Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

A canary published right after another can read a stale `canary` tag

Ouverte
#3,791 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Les mainteneurs répondent en général sous 3 jours

@armando-navarro y travaille déjà.

Depuis le 8/10/2026.

  • #3794 par @armando-navarro — ouverte

Évaluation

Difficulté
3/5
Temps estimé
Une demi-journée
Accessibilité débutants
65/100
Type d'issue
Bug
Clarté
Plutôt claire
Activité
Active
Stack technique
github-actions, typescript
Domaine
release

Piste de recherche

Look at the publish job in the CI workflow and the script that checks the canary tag before publishing (introduced in #3784). The fix should prevent the race condition where a pending canary publish is invisible during npm's malware scan. Verify by simulating two rapid canary publishes and checking that the dist-tag points to the newer version.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

comp: build/pipeline type: bug version: current (v17+)

#3784 made the publish job skip a canary whose commit is not after the commit of the canary already on npm. npm makes a new version, and the dist-tag the publish moved, visible only when its publish-time malware scan finishes, so that check can read a canary that is about to change.

Details
  • Over the eight canaries published since 2026-09-27, npm listed each version 56 to 249 seconds after the Publish step finished (median 127). GitHub's changelog calls the delay "typically around five minutes".
  • If two merges land close together and the older commit's publish starts inside that window, it reads the previous canary, passes the check, publishes, and leaves canary on the older build until the next merge.
Scope
  • Only the canary dist-tag is affected, so only npm install @angular/fire@canary and ng add @angular/fire@canary. latest and next move only on tagged releases.
  • It needs two merges to main within a few minutes of each other, with the older one's publish running second.
  • It lasts until the next merge publishes a newer canary.
Langage dominant
TypeScript
Étoiles
7.8k
Forks
2.2k
Merge moyen
3 j 2 h
PR mergées (30 j)
13

Préparer son environnement

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de angular/angularfire

Toutes les issues de angular/angularfire

Issues similaires

Plus d'issues TypeScript

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.