From bfbeed0be6a504761061374b76b27aa02419d573 Mon Sep 17 00:00:00 2001 From: Austin Burdine Date: Tue, 6 Oct 2026 11:43:39 -0400 Subject: [PATCH] Wait for new Ghost version on npm before committing/opening upstream PR The ghost-version-publish dispatch can fire before the new version is installable from npm, and the Ghost-CLI images run "ghost install" against npm at build time, so both this repo's CI and the official-images PR checks were failing on the race. Poll the registry (abbreviated and full packuments, plus the tarball) for up to 30 minutes before pushing anything. --- .github/workflows/update.yml | 40 ++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) diff --git a/.github/workflows/update.yml b/.github/workflows/update.yml index 01f2ba0e..d4ace893 100644 --- a/.github/workflows/update.yml +++ b/.github/workflows/update.yml @@ -136,6 +136,46 @@ jobs: if: steps.inputs.outputs.dry_run == 'true' run: git diff + # the ghost-version-publish dispatch can arrive before the new Ghost version + # is installable from npm (the registry and its CDN lag the publish), and + # the Ghost-CLI images run "ghost install " against npm at build + # time; pushing the commit (which kicks off this repo's CI) or opening the + # upstream PR before then just fails CI. + # the "-next" images install from the GitHub release tarball instead, which + # versions.sh already waits for, so only versions with a .cli pin are checked + - name: Wait for Ghost on npm + if: steps.inputs.outputs.dry_run != 'true' && (steps.changes.outputs.changed == 'true' || steps.inputs.outputs.make_image_pr == 'true') + timeout-minutes: 35 + run: | + deadline=$(( SECONDS + 30 * 60 )) + for version in $(jq --raw-output '[ .[] | select(has("cli")) | .version ] | unique[]' versions.json); do + export version + until ( + # check both packument flavors: npm clients request the abbreviated + # one, others the full one, and each is cached independently + for accept in 'application/vnd.npm.install-v1+json' 'application/json'; do + tarball="$( + curl -fsSL --connect-timeout 10 --max-time 60 \ + --header "Accept: $accept" \ + --header 'Cache-Control: no-cache' \ + 'https://registry.npmjs.org/ghost' \ + | jq --raw-output '.versions[env.version].dist.tarball // empty' + )" + [ -n "$tarball" ] || exit 1 + done + # the tarball is served separately from the metadata + curl -fsSL --head --connect-timeout 10 --max-time 60 "$tarball" > /dev/null + ); do + if [ "$SECONDS" -ge "$deadline" ]; then + echo >&2 "error: ghost@$version is still not available on npm; re-run this workflow once it is" + exit 1 + fi + echo "ghost@$version is not available on npm yet; waiting..." + sleep 30 + done + echo "ghost@$version is available on npm." + done + - name: Commit and push changes id: commit if: steps.inputs.outputs.dry_run != 'true' && steps.changes.outputs.changed == 'true'