Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

A canary published right after another can read a stale `canary` tag

Aperta
#3,791 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 3 giorni

@armando-navarro ci sta già lavorando.

Dal 8/10/2026.

  • #3794 di @armando-navarro — aperta

Valutazione

Difficoltà
3/5
Tempo stimato
Mezza giornata
Idoneità per principianti
65/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
github-actions, typescript
Ambito
release

Direzione di ricerca

Look at the publish job in the CI workflow and the script that checks the canary tag before publishing (introduced in #3784). The fix should prevent the race condition where a pending canary publish is invisible during npm's malware scan. Verify by simulating two rapid canary publishes and checking that the dist-tag points to the newer version.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

comp: build/pipeline type: bug version: current (v17+)

#3784 made the publish job skip a canary whose commit is not after the commit of the canary already on npm. npm makes a new version, and the dist-tag the publish moved, visible only when its publish-time malware scan finishes, so that check can read a canary that is about to change.

Details
  • Over the eight canaries published since 2026-09-27, npm listed each version 56 to 249 seconds after the Publish step finished (median 127). GitHub's changelog calls the delay "typically around five minutes".
  • If two merges land close together and the older commit's publish starts inside that window, it reads the previous canary, passes the check, publishes, and leaves canary on the older build until the next merge.
Scope
  • Only the canary dist-tag is affected, so only npm install @angular/fire@canary and ng add @angular/fire@canary. latest and next move only on tagged releases.
  • It needs two merges to main within a few minutes of each other, with the older one's publish running second.
  • It lasts until the next merge publishes a newer canary.
Lingua principale
TypeScript
Stelle
7.8k
Fork
2.2k
Merge medio
3g 2h
PR unite (30g)
13

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di angular/angularfire

Tutte le issue di angular/angularfire

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.