From fd862625690b3b633e417dd7a18e6d4b3eb15ca8 Mon Sep 17 00:00:00 2001 From: Jacob Cable Date: Mon, 28 Sep 2026 18:56:58 +0100 Subject: [PATCH 1/2] fix(release-kit): drop dist-tag add on stable publish The trusted-publishing OIDC token authorises npm publish only, so the npm dist-tag add that followed a stable publish failed with E401 after the package was already live. The failure skipped the push, tag and GitHub release steps. Stable releases now publish with --tag latest only. Also carries the two next-only steps (Print inputs, explicit registry on the firebase-functions@next install) into kits so the next copy can be synced byte-for-byte. --- .github/workflows/release-kit.yaml | 17 +++++++++++------ 1 file changed, 11 insertions(+), 6 deletions(-) diff --git a/.github/workflows/release-kit.yaml b/.github/workflows/release-kit.yaml index 91130d2c50..ef4c06a660 100644 --- a/.github/workflows/release-kit.yaml +++ b/.github/workflows/release-kit.yaml @@ -65,6 +65,12 @@ jobs: permissions: contents: read steps: + - name: Print inputs + env: + INPUTS: ${{ toJSON(inputs) }} + run: | + echo "$INPUTS" + # Kits live only on the kits branch; the ref is pinned so dispatching # from any branch (including next, which lists the workflow in the UI) # releases the same content. @@ -94,7 +100,7 @@ jobs: run: | npm ci if [ "$USE_FIREBASE_FUNCTIONS_RC" = "true" ]; then - npm install --save firebase-functions@next + npm install --save --registry=https://registry.npmjs.org firebase-functions@next fi npm test @@ -219,7 +225,7 @@ jobs: else NEW_VER=$(npx --yes semver@7.8.5 -i "$BUMP_LEVEL" "$HIGHEST_STABLE") BUMP_TYPE="$BUMP_LEVEL" - TARGET_TAG="latest (and next)" + TARGET_TAG="latest" fi for v in $TAKEN; do @@ -245,7 +251,7 @@ jobs: run: | npm ci --registry=https://registry.npmjs.org if [ "$USE_FIREBASE_FUNCTIONS_RC" = "true" ]; then - npm install --save firebase-functions@next + npm install --save --registry=https://registry.npmjs.org firebase-functions@next fi npm run build @@ -368,10 +374,9 @@ jobs: if [ "$IS_PRERELEASE" = "true" ]; then npm publish --tag next --provenance --access public $DRY_RUN_FLAG else + # No `npm dist-tag add` here: the trusted-publishing token only + # authorises publish, so a dist-tag mutation fails with E401. npm publish --tag latest --provenance --access public $DRY_RUN_FLAG - if [ "$DRY_RUN" != "true" ]; then - npm dist-tag add ${PKG_NAME}@${VERSION} next - fi fi # Pushed only after a successful publish: a failed publish leaves the From 8aa8d557219dc50512aadbc29baf6c26e71ee17a Mon Sep 17 00:00:00 2001 From: Jacob Cable Date: Mon, 28 Sep 2026 18:56:58 +0100 Subject: [PATCH 2/2] docs(firestore-bigquery-export): CHANGELOG for kit 0.1.1 0.1.0 was published from the next copy of the workflow, which lacked the shrinkwrap prune step, so consumers on npm 10 fail npm ci with EBADPLATFORM. --- kits/firestore-bigquery-export/CHANGELOG.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/kits/firestore-bigquery-export/CHANGELOG.md b/kits/firestore-bigquery-export/CHANGELOG.md index 03400fa4fa..d5c5e1663e 100644 --- a/kits/firestore-bigquery-export/CHANGELOG.md +++ b/kits/firestore-bigquery-export/CHANGELOG.md @@ -1,3 +1,4 @@ -## Version 0.1.0 +## Version 0.1.1 +- fix: 0.1.0 shipped the kit's devDependencies in its `npm-shrinkwrap.json`, so a consumer `npm ci` under npm 10 (the Cloud Functions buildpack) fails with `EBADPLATFORM` on the `@esbuild/*` platform binaries. 0.1.1 ships the pruned shrinkwrap. Do not use 0.1.0. - Initial release of kit, see README for differences between the legacy extension and this kit