A canary published right after another can read a stale `canary` tag
維護者通常 3 天內回覆
評估
- 難度
- 3/5
- 預估耗時
- 半天
- 新手友好度
- 65/100
- Issue 類型
- 缺陷
- 描述清晰度
- 基本清楚
- 活躍度
- 活躍
- 技術堆疊
- github-actions, typescript
- 領域
- release
研究方向
Look at the publish job in the CI workflow and the script that checks the canary tag before publishing (introduced in #3784). The fix should prevent the race condition where a pending canary publish is invisible during npm's malware scan. Verify by simulating two rapid canary publishes and checking that the dist-tag points to the newer version.
由索引模型根據 Issue 內容生成。
描述
#3784 made the publish job skip a canary whose commit is not after the commit of the canary already on npm. npm makes a new version, and the dist-tag the publish moved, visible only when its publish-time malware scan finishes, so that check can read a canary that is about to change.
Details
- Over the eight canaries published since 2026-09-27, npm listed each version 56 to 249 seconds after the Publish step finished (median 127). GitHub's changelog calls the delay "typically around five minutes".
- If two merges land close together and the older commit's publish starts inside that window, it reads the previous canary, passes the check, publishes, and leaves
canaryon the older build until the next merge.
Scope
- Only the
canarydist-tag is affected, so onlynpm install @angular/fire@canaryandng add @angular/fire@canary.latestandnextmove only on tagged releases. - It needs two merges to
mainwithin a few minutes of each other, with the older one's publish running second. - It lasts until the next merge publishes a newer canary.
- 主要語言
- TypeScript
- 星號
- 7.8k
- 分支
- 2.2k
- 平均合併
- 3 天 2 小時
- 30 天內合併 PR
- 13
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
angular/angularfire 的其他 Issue
-
A 20.x release after 21.0.0 would move `latest` back to 20.x, and `next` stays on the release candidate可能已有人在做 @armando-navarro 今天認領。 未關閉comp: build/pipeline type: bug version: current (v17+)
難度 2/5 1-3 小時 新手友好度 85/100
angular/angularfire#3790 ·
維護者通常 3 天內回覆
-
docs: the App Check guide does not cover server-side rendering可能已有人在做 @armando-navarro 於 10 天前認領。 未關閉comp: app-check comp: docs comp: ssr type: chore version: current (v17+)
難度 2/5 1-3 小時 新手友好度 88/100
angular/angularfire#3774 ·
維護者通常 3 天內回覆
-
`ng update @angular/fire` stops before the v21 migration when it runs Angular CLI 22.3可能已有人在做 @armando-navarro 今天認領。 未關閉comp: schematics type: bug version: current (v17+)
難度 3/5 1-2 天 新手友好度 25/100
angular/angularfire#3789 ·
維護者通常 3 天內回覆
-
Use `TransferState` to hand server-rendered Firestore data to the browser, instead of reading every document twice可能重新可做 @armando-navarro 於 38 天前認領,目前沒有進行中的 PR。 未關閉comp: firestore comp: ssr priority: P0 (critical) type: feature version: current (v17+)
angular/angularfire#3757 · 已指派 1 人 ·
維護者通常 3 天內回覆
-
Six `firebase` entry points have no `@angular/fire` equivalent, so their exports are unreachable可能重新可做 @armando-navarro 於 38 天前認領,目前沒有進行中的 PR。 未關閉comp: core type: feature
angular/angularfire#3755 · 已指派 1 人 ·
維護者通常 3 天內回覆
查看 angular/angularfire 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 76/100
維護者通常 1 天內回覆
-
難度 1/5 1-3 小時 新手友好度 84/100
answerLoops/answerLoops#345 ·
維護者通常 1 天內回覆
-
難度 1/5 1 小時以內 新手友好度 82/100
siyuan-note/siyuan#20313 ·
維護者通常 1 天內回覆
-
bug
難度 2/5 1-3 小時 新手友好度 78/100
LanternOps/breeze#8254 ·
維護者通常 1 天內回覆
-
難度 1/5 1-3 小時 新手友好度 82/100
gofish-graphics/gofish-graphics#1084 ·
維護者通常 1 天內回覆