fix(release): regenerate and stage both template lockfiles on publish - #626
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The release artifact can embed private JFrog URLs in the regenerated lockfiles.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Regenerates both template lockfiles during release publishing to keep pnpm-first scaffolds synchronized.
Changes:
- Adds retryable npm/pnpm lockfile regeneration and staging.
- Regenerates both locks in the release artifact workflow.
| File | Description |
|---|---|
tools/publish-template-tag.ts |
Regenerates and stages both lockfiles. |
.github/workflows/prepare-release.yml |
Adds pnpm lockfile regeneration. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Contributor
🤖 AppKit PR bot🔬 Run evalsStart an eval for this PR from the evals-monitor app: Go to Evals Monitor → 📦 Try this PR's app templateScaffolds a new app from this PR's SDK build. Run it in any folder (requires the GitHub CLI — gh run download 37030059932 -R databricks/appkit -n appkit-template-0.82.0-pr.875dabd-template-publish-626 -D appkit-pr-626 \
&& unzip -o "appkit-pr-626/appkit-template-0.82.0-pr.875dabd-template-publish-626.zip" -d "appkit-pr-626" \
&& databricks apps init --template "appkit-pr-626"The template pins |
MarioCadenas
approved these changes
Oct 2, 2026
pkosiec
reviewed
Oct 2, 2026
The app template is pnpm-first and ships both package-lock.json and pnpm-lock.yaml, but the release-publish sites only refreshed the npm lock, shipping a stale pnpm-lock.yaml pinned to the previous appkit version. Scaffolded apps default to pnpm and then fail `pnpm install --frozen-lockfile` (ERR_PNPM_OUTDATED_LOCKFILE) or silently re-resolve. - publish-template-tag.ts: share the registry-propagation retry between npm and pnpm, add `pnpm install --lockfile-only --no-frozen-lockfile`, a pnpm preflight (fail loud, never skip the pnpm lock), and stage pnpm-lock.yaml. - prepare-release.yml: regenerate both locks in the template artifact, then rewrite them back to public npm (fail-closed, mirroring ci.yml), since that job installs under the JFrog .npmrc. This also fixes a pre-existing leak: package-lock.json has resolved against JFrog in this artifact since #263. Co-authored-by: Isaac <no-reply@databricks.com> Signed-off-by: Atila Fassina <atila@fassina.eu>
atilafassina
force-pushed
the
template-publish
branch
from
October 2, 2026 15:52
9662276 to
7e2c939
Compare
atilafassina
enabled auto-merge (squash)
October 2, 2026 15:56
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What
The app template is pnpm-first and ships both
template/package-lock.jsonandtemplate/pnpm-lock.yaml(since #593), but the release-publish sites only refreshed the npm lock. The publishedtemplate-vX.X.Xtag therefore shipped apnpm-lock.yamlpinned to the previous appkit version. Because scaffolded apps default to pnpm, they then failpnpm install --frozen-lockfile(ERR_PNPM_OUTDATED_LOCKFILE) or silently re-resolve to an untested tree.This completes the "two-headed lock regeneration (CI/release)" item from the pnpm-first template work at the two release-publish sites #593 left on the npm-only path.
How the template uses two lockfiles
This is one template that carries both lockfiles as two package-manager variants — not two separate templates. At
databricks apps init(and inselectSmokePackageManager), the chosen PM's files are kept and the other's are deleted:pnpm-lock.yaml+pnpm-workspace.yaml+.npmrc, deletepackage-lock.jsonpackage-lock.json, deletepnpm-lock.yaml+pnpm-workspace.yaml+.npmrc(and setpackageManager: npm@…)So the scaffolded app a user ends up with has exactly one lockfile matching their chosen PM.
detectPackageManagercheckspnpm-lock.yamlbeforepackage-lock.json, which is why the non-chosen lock must be removed. Because either lock can be the one selected, both must be version-correct in what we publish — which is exactly why this fix regenerates and validates both, not just the npm one.Changes
tools/publish-template-tag.tspnpm install --lockfile-only --no-frozen-lockfileto regeneratetemplate/pnpm-lock.yamlagainst the bumped versions (--no-frozen-lockfilerequired because pnpm defaults to frozen under CI;--lockfile-onlyskips rebuildingnode_modules).template/pnpm-lock.yamlalongside the npm lock..github/workflows/prepare-release.ymlci.yml's existing dual-regen.ci.yml), since the artifact job installs under the JFrog.npmrc. This also fixes a pre-existing leak:package-lock.jsonhas resolved against JFrog in this artifact since the job was added in feat: add template artifact to prepare-release pipeline #263.No changes needed in the secure release repo — it already provisions pnpm and installs from public npm.
Testing
pnpm check,pnpm -r typecheck,pnpm testall green (5361 passed).Follow-up
A stacked PR adds the recurrence guard: a version-parity verifier that aborts the release and fails PR CI if a template lockfile doesn't resolve the released version.
This pull request and its description were written by Isaac.