Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneesskunk-ape

Relationships

#3016 extension push --dry-run skips auth, collective and version-exists checks, and prints 'No API calls were made' while calling the registry

Opened by skunk-ape · 10/5/2026· Shipped 10/6/2026

Problem

A green swamp extension push --dry-run is not a green push. Dry-run skips authentication, the collective-membership check, the reserved-collective check and the version-exists check (src/libswamp/extensions/push.ts:551-595, :872), so an author can get a clean dry-run and then fail on push for any of those. #1393 was the same class for the label cap and shipped a local check; this issue covers the remaining registry-side checks.

Two further mismatches:

  • With credentials present, dry-run still calls GET /extensions/{name}/latest for the version-drift check (extension_push.ts:572-590), and still calls OSV and npm, yet the summary prints "No API calls were made." (renderer :283).
  • CI runs the real push with --yes from swamp repo init --tool none inside the extension directory (swamp-extensions publish.yml:113-118), a layout no local dry-run reproduces unless the author does the same by hand.

Expected

  • With credentials present, dry-run runs auth, collective membership, reserved-collective and version-exists as read-only checks and reports each result the way the real push would. Without credentials it says which checks it could not run.
  • The summary lists the API calls actually made (registry, OSV, npm), or says none were made only when that is true.
  • The CI layout is reproducible locally: a documented recipe in the swamp skill, or a flag, so the author can run exactly what publish.yml runs.

Acceptance

  • Dry-run against a version that already exists on the target channel reports it, exit non-zero, same wording as the real push.
  • Dry-run against a collective the caller is not a member of reports it.
  • Dry-run summary for a run that hit the registry lists that call; a run with no credentials and --skip-upgrade-check says no calls were made and makes none (verify with a network trace or a fake fetcher).

Out of scope

Explaining entitlement refusals by plan is #1545, which follows this issue in the same lane.

Source: the extension push assessment (2026-10-02, swamp 20261002.194016) and the Extension Push UX Plan, which groups this with its lane and order.

02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPED+ 1 MOREASSIGNED+ 5 MOREREVIEW+ 18 MOREPR_MERGED+ 2 MORESESSION_SUMMARIZED

Shipped

10/6/2026, 3:17:01 PM

Click a lifecycle step above to view its details.

03Sludge Pulse
skunk-ape assigned skunk-ape10/6/2026, 1:53:03 PM
Editable. Press Enter to edit.

skunk-ape commented 10/6/2026, 4:50:35 PM

Post-ship note (2026-10-06): the first release carrying this (20261006.152703.0) and every release since fail the swamp-uat release UAT in 22 dry-run tests, so stable has not promoted past 20261006.150249.0. Cause: the dry run now runs collective-membership read-only with credentials present, and the UAT fixtures publish under collectives the CI account (@swamp-uat) is not in. The swamp behaviour is as designed; the suite assumed a dry run was registry-free. Fix in swamp-uat (cue work item uat-dry-run: fixtures derive the collective from whoami, positive tests for the new verdicts). One real defect found: the authentication verdict prints 'Signed in as .' for an API-key credential, filed as #3088. Process gap: this item shipped without a UAT work item alongside it, which is how the suite went unadjusted.

Sign in to post a ripple.