What happened (2026-09-21)
Dispatched build-router.yml with publish=true on branch fix/router-knn-embedder-pkg-native-types (run 35610002495). All five build jobs and the Publish Router Platform Packages job reported success, but nothing reached npm. The job log shows every platform publish failing:
npm error code E404
npm error 404 Not Found - PUT https://registry.npmjs.org/@ruvector%2frouter-darwin-arm64 - Not found
Failed to publish @ruvector/router-darwin-arm64
npm returns 404 (not 403) for an unauthenticated/unauthorized publish to a scoped package, so this is the repo's NPM_TOKEN secret being expired/rotated or lacking publish rights on @ruvector/*. (The last router publish that worked was 0.1.30 on 2026-04-06.)
Why it looked green
.github/workflows/build-router.yml:
npm publish --access public || echo "Failed to publish @ruvector/router-${platform}"
...
run: npm publish --access public || echo "Package may already exist"
A publish step that cannot fail is worse than no CI: the optional-deps-resolvable-on-npm guard on the PR then fails with no obvious cause.
Proposed fix
- Rotate
NPM_TOKEN (granular token, publish scope, packages @ruvector/*).
- Replace both
|| echo … with a real failure. If "already published" must stay tolerated, check first:
if npm view "@ruvector/router-${platform}@${VERSION}" version >/dev/null 2>&1; then echo "already published"; else npm publish --access public; fi
- Add a post-publish verification step (
npm view <pkg>@<version> version for all six packages) so the job's conclusion means "it is on the registry".
- Consider
npm publish --provenance now that publishes run from GitHub Actions.
The 0.1.31 packages were published from the maintainer's local session using the exact CI-built artifacts from run 35610002495 to unblock #1005.
🤖 Generated with claude-flow
What happened (2026-09-21)
Dispatched
build-router.ymlwithpublish=trueon branchfix/router-knn-embedder-pkg-native-types(run 35610002495). All five build jobs and the Publish Router Platform Packages job reported success, but nothing reached npm. The job log shows every platform publish failing:npm returns 404 (not 403) for an unauthenticated/unauthorized publish to a scoped package, so this is the repo's
NPM_TOKENsecret being expired/rotated or lacking publish rights on@ruvector/*. (The last router publish that worked was 0.1.30 on 2026-04-06.)Why it looked green
.github/workflows/build-router.yml:A publish step that cannot fail is worse than no CI: the
optional-deps-resolvable-on-npmguard on the PR then fails with no obvious cause.Proposed fix
NPM_TOKEN(granular token, publish scope, packages@ruvector/*).|| echo …with a real failure. If "already published" must stay tolerated, check first:npm view <pkg>@<version> versionfor all six packages) so the job's conclusion means "it is on the registry".npm publish --provenancenow that publishes run from GitHub Actions.The 0.1.31 packages were published from the maintainer's local session using the exact CI-built artifacts from run 35610002495 to unblock #1005.
🤖 Generated with claude-flow