A canary published right after another can read a stale `canary` tag
Mantenedores costumam responder em até 3 dias
Avaliação
- Dificuldade
- 3/5
- Tempo estimado
- Meio dia
- Facilidade para iniciantes
- 65/100
- Tipo de issue
- Bug
- Clareza
- Razoavelmente clara
- Status de atividade
- Ativa
- Stack de tecnologia
- github-actions, typescript
- Domínio
- release
Direção de pesquisa
Look at the publish job in the CI workflow and the script that checks the canary tag before publishing (introduced in #3784). The fix should prevent the race condition where a pending canary publish is invisible during npm's malware scan. Verify by simulating two rapid canary publishes and checking that the dist-tag points to the newer version.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
#3784 made the publish job skip a canary whose commit is not after the commit of the canary already on npm. npm makes a new version, and the dist-tag the publish moved, visible only when its publish-time malware scan finishes, so that check can read a canary that is about to change.
Details
- Over the eight canaries published since 2026-09-27, npm listed each version 56 to 249 seconds after the Publish step finished (median 127). GitHub's changelog calls the delay "typically around five minutes".
- If two merges land close together and the older commit's publish starts inside that window, it reads the previous canary, passes the check, publishes, and leaves
canaryon the older build until the next merge.
Scope
- Only the
canarydist-tag is affected, so onlynpm install @angular/fire@canaryandng add @angular/fire@canary.latestandnextmove only on tagged releases. - It needs two merges to
mainwithin a few minutes of each other, with the older one's publish running second. - It lasts until the next merge publishes a newer canary.
- Linguagem predominante
- TypeScript
- Estrelas
- 7.8k
- Forks
- 2.2k
- Merge médio
- 3d 2h
- PRs com merge (30d)
- 13
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Tem um modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de angular/angularfire
-
A 20.x release after 21.0.0 would move `latest` back to 20.x, and `next` stays on the release candidateTalvez já em andamento @armando-navarro assumiu hoje. Abertacomp: build/pipeline type: bug version: current (v17+)
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
angular/angularfire#3790 ·
Mantenedores costumam responder em até 3 dias
-
docs: the App Check guide does not cover server-side renderingTalvez já em andamento @armando-navarro assumiu há 10 dias. Abertacomp: app-check comp: docs comp: ssr type: chore version: current (v17+)
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
angular/angularfire#3774 ·
Mantenedores costumam responder em até 3 dias
-
`ng update @angular/fire` stops before the v21 migration when it runs Angular CLI 22.3Talvez já em andamento @armando-navarro assumiu hoje. Abertacomp: schematics type: bug version: current (v17+)
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 25/100
angular/angularfire#3789 ·
Mantenedores costumam responder em até 3 dias
-
Use `TransferState` to hand server-rendered Firestore data to the browser, instead of reading every document twiceTalvez livre de novo @armando-navarro assumiu há 37 dias e não há nenhum pull request aberto. Abertacomp: firestore comp: ssr priority: P0 (critical) type: feature version: current (v17+)
angular/angularfire#3757 · 1 responsável ·
Mantenedores costumam responder em até 3 dias
-
Six `firebase` entry points have no `@angular/fire` equivalent, so their exports are unreachableTalvez livre de novo @armando-navarro assumiu há 37 dias e não há nenhum pull request aberto. Abertacomp: core type: feature
angular/angularfire#3755 · 1 responsável ·
Mantenedores costumam responder em até 3 dias
Todas as issues de angular/angularfire
Issues semelhantes
-
[bug] diagnostics.dumpBody:Buffer 形态请求(透传 lane)跳过 dumps/ 落盘,仅留 raw/-unknown-Talvez já em andamento @ranxianglei assumiu hoje. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 62/100
ranxianglei/billion-context#2421 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
pending triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
nuxt/test-utils#1842 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
MoonshotAI/kimi-code#4146 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
farbenmeer/tapi#531 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
Mantenedores costumam responder em até 1 dia