1 file changed, 13 insertions(+), 4 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index eef6be0..3036e83 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -66,7 +66,7 @@ jobs: npm: needs: verify runs-on: ubuntu-latest - timeout-minutes: 10 + timeout-minutes: 15 environment: npm permissions: contents: read @@ -85,11 +85,20 @@ jobs: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} TAG: ${{ github.ref_name }} run: | - if npm view "@pymodel/designer-skill-mcp@${TAG#v}" version >/dev/null 2>&1; then - echo "already on npm; skipping" - else + published() { npm view "@pymodel/designer-skill-mcp@${TAG#v}" version >/dev/null 2>&1; } + if [ -n "$NODE_AUTH_TOKEN" ]; then + if published; then echo "already on npm; skipping"; exit 0; fi npm publish ./pkg/*.tgz --provenance --access public --ignore-scripts + exit 0 fi + # No token: release.sh PUBLISH_LOCAL=1 published it; npm processes uploads + # asynchronously, so wait for the version instead of racing it. + for _ in $(seq 60); do + if published; then echo "published locally; skipping"; exit 0; fi + sleep 10 + done + echo "::error::${TAG#v} not on npm after 10 min and no NPM_TOKEN secret to publish it" + exit 1 registry: needs: npm