-
Notifications
You must be signed in to change notification settings - Fork 0
publish.yml: notify on failure #101
Copy link
Copy link
Open
Labels
afk-readyTight enough for autonomous-agent pickup; orthogonal to status:*Tight enough for autonomous-agent pickup; orthogonal to status:*enhancementNew feature or requestNew feature or requestkind:bseBug or small enhancement; opportunistic / throw-in workBug or small enhancement; opportunistic / throw-in workstatus: readySpec'd, awaiting pickupSpec'd, awaiting pickup
Description
Activity
Metadata
Metadata
Assignees
Labels
afk-readyTight enough for autonomous-agent pickup; orthogonal to status:*Tight enough for autonomous-agent pickup; orthogonal to status:*enhancementNew feature or requestNew feature or requestkind:bseBug or small enhancement; opportunistic / throw-in workBug or small enhancement; opportunistic / throw-in workstatus: readySpec'd, awaiting pickupSpec'd, awaiting pickup
Problem
publish.ymlfails silently. Nothing surfaces a failed release.Concrete instance: run 33986727640 (2026-09-05) failed publishing v2.1.0. The
NPM_TOKENsecret had expired on 2026-08-18, sonpm publishreturned:The tag
v2.1.0was already pushed by that point, so the repo looked released while npm, the MCP Registry, and GitHub Releases all stayed on 2.0.4. It sat that way for three days and was only caught by accident while working on an unrelated PR.The failure mode compounds: the npm step dies first, which skips the MCP Registry publish and the GitHub Release creation. One expired credential silently drops all three.
Acceptance criteria
publish.ymlhas a job or step guarded byif: failure()that fires when any publish step fails.Notes
Token expiry will recur — the replacement token has its own expiration date. This issue is about surfacing the class of failure, not preventing this one cause. See the Trusted Publishing issue for removing the token entirely.