Hmbown/CodeWhale · error · Error

npm package version does not match codewhaleBinaryVersion …

Error message

npm package version ${pkg.version} does not match codewhaleBinaryVersion ${version}. Set CODEWHALE_ALLOW_NPM_BINARY_MISMATCH=1 only for an intentional packaging-only npm release.

What it means

verify-release-assets asserts that the npm package.json version equals the codewhaleBinaryVersion the package points at. A mismatch means the npm release does not correspond to the binary release it references, which is only legitimate for deliberate packaging-only releases.

Solutions

  1. Align package.json version with codewhaleBinaryVersion (usually bump package.json to match the binary release)
  2. If this is intentionally packaging-only, set CODEWHALE_ALLOW_NPM_BINARY_MISMATCH=1 for this run
  3. Re-cut the release so both versions match

Example fix

// package.json
// before
"version": "0.9.6"
// after
"version": "0.9.7" // matches codewhaleBinaryVersion
Defensive patterns

Strategy: validation

Validate before calling

const pkg = require("./package.json");
if (pkg.version !== pkg.codewhaleBinaryVersion && process.env.CODEWHALE_ALLOW_NPM_BINARY_MISMATCH !== "1") {
  throw new Error(`version ${pkg.version} != codewhaleBinaryVersion ${pkg.codewhaleBinaryVersion}`);
}

Try / catch

try { await run(); } catch (e) { if (/does not match codewhaleBinaryVersion/.test(e.message)) { console.error("Bump package.json or set CODEWHALE_ALLOW_NPM_BINARY_MISMATCH=1 for packaging-only releases"); process.exitCode = 1; } else throw e; }

Prevention

When it happens

Trigger: Running the release-asset verification script (run()) when pkg.version !== version and CODEWHALE_ALLOW_NPM_BINARY_MISMATCH is not set to 1.

Common situations: Cutting an npm-only patch (e.g. fixing packaging scripts) without bumping codewhaleBinaryVersion; rebasing release branches so versions drift; forgetting to bump package.json after a binary release.

Understand the failure class

Background: Schema validation failed / invalid input schema: payload rejected because its shape doesn't match the expected schema — this error's family across 28 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15). Data as JSON: /api/errors/59ac30bcadb4d964. Report an issue: GitHub.

Appendix: source

Thrown at npm/codewhale/scripts/verify-release-assets.js:59

      process.env.CODEWHALE_USE_CNB_MIRROR,
  );
}

function packageVersionMatchesBinaryVersion(version) {
  return String(pkg.version).trim() === version;
}

function assertPackageVersionMatchesBinaryVersion(version) {
  if (packageVersionMatchesBinaryVersion(version)) {
    return;
  }
  if (process.env.CODEWHALE_ALLOW_NPM_BINARY_MISMATCH === "1") {
    console.log(
      `npm package version ${pkg.version} points at binary release ${version} (allowed packaging-only mismatch).`,
    );
    return;
  }
  throw new Error(
    `npm package version ${pkg.version} does not match codewhaleBinaryVersion ${version}. ` +
      "Set CODEWHALE_ALLOW_NPM_BINARY_MISMATCH=1 only for an intentional packaging-only npm release.",
  );
}

function requestStatus(url, method = "HEAD", redirects = 0) {
  if (redirects > 10) {
    throw new Error(`Too many redirects while checking ${url}`);
  }
  const client = url.startsWith("https:") ? https : http;
  return new Promise((resolve, reject) => {
    const req = client.request(
      url,
      {
        method,
        headers: {
          "User-Agent": "codewhale-npm-release-check",
        },

View on GitHub (pinned to 433685b202)