A canary published right after another can read a stale `canary` tag
Maintainer thường phản hồi trong vòng 3 ngày
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- Nửa ngày
- Mức phù hợp với người mới
- 65/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- github-actions, typescript
- Lĩnh vực
- release
Hướng nghiên cứu
Look at the publish job in the CI workflow and the script that checks the canary tag before publishing (introduced in #3784). The fix should prevent the race condition where a pending canary publish is invisible during npm's malware scan. Verify by simulating two rapid canary publishes and checking that the dist-tag points to the newer version.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
#3784 made the publish job skip a canary whose commit is not after the commit of the canary already on npm. npm makes a new version, and the dist-tag the publish moved, visible only when its publish-time malware scan finishes, so that check can read a canary that is about to change.
Details
- Over the eight canaries published since 2026-09-27, npm listed each version 56 to 249 seconds after the Publish step finished (median 127). GitHub's changelog calls the delay "typically around five minutes".
- If two merges land close together and the older commit's publish starts inside that window, it reads the previous canary, passes the check, publishes, and leaves
canaryon the older build until the next merge.
Scope
- Only the
canarydist-tag is affected, so onlynpm install @angular/fire@canaryandng add @angular/fire@canary.latestandnextmove only on tagged releases. - It needs two merges to
mainwithin a few minutes of each other, with the older one's publish running second. - It lasts until the next merge publishes a newer canary.
- Ngôn ngữ chính
- TypeScript
- Star
- 7.8k
- Fork
- 2.2k
- Merge trung bình
- 3 ngày 2 giờ
- Pull request đã merge (30 ngày)
- 13
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của angular/angularfire
-
A 20.x release after 21.0.0 would move `latest` back to 20.x, and `next` stays on the release candidateCó thể đã có người làm @armando-navarro đã nhận hôm nay. Đang mởcomp: build/pipeline type: bug version: current (v17+)
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
angular/angularfire#3790 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
docs: the App Check guide does not cover server-side renderingCó thể đã có người làm @armando-navarro đã nhận 10 ngày trước. Đang mởcomp: app-check comp: docs comp: ssr type: chore version: current (v17+)
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
angular/angularfire#3774 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
`ng update @angular/fire` stops before the v21 migration when it runs Angular CLI 22.3Có thể đã có người làm @armando-navarro đã nhận hôm nay. Đang mởcomp: schematics type: bug version: current (v17+)
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 25/100
angular/angularfire#3789 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Use `TransferState` to hand server-rendered Firestore data to the browser, instead of reading every document twiceCó thể làm lại được @armando-navarro đã nhận 37 ngày trước và không có pull request nào đang mở. Đang mởcomp: firestore comp: ssr priority: P0 (critical) type: feature version: current (v17+)
angular/angularfire#3757 · 1 người được giao ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Six `firebase` entry points have no `@angular/fire` equivalent, so their exports are unreachableCó thể làm lại được @armando-navarro đã nhận 37 ngày trước và không có pull request nào đang mở. Đang mởcomp: core type: feature
angular/angularfire#3755 · 1 người được giao ·
Maintainer thường phản hồi trong vòng 3 ngày
Tất cả issue của angular/angularfire
Issue tương tự
-
DB-plane provider_chat_options.* is accepted by config set but never merged into the loaded configĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Bump Firebase JS SDK (12.19.0 → 13.0.0)Có thể đã có người làm @SelaseKay đã nhận hôm nay. Đang mởNeeds Attention type: enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
invertase/react-native-firebase#9364 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
clouflaure de fernandoĐang mởenhancement
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
cloudflare/mcp#271 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 4 ngày
-
[fullsend] E2E: rhdh-version-override — run-e2e.sh overrides RHDH_VERSION to non-existent 2.1Đang mởe2e-failure ready-to-code
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
redhat-developer/rhdh-plugin-export-overlays#4261 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày