Components 3.x is in maintenance/security-critical support until its end-of-life date is set, but there is no way to ship a 3.x patch without harming the 4.x line. #375 needs one: a 3.6.2 that narrows the PrimeReact peers to >=11.0.0 <11.2.0. A security fix would need one urgently, and the path should exist before that happens rather than being designed during an incident.
Constraints found while investigating #375:
- 3.x was released from
main before 4.0. There is no 3.x branch; v3.6.1 is the latest 3.x tag.
- At v3.6.1,
publish-version runs npm publish --provenance without --tag, so publishing 3.6.2 that way would move npm latest from 4.x to 3.6.2 for every consumer.
cratis/release-action computes the next version from the repository's latest GitHub release or the highest version tag. A v3.6.2 GitHub release marked Latest would make the next 4.x release compute a 3.6.x version.
- npm trusted publishing is bound to the publishing workflow. A new workflow file or branch may need its own trusted-publisher entry, and nobody in this session has npm credentials to repair dist-tags by hand.
Done when:
Components 3.x is in maintenance/security-critical support until its end-of-life date is set, but there is no way to ship a 3.x patch without harming the 4.x line. #375 needs one: a 3.6.2 that narrows the PrimeReact peers to
>=11.0.0 <11.2.0. A security fix would need one urgently, and the path should exist before that happens rather than being designed during an incident.Constraints found while investigating #375:
mainbefore 4.0. There is no 3.x branch; v3.6.1 is the latest 3.x tag.publish-versionrunsnpm publish --provenancewithout--tag, so publishing 3.6.2 that way would move npmlatestfrom 4.x to 3.6.2 for every consumer.cratis/release-actioncomputes the next version from the repository's latest GitHub release or the highest version tag. A v3.6.2 GitHub release marked Latest would make the next 4.x release compute a 3.6.x version.Done when:
support/3.xbranch, cut from v3.6.1, can publish a 3.x patch with an explicit version, to a dedicated dist-tag (for examplev3-lts), without creating a GitHub release marked Latest.mainrelease still computes its version from 4.x.