nodeSolidServer / nodeSolidServer/node-solid-server
npm: Hash-based Publishing Breaking Semver Convention
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 1.8k
- Forks
- 308
- PR merge metrics
- No merged PRs in 30d
Description
For many years, NSS has followed semver with branch protection and reviews. Since December 2025, CI was changed to publish hash-versioned packages on every push and PR, creating new versions on each commit regardless of whether functionality has changed.
Suggested fix:
- Remove the hash-based npm-publish-build job, or
- Add a version-exists check to prevent duplicate publishes.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Locate the CI configuration containing the hash-based npm-publish-build job and read how it publishes packages on pushes and pull requests. Make the publishing workflow either remove that job or check whether a version already exists, then verify that unchanged commits do not create duplicate package versions.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, nodejs
- Domain
- ci-cd, release
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 62/100