Skip to content

Verify npm propagation and clean installation before MCP publication - #55

Merged
jakezwang merged 1 commit into
masterfrom
codex/npm-publication-readiness
Sep 24, 2026
Merged

jakezwang merged 1 commit into
masterfrom
codex/npm-publication-readiness

Conversation

@jakezwang

Copy link
Copy Markdown
Collaborator

npm can accept an upload before the exact version becomes publicly readable. The previous one-minute MCP check could fail during that propagation window despite a successful npm publish.

Add a shared verifier that polls the public registry for up to 15 minutes at 30-second intervals. After publishing, require a fresh npm install with an isolated prefix/cache, verify the installed binary against the matching GitHub release SHA256SUMS, and run its CLI launcher. MCP uses the same bounded wait in metadata-only mode. Exact stable versions are required by default; workflows explicitly enable exact prereleases to preserve existing support. Recovery instructions distinguish an accepted upload from an upload failure and avoid republishing immutable versions.

Validation:

  • All 12 Node release/installer/verifier tests pass, covering propagation retries, deadline enforcement, cache isolation, checksum mismatch and wrong CLI version.
  • Actual public argonctl@2.1.2 fresh installation passed SHA256 verification and returned argon version 2.1.2; metadata-only mode also passed.
  • A nonexistent public version exited nonzero after the requested 1,200 ms deadline.
  • Node syntax, actionlint on the three affected workflows, and diff whitespace checks pass.

No release tag, VERSION, or published package changed. Hold merge for release coordination.

@jakezwang
jakezwang merged commit 505f1f1 into master Sep 24, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant