Hmbown/CodeWhale · error · Error
npm package version does not match codewhaleBinaryVersion …
Error message
npm package version ${pkg.version} does not match codewhaleBinaryVersion ${version}. Set CODEWHALE_ALLOW_NPM_BINARY_MISMATCH=1 only for an intentional packaging-only npm release. What it means
verify-release-assets asserts that the npm package.json version equals the codewhaleBinaryVersion the package points at. A mismatch means the npm release does not correspond to the binary release it references, which is only legitimate for deliberate packaging-only releases.
Solutions
- Align package.json version with codewhaleBinaryVersion (usually bump package.json to match the binary release)
- If this is intentionally packaging-only, set CODEWHALE_ALLOW_NPM_BINARY_MISMATCH=1 for this run
- Re-cut the release so both versions match
Example fix
// package.json // before "version": "0.9.6" // after "version": "0.9.7" // matches codewhaleBinaryVersion
Defensive patterns
Strategy: validation
Validate before calling
const pkg = require("./package.json");
if (pkg.version !== pkg.codewhaleBinaryVersion && process.env.CODEWHALE_ALLOW_NPM_BINARY_MISMATCH !== "1") {
throw new Error(`version ${pkg.version} != codewhaleBinaryVersion ${pkg.codewhaleBinaryVersion}`);
} Try / catch
try { await run(); } catch (e) { if (/does not match codewhaleBinaryVersion/.test(e.message)) { console.error("Bump package.json or set CODEWHALE_ALLOW_NPM_BINARY_MISMATCH=1 for packaging-only releases"); process.exitCode = 1; } else throw e; } Prevention
- Bump package.json and codewhaleBinaryVersion together in release tooling
- Add a pre-release CI step running this verification
- Set CODEWHALE_ALLOW_NPM_BINARY_MISMATCH only in deliberate packaging-only release jobs
When it happens
Trigger: Running the release-asset verification script (run()) when pkg.version !== version and CODEWHALE_ALLOW_NPM_BINARY_MISMATCH is not set to 1.
Common situations: Cutting an npm-only patch (e.g. fixing packaging scripts) without bumping codewhaleBinaryVersion; rebasing release branches so versions drift; forgetting to bump package.json after a binary release.
Understand the failure class
Background: Schema validation failed / invalid input schema: payload rejected because its shape doesn't match the expected schema — this error's family across 28 libraries.
Related errors
- Downloaded release artifacts are missing
- No release.yml workflow run found for
- No successful asset-publishing job found in release.yml…
- npm pack metadata did not include a filename
- workspace packages have mixed versions
AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15).
Data as JSON: /api/errors/59ac30bcadb4d964.
Report an issue: GitHub.
Appendix: source
Thrown at npm/codewhale/scripts/verify-release-assets.js:59
process.env.CODEWHALE_USE_CNB_MIRROR,
);
}
function packageVersionMatchesBinaryVersion(version) {
return String(pkg.version).trim() === version;
}
function assertPackageVersionMatchesBinaryVersion(version) {
if (packageVersionMatchesBinaryVersion(version)) {
return;
}
if (process.env.CODEWHALE_ALLOW_NPM_BINARY_MISMATCH === "1") {
console.log(
`npm package version ${pkg.version} points at binary release ${version} (allowed packaging-only mismatch).`,
);
return;
}
throw new Error(
`npm package version ${pkg.version} does not match codewhaleBinaryVersion ${version}. ` +
"Set CODEWHALE_ALLOW_NPM_BINARY_MISMATCH=1 only for an intentional packaging-only npm release.",
);
}
function requestStatus(url, method = "HEAD", redirects = 0) {
if (redirects > 10) {
throw new Error(`Too many redirects while checking ${url}`);
}
const client = url.startsWith("https:") ? https : http;
return new Promise((resolve, reject) => {
const req = client.request(
url,
{
method,
headers: {
"User-Agent": "codewhale-npm-release-check",
},View on GitHub (pinned to 433685b202)