chore(deps): pin the release orchestrator exactly, at the version that survives a moving branch - #56
Merged
Merged
Conversation
…t survives a moving branch The range was the only floating one of the three repositories using this tool, and pnpm-workspace.yaml own saveExact comment already claimed this dependency was pinned exactly when it was not. An exact pin now, written by the package manager. 3.0.1 is what makes the jump worth taking: it retries a single-commit release whose atomic push lost a race to the branch, which is the strategy this workspace runs. Before it, a commit landing on main between the job checking out and its push cost the whole run. 3.0.2 fixes the per-package strategy, which this workspace does not use. Neither major in between needs anything here. 2.0.0 wants Node 22.18 or later and bans non-erasable syntax in TypeScript config files; .tool-versions pins the 22 line, which resolves to a release past that floor, and release-workspace.config.ts uses neither enum nor namespace. 3.0.0 stops a package marked private creating a GitHub Release, and all three packages here publish to npm, so none is affected.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two things at once, both small:
@exadev/semantic-release-workspacegoes from^1.2.1to an exact3.0.2.The exact pin. This was the only floating range on this dependency across the three repositories that use the tool; documents.js and wire-mesh both pin exactly.
pnpm-workspace.yaml's ownsaveExactcomment already describes this dependency as one of the "exact pins already used", which it was not. Written by the package manager, not by hand:pnpm addpreserves an existing range's prefix, so this needed a remove and re-add forsaveExact: trueto actually apply.The version. 3.0.1 is the one that matters here: it retries a
commitStrategy: 'single'release whose atomic push lost a race to the branch, which is the strategy this workspace runs. Before it, a commit landing on main between the job checking out and its push cost the entire run (ExaDev/semantic-release-workspace#38). 3.0.2 fixes theper-packagestrategy, which this workspace does not use, so it changes nothing here.The two majors in between
Checked rather than assumed, and neither needs anything:
.tool-versionspinsnodejs 22, which resolves to the newest 22.x and so sits past that floor; I have left that floating-major convention alone rather than changing it as a side effect of a dependency bump, but it is worth knowing that the floor is only cleared by the resolution, not by the pin itself.release-workspace.config.tsuses neitherenumnornamespace.privatefrom creating a GitHub Release. All three packages here publish to npm and none is private, so there is nothing to absorb.