A canary published right after another can read a stale `canary` tag
Les mainteneurs répondent en général sous 3 jours
Évaluation
- Difficulté
- 3/5
- Temps estimé
- Une demi-journée
- Accessibilité débutants
- 65/100
- Type d'issue
- Bug
- Clarté
- Plutôt claire
- Activité
- Active
- Stack technique
- github-actions, typescript
- Domaine
- release
Piste de recherche
Look at the publish job in the CI workflow and the script that checks the canary tag before publishing (introduced in #3784). The fix should prevent the race condition where a pending canary publish is invisible during npm's malware scan. Verify by simulating two rapid canary publishes and checking that the dist-tag points to the newer version.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
#3784 made the publish job skip a canary whose commit is not after the commit of the canary already on npm. npm makes a new version, and the dist-tag the publish moved, visible only when its publish-time malware scan finishes, so that check can read a canary that is about to change.
Details
- Over the eight canaries published since 2026-09-27, npm listed each version 56 to 249 seconds after the Publish step finished (median 127). GitHub's changelog calls the delay "typically around five minutes".
- If two merges land close together and the older commit's publish starts inside that window, it reads the previous canary, passes the check, publishes, and leaves
canaryon the older build until the next merge.
Scope
- Only the
canarydist-tag is affected, so onlynpm install @angular/fire@canaryandng add @angular/fire@canary.latestandnextmove only on tagged releases. - It needs two merges to
mainwithin a few minutes of each other, with the older one's publish running second. - It lasts until the next merge publishes a newer canary.
- Langage dominant
- TypeScript
- Étoiles
- 7.8k
- Forks
- 2.2k
- Merge moyen
- 3 j 2 h
- PR mergées (30 j)
- 13
Préparer son environnement
- Aucun Dockerfile ni fichier Docker Compose
- Propose un modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de angular/angularfire
-
A 20.x release after 21.0.0 would move `latest` back to 20.x, and `next` stays on the release candidatePeut-être pris @armando-navarro l’a pris il y a 1 jour. Ouvertecomp: build/pipeline type: bug version: current (v17+)
Difficulté 2/5 1-3 heures Accessibilité débutants 85/100
angular/angularfire#3790 ·
Les mainteneurs répondent en général sous 3 jours
-
docs: the App Check guide does not cover server-side renderingPeut-être pris @armando-navarro l’a pris il y a 11 jours. Ouvertecomp: app-check comp: docs comp: ssr type: chore version: current (v17+)
Difficulté 2/5 1-3 heures Accessibilité débutants 88/100
angular/angularfire#3774 ·
Les mainteneurs répondent en général sous 3 jours
-
`ng update @angular/fire` stops before the v21 migration when it runs Angular CLI 22.3Peut-être pris @armando-navarro l’a pris il y a 1 jour. Ouvertecomp: schematics type: bug version: current (v17+)
Difficulté 3/5 1-2 jours Accessibilité débutants 25/100
angular/angularfire#3789 ·
Les mainteneurs répondent en général sous 3 jours
-
Use `TransferState` to hand server-rendered Firestore data to the browser, instead of reading every document twicePeut-être à nouveau libre @armando-navarro l’a pris il y a 39 jours, et aucune pull request n’est ouverte. Ouvertecomp: firestore comp: ssr priority: P0 (critical) type: feature version: current (v17+)
angular/angularfire#3757 · 1 personne assignée ·
Les mainteneurs répondent en général sous 3 jours
-
Six `firebase` entry points have no `@angular/fire` equivalent, so their exports are unreachablePeut-être à nouveau libre @armando-navarro l’a pris il y a 39 jours, et aucune pull request n’est ouverte. Ouvertecomp: core type: feature
angular/angularfire#3755 · 1 personne assignée ·
Les mainteneurs répondent en général sous 3 jours
Toutes les issues de angular/angularfire
Issues similaires
-
[Docs] README: FAQ setup command, IDA in the intro, Node badgePeut-être pris @akram1089 l’a pris aujourd’hui. Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 85/100
morluto/rea#1353 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
[Feature]: [P3] engine-rs: the package source hash should ignore line endings and untracked filesOuverte
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
maniator/verticopolis#880 ·
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
-
Difficulté 2/5 1-3 heures Accessibilité débutants 62/100
siyuan-note/siyuan#20353 ·
Les mainteneurs répondent en général sous 1 jour
-
afk-ok area:data-quality importer size:S
Difficulté 2/5 1-3 heures Accessibilité débutants 82/100
enorm-labs/event-junkie#3027 ·
Les mainteneurs répondent en général sous 1 jour