Prevent @astrojs/upgrade from downgrading packages when a dist-tag points to an older version#17216
Merged
Conversation
…\n\nWhen running , the resolveTargetVersion() function\nunconditionally used the version from the beta dist-tag without checking\nif it would be a downgrade from the currently installed version.\n\nThis caused packages like @astrojs/sitemap (3.7.3 → 3.6.1-beta.3) and\n@astrojs/rss (4.0.18 → 4.0.15-beta.4) to be downgraded.\n\nAdded a semver comparison that falls back to the dist-tag when\nthe requested dist-tag version is older than what's currently installed.
1 task
|
matthewp
approved these changes
Jun 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
resolveTargetVersion()now compares the dist-tag version against the currently installed version before applying it. If the dist-tag resolves to an older version than what's installed, the function falls back tolatestinstead of downgrading.pnpm dlx @astrojs/upgrade betawould silently downgrade companion packages (e.g.@astrojs/sitemapfrom3.7.3→3.6.1-beta.3) when theirbetadist-tag pointed to a pre-release that predated the current stable.resolveTargetVersionis now exported so it can be unit-tested directly.Testing
describe('resolveTargetVersion')inpackages/upgrade/test/verify.test.tswith three cases: no-downgrade when the beta dist-tag is older than the installed version; correct upgrade when the beta dist-tag is newer; and fallback tolatestwhen the requested dist-tag doesn't exist on the registry.Docs
@astrojs/upgradebehavior with no API surface change.Closes #17024