feat(release): committed toolchain manifest — npm ci replaces ad-hoc installs #135
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/release-toolchain-manifest"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Root package.json + package-lock.json pin the entire release toolchain
(semantic-release 25.0.9, @webgrip/semantic-release-config 1.2.3,
semantic-release-monorepo 8.0.2, preset 10.4.0) with the overrides block
mirroring the config's own verbatim — the npm-sanctioned mechanism for
forcing the PR #10 notes pair (generator 15.0.0-beta.2 / analyzer
14.0.0-beta.3) that no install argument can express: both betas sit outside
semantic-release's ^14/^13 ranges, so any manifest-less install nests stable
copies under semantic-release, whose plugin loader (own dir before cwd)
loads them — measured across runs 426-435.
The composite's install step becomes
npm ciat the repo root(semantic-release-monorepo's documented root-install mode for monorepos),
plus a loud post-install assertion (no nested generator, pair >=15/>=10)
because this failure mode renders EMPTY notes silently. npx replaced with
the explicit bin path so a missing install can never fall back to a
registry fetch. config-version input is now vestigial; the npm cache keys
on the lockfile hash.
Verified locally against the real tree: overrides applied (single copies,
betas resolved), and ops/docker/agent-runner/.releaserc.cjs loads from its
own directory through the root tree with the config's load-time pairing
guard passing.
Supersedes PR #133 (the scratch-prefix bridge) per Ryan's direct call:
same intent — honour PR #10's design — expressed as committed state
instead of install-time reconstruction.
Co-Authored-By: Claude Fable 5 noreply@anthropic.com