Skip to content

fix: failing patch release bumper on missing package-lock.json - #1730

Open
jescalada wants to merge 12 commits into
mainfrom
fix-patch-bumper-workflow
Open

jescalada wants to merge 12 commits into
mainfrom
fix-patch-bumper-workflow

Conversation

@jescalada

@jescalada jescalada commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Description

Related Issue

Resolves #

Checklist

General

Documentation

  • Documentation has been added/updated for any new features

Configuration

  • If configuration schema (config.schema.json) was modified:
    • TypeScript types regenerated (npm run generate-config-types)
    • Schema reference docs regenerated (npm run gen-schema-doc)

Tests

  • Tests have been added/updated for new functionality
  • Unit tests pass (npm test)
  • Linting and formatting pass (npm run lint and npm run format:check)
  • Type checks pass (npm run check-types)

@jescalada
jescalada requested a review from a team as a code owner September 8, 2026 01:04
@netlify

netlify Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for endearing-brigadeiros-63f9d0 canceled.

Name Link
🔨 Latest commit 54200c0
🔍 Latest deploy log https://app.netlify.com/projects/endearing-brigadeiros-63f9d0/deploys/6ab8eccd33f3d00009d7c5ca

@github-actions github-actions Bot added the fix label Sep 8, 2026
@github-actions

github-actions Bot commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@codecov

codecov Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 86.39%. Comparing base (8ee2272) to head (54200c0).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1730   +/-   ##
=======================================
  Coverage   86.39%   86.39%           
=======================================
  Files         103      103           
  Lines        5843     5843           
  Branches     1084     1084           
=======================================
  Hits         5048     5048           
  Misses        535      535           
  Partials      260      260           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@jescalada
jescalada changed the base branch from main to release/2.0 September 8, 2026 02:27
@jescalada
jescalada changed the base branch from release/2.0 to main September 8, 2026 02:29

@kriswest kriswest left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, although co-pilot had a few suggestions you could apply:

  1. Check version tag doesn't already exist
if git rev-parse "v$VERSION" >/dev/null 2>&1; then
  echo "::error::Version v$VERSION already exists"
  exit 1
fi
  1. Verify files actually changed
git diff --quiet && {
  echo "::error::No version changes detected"
  exit 1
}
  1. Validate lockfile integrity
npm install --package-lock-only
git diff --exit-code

For a FINOS/open-source release process, I'd consider the "version tag already exists" check the most important omission because it prevents accidentally generating a PR for a version that's already been released.

@jescalada

jescalada commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor Author

@kriswest The reason the patch release wasn't working as expected is that the "Patch lockfile versions" step wasn't actually doing anything (embarrassing proof that I should pay more attention when using AI-generated code):

image

I figured the best choice is to extract all the repeated steps along with the script into a separate action and import that instead so that the bumper workflows don't drift...

Since the package.json version bumps did work, the PR was generated normally, and the 2.0.1/2.1.1 builds don't seem to have issues (unless we were to run npm ci on those branches).

@jescalada
jescalada force-pushed the fix-patch-bumper-workflow branch from 40fb0ee to 0eaa03c Compare September 27, 2026 10:15
@jescalada

Copy link
Copy Markdown
Contributor Author

PR successfully generated here: #1765

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants