Skip to content

The canary dist-tag can move back to an older build #3783

Description

@armando-navarro

Every push to main and every weekday scheduled run builds a canary and runs npm publish --tag canary, which moves the canary dist-tag to that build. Nothing checks that the build is newer than the one the tag already points at, so the tag can end up on an older build.

Details

  • Two merges close together can publish out of order. Each merge starts its own workflow run, and the publish job waits for that run's tests. If a second merge lands while the first run is still going and the first run's tests finish last, the older commit's canary publishes last and takes the tag.
    • A run takes about 6 to 7 minutes. On 2026-09-27 the run for f182972 started 21 seconds after the canary for 84a8a51 had published.
  • Re-running an older run can publish it late. A run on main whose canary never published, for example because a test failed, publishes when it is re-run, even if newer canaries have gone out since.
  • Nothing puts the tag back. The weekday scheduled run rebuilds the latest commit on main, whose version is already on npm, so its publish fails with E403 (example). The tag stays on the older build until the next merge.

Scope

I have not seen the tag move back yet. While it sits on an older build, npm install @angular/fire@canary installs that build.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    comp: build/pipelineBuild, bundling, packaging, release pipeline.type: bugDefect: expected behavior doesn't happen.version: current (v17+)Targets the current modular API (v17+).

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions