Relationships
#3015 extension push: --accept-warnings separate from --yes, and --json exits non-zero instead of skipping the warnings prompt
Opened by skunk-ape · 10/5/2026· Shipped 10/5/2026
Problem
swamp extension push has two prompts on the way to a publish: "Continue with push despite warnings? [y/N]" and "Push @ to registry? [y/N]". One flag, --yes, answers both (src/cli/commands/extension_push.ts:552-566 and :635). CI therefore cannot confirm a push without also waiving every warning, including a real safety warning. In --json mode the warnings prompt is skipped silently and the push proceeds.
Across 42 dry-runs in the assessment every extension carried at least one warning (42/42 "no adversarial review recorded"), so in practice --yes is always waiving something, and nothing records that it did.
Expected
--yesconfirms the push. It does not waive warnings.- A new
--accept-warningswaives warnings. The push summary (log and JSON) records that warnings were accepted and lists them. - A non-interactive run (
--json, or no TTY) that hits a warning without--accept-warningsexits non-zero and names the flag it needs, instead of skipping the prompt. - Interactive behaviour is unchanged: two prompts, two answers.
Acceptance
push --dry-run --jsonon an extension with a warning and no--accept-warnings: non-zero exit, error names--accept-warnings.- The same with
--accept-warnings: exit 0, output carries the accepted warnings. push --yeson an extension with a warning, interactive: still prompts for the warnings.- swamp-extensions
.forgejo/workflows/publish.ymlis updated to pass both flags where it passed--yesalone.
Out of scope
Per-rule suppression in the manifest and the channel-aware prompts (#2939) are separate issues in the same lane and build on this one.
Source: the extension push assessment (2026-10-02, swamp 20261002.194016) and the Extension Push UX Plan, which groups this with its lane and order.
Shipped
Click a lifecycle step above to view its details.
skunk-ape commented 10/5/2026, 2:34:53 PM
Guardrail: this must not make a push easier by weakening a gate. --accept-warnings waives warnings only (never errors), every waived warning is recorded in the push output and should travel with the push so the registry can show it, and the non-interactive default becomes stricter (exit non-zero), not looser.
skunk-ape commented 10/5/2026, 9:59:57 PM
Follow-up: the flag split shipped in 20261005.154947.0 broke non-interactive publishes for external CI (every clean-runner push carries the adversarial-review warning). #3047 restores --yes waiving warnings, keeps the acceptedWarnings record this issue added, and keeps --accept-warnings as an optional alias. The long-term shape is declared acceptances (#3021, being redesigned), not a blanket flag.
Sign in to post a ripple.