@@ -113,7 +113,9 @@ version-specific `release-<version>` npm tag if `latest` or `prerelease` has
113113advanced, so recovery never intentionally downgrades those channels. A version
114114already on npm with a missing/stale channel tag fails closed: npm OIDC cannot
115115perform ` npm dist-tag add ` , so an npm administrator must repair that tag
116- separately.
116+ separately. The npm dist-tag recheck cannot prevent a concurrent publisher
117+ from advancing a tag between the read and ` npm publish --tag ` ; the cutover
118+ requires exclusive ownership of these packages' channel tags.
117119
118120** Required setup before cutover:** On npmjs.com, configure an npm trusted
119121publisher ** with ` npm publish ` permission** for each of the nine packages:
@@ -127,7 +129,16 @@ repository is `github/copilot-cli`); leave environment unset. Use GitHub-hosted
127129runners. The workflow uses Node 24, npm >= 11.5.1 and ` id-token: write ` , with
128130no ` NPM_TOKEN ` or ` NODE_AUTH_TOKEN ` . The runtime repository must continue its
129131existing publishing until this workflow is merged ** and all nine npm trusted
130- publishers are configured** ; only then should its npm publication be cut over.
132+ publishers are configured** . At cutover, disable the old runtime
133+ ` publish-cli.yml ` workflow, wait for all its in-progress and queued runs to
134+ finish, then merge the runtime workflow change. Retire any other publisher
135+ of these nine packages and prohibit reruns of older runtime release runs.
136+ Only then set the ` CLI_NPM_RELEASE_CUTOVER_COMPLETE ` repository Actions
137+ variable to ` true ` in ` github/copilot-cli ` and re-enable the updated runtime
138+ workflow. Without this variable the new workflow fails before any npm
139+ publish, including manual recovery. If an external publisher is restarted,
140+ unset the variable before publishing another release; a dist-tag read is
141+ not a concurrency lock.
131142Its internal Azure feed publication and ancillary release tasks remain separate.
132143The release artifact producer must attach the nine actual npm package tarballs
133144under the new ` npm-github-copilot- ` names before cutover. Older releases such as
0 commit comments