From d47668236a10c3a994f62551f4debc5b7ea517aa Mon Sep 17 00:00:00 2001 From: Simon Nodel Date: Fri, 4 Sep 2026 22:28:15 -0700 Subject: [PATCH] fix(release): pack the tarball after the CLI is rebuilt MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `lingo-tracker --version` printed 0.16.0 on the published 0.17.0 package. The version is not hardcoded: apps/cli/src/main.ts uses `.version(__CLI_VERSION__)`, which esbuild replaces at build time from the root package.json. The bundle therefore freezes whatever version was current when the CLI was built. semantic-release runs its prepare steps in plugin order, and @semantic-release/npm both bumps package.json and packs the tarball in the same step. So the tarball was packed from the CLI built by the workflow's earlier `pnpm run build` — before the bump — and the @semantic-release/exec rebuild that followed came too late to reach it. `npm publish ./dist/*.tgz` then shipped the pre-bump bundle. Drop `tarballDir` from the npm plugin and pack from the exec step instead, after the rebuild. This is the ordering the `republish` job already uses: checkout the tag, build, then pack. Also verify the packed CLI reports the released version before publishing, so a regression fails the release instead of reaching npm. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01RifJr7xyhZkaTWn4ssV1b4 --- .github/workflows/release.yml | 14 ++++++++++++++ .releaserc.json | 5 ++--- 2 files changed, 16 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index ea7bdc01..2a288f3b 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -81,6 +81,20 @@ jobs: HUSKY: '0' run: pnpm run release + # The CLI bundle bakes its --version in at build time, so a tarball packed + # before the version bump ships the previous version. Catch that here rather + # than on npm. + - name: Verify packed CLI reports the released version + if: hashFiles('dist/*.tgz') != '' + run: | + version="$(node -p "require('./package.json').version")" + tar xzf ./dist/*.tgz -C "$RUNNER_TEMP" package/dist/apps/cli/main.cjs + if ! grep -q "version(\"$version\")" "$RUNNER_TEMP/package/dist/apps/cli/main.cjs"; then + echo "::error::packed CLI does not report $version" + grep -o 'version("[0-9][^"]*")' "$RUNNER_TEMP/package/dist/apps/cli/main.cjs" | head -1 + exit 1 + fi + - name: Publish to npm (trusted publishing) if: hashFiles('dist/*.tgz') != '' run: npm publish ./dist/*.tgz --provenance --access public diff --git a/.releaserc.json b/.releaserc.json index 32a2815d..e3655082 100644 --- a/.releaserc.json +++ b/.releaserc.json @@ -7,14 +7,13 @@ [ "@semantic-release/npm", { - "npmPublish": false, - "tarballDir": "dist" + "npmPublish": false } ], [ "@semantic-release/exec", { - "prepareCmd": "pnpm nx build cli --skip-nx-cache" + "prepareCmd": "pnpm nx build cli --skip-nx-cache && npm pack --pack-destination dist" } ], [