Skip to content

Add a safe release path for Components 3.x maintenance fixes #379

Description

@woksin

Components 3.x is in maintenance/security-critical support until its end-of-life date is set, but there is no way to ship a 3.x patch without harming the 4.x line. #375 needs one: a 3.6.2 that narrows the PrimeReact peers to >=11.0.0 <11.2.0. A security fix would need one urgently, and the path should exist before that happens rather than being designed during an incident.

Constraints found while investigating #375:

  • 3.x was released from main before 4.0. There is no 3.x branch; v3.6.1 is the latest 3.x tag.
  • At v3.6.1, publish-version runs npm publish --provenance without --tag, so publishing 3.6.2 that way would move npm latest from 4.x to 3.6.2 for every consumer.
  • cratis/release-action computes the next version from the repository's latest GitHub release or the highest version tag. A v3.6.2 GitHub release marked Latest would make the next 4.x release compute a 3.6.x version.
  • npm trusted publishing is bound to the publishing workflow. A new workflow file or branch may need its own trusted-publisher entry, and nobody in this session has npm credentials to repair dist-tags by hand.

Done when:

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions