Skip to content

fix(release): fix semantic-release fail-step crash (@semantic-release/github $owner bug) - #1

Merged
SahinurDEV merged 1 commit into
mainfrom
fix/release-workflow
Oct 9, 2026
Merged

SahinurDEV merged 1 commit into
mainfrom
fix/release-workflow

Conversation

@SahinurDEV

Copy link
Copy Markdown
Owner

Why the Release workflow fails

Run: https://github.com/SahinurDEV/ForgeData/actions/runs/37893945394 (commit f66e6e3). The single Release job fails in the npx semantic-release step with two errors:

  1. Invalid npm token (root cause, owner-side, not fixed by this PR).

    npm error 401 Unauthorized - GET https://registry.npmjs.org/-/whoami
    [semantic-release] › ✘  EINVALIDNPMTOKEN Invalid npm token.
    

    @semantic-release/npm rejects the NPM_TOKEN repo secret (last updated 2026-07-09). npm granular tokens with write access expire after at most 90 days, so this one most likely expired around 2026-10-07. Whatever the reason, the secret has to be replaced.

  2. The plugin's fail step crashes (fixed here).

    ✘  Failed step "fail" of plugin "@semantic-release/github"
    Error: Variable $owner of type String! was provided invalid value
    

    semantic-release@24.2.9 pulls in @semantic-release/github@11.0.6, the latest 11.x release. In that version lib/fail.js calls findSRIssues(octokit, logger, failTitle, labels, owner, repo), but find-sr-issues.js only takes (octokit, logger, labels, owner, repo). The extra argument pushes the labels array into $owner, so GitHub's GraphQL API rejects the query. Because of this, a failed release never opens its "release failed" issue. The bug is not caused by the account rename. 12.x fixes the call.

Change

  • Add an npm overrides entry in package.json that pins @semantic-release/github to ^12.0.10 and regenerate package-lock.json. Its peer dependency (semantic-release >=24.1.0) and engine requirement (node ^22.14 || >=24.10) both fit this workflow, which uses node-version: 22.x.

Verification

  • A clean npm ci works. npm ls @semantic-release/github shows 12.0.10 overridden.
  • npm run lint, npm run typecheck, npm run test:coverage (26 files, 250 tests) and npm run build all pass.
  • I ran the plugin's fail() with a mocked Octokit. The GraphQL variables now come out as {"owner":"SahinurDEV","repo":"ForgeData",...} and the step finishes without error.

Owner action still required

The Release job will still fail until NPM_TOKEN is valid. Do one of the following:

  • Create a new npm granular access token with Read and write access to @sahinur/forgedata that can publish without an OTP ("bypass 2FA"). Save it under Settings → Secrets and variables → Actions → NPM_TOKEN. Note that it will expire again.
  • Or switch to npm Trusted Publishing (OIDC) for this repo/workflow on npmjs.com. The workflow already has id-token: write. This needs @semantic-release/npm ≥ 13.1 (that is, semantic-release 25), which would be a separate upgrade.

Also: v0.1.1 and v0.2.0 were tagged and published to npm by hand, and no Release run has ever succeeded. The next good run will use these tags as its baseline.

…il-step crash

@semantic-release/github 11.0.6 (pulled in by semantic-release 24.2.9) passes
failTitle as an extra positional argument to findSRIssues(), shifting owner
into the wrong slot, so the 'fail' step crashes with
'Variable $owner of type String! was provided invalid value' instead of
opening the failure issue. 12.0.10 fixes the call.
@SahinurDEV
SahinurDEV merged commit 320f685 into main Oct 9, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant