Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

A canary published right after another can read a stale `canary` tag

Aberta
#3,791 0 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 3 dias

@armando-navarro já está trabalhando nisso.

Desde 8/10/2026.

  • #3794 de @armando-navarro — aberto

Avaliação

Dificuldade
3/5
Tempo estimado
Meio dia
Facilidade para iniciantes
65/100
Tipo de issue
Bug
Clareza
Razoavelmente clara
Status de atividade
Ativa
Stack de tecnologia
github-actions, typescript
Domínio
release

Direção de pesquisa

Look at the publish job in the CI workflow and the script that checks the canary tag before publishing (introduced in #3784). The fix should prevent the race condition where a pending canary publish is invisible during npm's malware scan. Verify by simulating two rapid canary publishes and checking that the dist-tag points to the newer version.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

comp: build/pipeline type: bug version: current (v17+)

#3784 made the publish job skip a canary whose commit is not after the commit of the canary already on npm. npm makes a new version, and the dist-tag the publish moved, visible only when its publish-time malware scan finishes, so that check can read a canary that is about to change.

Details
  • Over the eight canaries published since 2026-09-27, npm listed each version 56 to 249 seconds after the Publish step finished (median 127). GitHub's changelog calls the delay "typically around five minutes".
  • If two merges land close together and the older commit's publish starts inside that window, it reads the previous canary, passes the check, publishes, and leaves canary on the older build until the next merge.
Scope
  • Only the canary dist-tag is affected, so only npm install @angular/fire@canary and ng add @angular/fire@canary. latest and next move only on tagged releases.
  • It needs two merges to main within a few minutes of each other, with the older one's publish running second.
  • It lasts until the next merge publishes a newer canary.
Linguagem predominante
TypeScript
Estrelas
7.8k
Forks
2.2k
Merge médio
3d 2h
PRs com merge (30d)
13

Preparar o ambiente

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de angular/angularfire

Todas as issues de angular/angularfire

Issues semelhantes

Mais issues de TypeScript

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.