Skip to content

chore(deps): pin the release orchestrator exactly, at the version that survives a moving branch - #56

Merged
Mearman merged 1 commit into
mainfrom
chore/bump-srw
Sep 20, 2026
Merged

Mearman merged 1 commit into
mainfrom
chore/bump-srw

Conversation

@Mearman

@Mearman Mearman commented Sep 20, 2026

Copy link
Copy Markdown
Member

Two things at once, both small: @exadev/semantic-release-workspace goes from ^1.2.1 to an exact 3.0.2.

The exact pin. This was the only floating range on this dependency across the three repositories that use the tool; documents.js and wire-mesh both pin exactly. pnpm-workspace.yaml's own saveExact comment already describes this dependency as one of the "exact pins already used", which it was not. Written by the package manager, not by hand: pnpm add preserves an existing range's prefix, so this needed a remove and re-add for saveExact: true to actually apply.

The version. 3.0.1 is the one that matters here: it retries a commitStrategy: 'single' release whose atomic push lost a race to the branch, which is the strategy this workspace runs. Before it, a commit landing on main between the job checking out and its push cost the entire run (ExaDev/semantic-release-workspace#38). 3.0.2 fixes the per-package strategy, which this workspace does not use, so it changes nothing here.

The two majors in between

Checked rather than assumed, and neither needs anything:

  • 2.0.0 requires Node 22.18 or later and bans non-erasable syntax in TypeScript config files. .tool-versions pins nodejs 22, which resolves to the newest 22.x and so sits past that floor; I have left that floating-major convention alone rather than changing it as a side effect of a dependency bump, but it is worth knowing that the floor is only cleared by the resolution, not by the pin itself. release-workspace.config.ts uses neither enum nor namespace.
  • 3.0.0 stops a package marked private from creating a GitHub Release. All three packages here publish to npm and none is private, so there is nothing to absorb.

…t survives a moving branch

The range was the only floating one of the three repositories using this
tool, and pnpm-workspace.yaml own saveExact comment already claimed this
dependency was pinned exactly when it was not. An exact pin now, written
by the package manager.

3.0.1 is what makes the jump worth taking: it retries a single-commit
release whose atomic push lost a race to the branch, which is the
strategy this workspace runs. Before it, a commit landing on main
between the job checking out and its push cost the whole run. 3.0.2
fixes the per-package strategy, which this workspace does not use.

Neither major in between needs anything here. 2.0.0 wants Node 22.18 or
later and bans non-erasable syntax in TypeScript config files;
.tool-versions pins the 22 line, which resolves to a release past that
floor, and release-workspace.config.ts uses neither enum nor namespace.
3.0.0 stops a package marked private creating a GitHub Release, and all
three packages here publish to npm, so none is affected.
@Mearman
Mearman marked this pull request as ready for review September 20, 2026 15:42
@Mearman
Mearman merged commit e5e5b5a into main Sep 20, 2026
14 checks passed
@Mearman
Mearman deleted the chore/bump-srw branch September 20, 2026 15:42
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-09-20T15:46:20.576668Z 130513d Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant