Relationships
#3138 extension push offers to promote a yanked version, and extension promote does not check for a yank
Opened by skunk-ape · 10/7/2026
Summary
The CLI treats a yanked version like any other published version in both promote paths. extension push offers to promote a yanked version that sits on a lower channel. extension promote sends a yanked version to the server without checking first. Today the server accepts that promote (swamp-club#3040). Once #3040 is fixed the server refuses it, and the author gets an error only after picking an option the CLI should never have shown.
Where
Seen at swamp 0387ae0a.
src/libswamp/extensions/published_version_lookup.tsfindPublishedVersionreads onlyversionandchannelfrom/api/v1/extensions/<name>/versions. The response already includesyankedAt(and the version view carries the yank), but the lookup drops it, soPublishedVersioncannot say a version is yanked.src/domain/extensions/extension_publish_checks.tsevaluateVersionExistsandsrc/cli/commands/extension_push.tsresolveExistingVersionResponsegivechoose(promote / bump / stop) for a version on a lower channel, even when that version is yanked.src/libswamp/extensions/promote.tsextensionPromote(theresolveFromChannelpath) checks the channel order but not the yank before calling the server.src/infrastructure/http/extension_api_client.tscheckResponsekeeps only the body'serrorand drops other fields such asreason.
Reproduce
swamp extension push <manifest> -y --channel beta # @ns/ext@V on beta
swamp extension yank @ns/ext@V --reason test -y
swamp extension push <manifest> --channel rc # interactive: offers "promote"
swamp extension promote @ns/ext V --channel rc # calls the server without checkingExpected
- The version stays taken after a yank, so push still refuses to re-publish it. But it should offer only bump or stop, and say the version is yanked, with the reason.
extension promotefails before calling the server, naming the yank and the reason.
Notes
The server-side refusal is swamp-club#3040: promote of a yanked version (or of a version of a yanked extension) returns 409 with error naming the yank and its reason. That is the guarantee; this issue covers the CLI experience only. The yanked versions must stay in the /versions list, because version uniqueness covers them.
Open
No activity in this phase yet.
Sign in to post a ripple.