Skip to content

ci(release): enable Corepack before setup-node so pnpm cache resolves - #1037

Merged
acreeger merged 1 commit into
mainfrom
ci/release-corepack-order
Sep 18, 2026
Merged

acreeger merged 1 commit into
mainfrom
ci/release-corepack-order

Conversation

@acreeger

Copy link
Copy Markdown
Collaborator

Why

Follow-up to #1035. That PR reordered the publish job so the npm upgrade runs after setup-node, but it moved corepack enable to after setup-node too — and setup-node has cache: 'pnpm', which needs pnpm on PATH at that moment. Result: the publish job died in the Setup Node.js step with:

Unable to locate executable file: pnpm.

Fix

Move corepack enable back to before setup-node (it provides the pnpm shim the cache step needs). Corepack doesn't touch npm, so the npm upgrade still runs after setup-node and still sticks. Net step order in the publish job:

Enable Corepack → Setup Node.js (cache: pnpm) → Upgrade npm → Verify npm ≥ 11.5.1 → install → build → publish.

Verified

This exact fix was smoke-tested end-to-end by publishing @iloom/cli@0.14.4-beta.0 under the beta dist-tag via OIDC trusted publishing (workflow dispatch on a temp branch). The publish succeeded with a signed provenance statement:

Publishing to https://registry.npmjs.org/ with tag beta and public access
publish Signed provenance statement with source and build information from GitHub Actions
publish Provenance statement published to transparency log
+ @iloom/cli@0.14.4-beta.0

Provenance is only emitted by OIDC trusted publishing — so this confirms both the corepack fix and that tokenless OIDC publishing works. latest was untouched (still 0.14.3).

🤖 Generated with Claude Code

setup-node's `cache: pnpm` needs pnpm on PATH when it runs; moving
`corepack enable` after setup-node broke it ("Unable to locate
executable file: pnpm"). Corepack doesn't touch npm, so enabling it
first is safe and the npm upgrade still runs after setup-node.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DEmbohrunFJi7Ld22FNFpL
@acreeger
acreeger merged commit 42f34c9 into main Sep 18, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant