A canary published right after another can read a stale `canary` tag
Los mantenedores suelen responder en 3 días
@armando-navarro ya está trabajando en esto.
Desde el 8/10/2026.
- #3794 de @armando-navarro — abierto
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- Medio día
- Aptitud para principiantes
- 65/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- github-actions, typescript
- Área
- release
Línea de trabajo
Look at the publish job in the CI workflow and the script that checks the canary tag before publishing (introduced in #3784). The fix should prevent the race condition where a pending canary publish is invisible during npm's malware scan. Verify by simulating two rapid canary publishes and checking that the dist-tag points to the newer version.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
#3784 made the publish job skip a canary whose commit is not after the commit of the canary already on npm. npm makes a new version, and the dist-tag the publish moved, visible only when its publish-time malware scan finishes, so that check can read a canary that is about to change.
Details
- Over the eight canaries published since 2026-09-27, npm listed each version 56 to 249 seconds after the Publish step finished (median 127). GitHub's changelog calls the delay "typically around five minutes".
- If two merges land close together and the older commit's publish starts inside that window, it reads the previous canary, passes the check, publishes, and leaves
canaryon the older build until the next merge.
Scope
- Only the
canarydist-tag is affected, so onlynpm install @angular/fire@canaryandng add @angular/fire@canary.latestandnextmove only on tagged releases. - It needs two merges to
mainwithin a few minutes of each other, with the older one's publish running second. - It lasts until the next merge publishes a newer canary.
- Lenguaje dominante
- TypeScript
- Estrellas
- 7.8k
- Forks
- 2.2k
- Merge medio
- 3 d 2 h
- PR fusionados (30 d)
- 13
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de angular/angularfire
-
A 20.x release after 21.0.0 would move `latest` back to 20.x, and `next` stays on the release candidatePosiblemente ocupada @armando-navarro la tomó hoy. Abiertocomp: build/pipeline type: bug version: current (v17+)
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
angular/angularfire#3790 ·
Los mantenedores suelen responder en 3 días
-
docs: the App Check guide does not cover server-side renderingPosiblemente ocupada @armando-navarro la tomó hace 10 días. Abiertocomp: app-check comp: docs comp: ssr type: chore version: current (v17+)
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
angular/angularfire#3774 ·
Los mantenedores suelen responder en 3 días
-
`ng update @angular/fire` stops before the v21 migration when it runs Angular CLI 22.3Posiblemente ocupada @armando-navarro la tomó hoy. Abiertocomp: schematics type: bug version: current (v17+)
Dificultad 3/5 1-2 días Aptitud para principiantes 25/100
angular/angularfire#3789 ·
Los mantenedores suelen responder en 3 días
-
Use `TransferState` to hand server-rendered Firestore data to the browser, instead of reading every document twiceQuizá libre de nuevo @armando-navarro la tomó hace 37 días y no hay ningún pull request abierto. Abiertocomp: firestore comp: ssr priority: P0 (critical) type: feature version: current (v17+)
angular/angularfire#3757 · 1 asignado ·
Los mantenedores suelen responder en 3 días
-
Six `firebase` entry points have no `@angular/fire` equivalent, so their exports are unreachableQuizá libre de nuevo @armando-navarro la tomó hace 37 días y no hay ningún pull request abierto. Abiertocomp: core type: feature
angular/angularfire#3755 · 1 asignado ·
Los mantenedores suelen responder en 3 días
Todos los issues de angular/angularfire
Issues similares
-
Tenant
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
MTES-MCT/Dossier-Facile-Frontend#2061 ·
Los mantenedores suelen responder en 1 día
-
area:frontend
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
interledger/publisher-tools#905 ·
Los mantenedores suelen responder en 1 día
-
Add: Cbeebies PL SDAbiertoapproved check:passed streams:add
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
iptv-org/iptv#54525 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
DB-plane provider_chat_options.* is accepted by config set but never merged into the loaded configAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
area:web
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
praetorianer777/GoTome#178 ·
Los mantenedores suelen responder en 1 día