Skip to content

fix: pin npm to v11 and bump Node to 22.x to avoid npm@latest engine break - #469

Merged
shannah merged 1 commit into
masterfrom
claude/jdeploy-npm-12-node-20-w4d24r
Jul 10, 2026
Merged

fix: pin npm to v11 and bump Node to 22.x to avoid npm@latest engine break#469
shannah merged 1 commit into
masterfrom
claude/jdeploy-npm-12-node-20-w4d24r

Conversation

@shannah

@shannah shannah commented Jul 9, 2026

Copy link
Copy Markdown
Owner

npm published v12.0.0 as "latest", which requires Node ^22.22.2 || ^24.15.0
|| >=26. The action provisioned Node 20.x and ran npm install -g npm@latest,
so every consumer pinned to shannah/jdeploy@master started failing with
EBADENGINE the moment npm 12 shipped, with no change on their side.

  • Pin the upgrade to npm@11 instead of tracking npm@latest so a future
    npm major with a higher Node engine requirement can't silently break the
    action again.
  • Bump Node from 20.x to 22.x, clearing the runner's Node 20 deprecation
    warning while staying compatible with npm 11's trusted-publishing (OIDC).
  • Gate the npm upgrade in action.yml on deploy_target == 'npm' since
    trusted publishing is npm-registry-only; GitHub-only releases skip it.

Applied the same pin/Node bump to the internal maven.yml release workflow.

…break

npm published v12.0.0 as "latest", which requires Node ^22.22.2 || ^24.15.0
|| >=26. The action provisioned Node 20.x and ran `npm install -g npm@latest`,
so every consumer pinned to shannah/jdeploy@master started failing with
EBADENGINE the moment npm 12 shipped, with no change on their side.

- Pin the upgrade to `npm@11` instead of tracking `npm@latest` so a future
  npm major with a higher Node engine requirement can't silently break the
  action again.
- Bump Node from 20.x to 22.x, clearing the runner's Node 20 deprecation
  warning while staying compatible with npm 11's trusted-publishing (OIDC).
- Gate the npm upgrade in action.yml on `deploy_target == 'npm'` since
  trusted publishing is npm-registry-only; GitHub-only releases skip it.

Applied the same pin/Node bump to the internal maven.yml release workflow.
@shannah
shannah merged commit 6257b2d into master Jul 10, 2026
20 checks passed
@shannah
shannah deleted the claude/jdeploy-npm-12-node-20-w4d24r branch July 10, 2026 01:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants