Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

A canary published right after another can read a stale `canary` tag

未關閉
#3,791 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 3 天內回覆

@armando-navarro 已經在處理了。

開始於 2026年10月8日。

  • #3794 來自 @armando-navarro —— 未關閉

評估

難度
3/5
預估耗時
半天
新手友好度
65/100
Issue 類型
缺陷
描述清晰度
基本清楚
活躍度
活躍
技術堆疊
github-actions, typescript
領域
release

研究方向

Look at the publish job in the CI workflow and the script that checks the canary tag before publishing (introduced in #3784). The fix should prevent the race condition where a pending canary publish is invisible during npm's malware scan. Verify by simulating two rapid canary publishes and checking that the dist-tag points to the newer version.

由索引模型根據 Issue 內容生成。

描述

comp: build/pipeline type: bug version: current (v17+)

#3784 made the publish job skip a canary whose commit is not after the commit of the canary already on npm. npm makes a new version, and the dist-tag the publish moved, visible only when its publish-time malware scan finishes, so that check can read a canary that is about to change.

Details
  • Over the eight canaries published since 2026-09-27, npm listed each version 56 to 249 seconds after the Publish step finished (median 127). GitHub's changelog calls the delay "typically around five minutes".
  • If two merges land close together and the older commit's publish starts inside that window, it reads the previous canary, passes the check, publishes, and leaves canary on the older build until the next merge.
Scope
  • Only the canary dist-tag is affected, so only npm install @angular/fire@canary and ng add @angular/fire@canary. latest and next move only on tagged releases.
  • It needs two merges to main within a few minutes of each other, with the older one's publish running second.
  • It lasts until the next merge publishes a newer canary.
主要語言
TypeScript
星號
7.8k
分支
2.2k
平均合併
3 天 2 小時
30 天內合併 PR
13

環境準備

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

angular/angularfire 的其他 Issue

查看 angular/angularfire 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。