fix(ci): extract npm pack tarball name from final stdout line - #1690
Conversation
The Release workflow's "Pack release tarball" step has been failing on every push to main since the cosign keyless signing landed (a9ae564, 2026-04-23). Latest casualty: the merge commit for #1689 (668e9a8). Root cause: `TARBALL=$(npm pack --silent)` captures ALL stdout, not just the tarball name. The `prepack` hook (`bun run build`) writes its own output to stdout — banner + bundled-assets table — and that output is NOT silenced by `npm --silent` (which only suppresses npm's own progress banner, not script-hook stdout). So `$TARBALL` ends up being a multi-line blob: $ bun build src/genie.ts ... Bundled 544 modules in 183ms genie.js 5.15 MB (entry point) ... automagik-genie-4.260428.3.tgz <-- the actual filename `[ ! -f "${TARBALL}" ]` then fails on the multi-line value, exiting 1 with "npm pack produced no tarball". Fix: pipe through `tail -n1` to extract only the final stdout line, which npm pack guarantees is the tarball filename. Verified locally: - Without fix: TARBALL is 17-line blob, `[ -f $TARBALL ]` fails. - With fix: TARBALL is `automagik-genie-4.260428.3.tgz`, file check passes. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
|
Warning Rate limit exceeded
To continue reviewing without waiting, purchase usage credits in the billing tab. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d6524e5647
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| # own progress banner, not the prepack hook's output. Capturing | ||
| # the full stdout therefore yields a multi-line blob ending with | ||
| # the tarball name; `tail -n1` extracts the filename reliably. | ||
| TARBALL=$(npm pack --silent | tail -n1) |
There was a problem hiding this comment.
Preserve
npm pack exit status in tarball capture
TARBALL=$(npm pack --silent | tail -n1) masks failures from npm pack because this workflow step does not set shell: bash, so the default non-Windows shell runs without pipefail and the pipeline status is taken from tail. That means an npm pack error can be treated as success if tail exits 0 and ${TARBALL} still points to an existing file, allowing the release job to continue from a failed pack operation. Capture npm pack output without a pipeline (or enable pipefail) so pack failures still stop the workflow.
Useful? React with 👍 / 👎.
Summary
Fixes the
Pack release tarballstep in.github/workflows/release.yml, which has been failing on every push to main since 2026-04-23 when cosign keyless signing landed (a9ae5649). Latest casualty: the merge commit for #1689 (668e9a8b).Root cause
TARBALL=\$(npm pack --silent)captures all stdout, not just the tarball name. Theprepackhook (bun run build) writes its own output to stdout — banner + bundled-assets table — and that output is not silenced bynpm --silent(which only suppresses npm's own progress banner, not script-hook stdout).So
\$TARBALLends up being a multi-line blob:[ ! -f "\${TARBALL}" ]then fails because\$TARBALLis a multi-line string, exiting 1 withnpm pack produced no tarball.Fix
Pipe through
tail -n1to extract only the final stdout line.npm packalways emits the tarball filename as its last line of stdout, so this is robust regardless of what the prepack hook writes.Why the workflow has been silently failing
Release runs on push-to-main only. Every Release run on main since 2026-04-28 has failed at the Pack step with this exact symptom — the merge commit and the workflow author both saw
--silentand assumed it covered prepack output too. The signing infrastructure downstream is fine; nothing ever got far enough to exercise it.Test plan
npm pack --silentreturns 17 lines, original[ -f \$TARBALL ]check failsTARBALL=\$(npm pack --silent | tail -n1)returnsautomagik-genie-4.260428.3.tgz, file check passesNotes
ca0a1d81,b32f761b, etc.🤖 Generated with Claude Code