* fix(release): reject leading-zero versions and pre-check npm before publish
The validate-version job used ^[0-9]+\.[0-9]+\.0$ which accepted leading
zeros (e.g. 1.01.0). npm version silently normalises such inputs to their
canonical semver form (1.1.0), creating divergent state across npm, git
tags, GitHub releases, and release branches — leaving orphaned artefacts
that require manual surgery to clean up.
Two changes to the validate-version job only:
1. Replace the format regex with ^(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.0$
so any segment with a leading zero is rejected in under 5 seconds with
an error message that includes the offending value.
2. Add a "Reject already-published versions" step that calls
`npm view $pkg@$VERSION` for both packages before any branch, install,
or build work begins. Duplicate-version requests now fail fast instead
of burning ~10 minutes before dying at the dry-run publish step.
Adds ADR-0175 documenting the incident, the decisions, and the recovery
runbook for the orphaned v1.01.0 / v1.03.0 artefacts.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* docs(adr): rename ADR to issue-number format per CONTRIBUTING.md policy
Renames docs/adr/0175-release-version-validation.md to
docs/adr/218-release-version-validation.md to match the issue-number
prefix convention required by CONTRIBUTING.md (section: Proposing an
ADR or PRD). Issue #218 was opened to track this CI hardening work.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>