SIGN IN SIGN UP

fix(ci): run the release on the Bun that rewrites the lockfile (#128)

## Summary

The Publish run for 0.15.0 failed: the release plugin bumped the three
package manifests, refreshed `bun.lock`, read it back, and found it
still recording 0.14.1.

```text
│  Plugin "domainkit-lockfile-sync" failed during applyCliDraft:
│  bun.lock is behind the manifests: @domainkit/capsuledb 0.14.1 != 0.15.0,
│  @domainkit/react 0.14.1 != 0.15.0, domainkit 0.14.1 != 0.15.0
```

Bun 1.4.0 does not treat a workspace version as a lockfile change. With
the three manifests already bumped to 0.15.0:

| Bun | `bun install --lockfile-only` | `bun.lock` records |
| ----- | ---------------------------------------------- |
------------------ |
| 1.4.0 | `Done! Checked 1709 packages (no changes)` | 0.14.1 |
| 1.4.0 | same with `--no-frozen-lockfile` | 0.14.1 |
| 1.4.2 | `Saved bun.lock (1709 packages)` | 0.15.0 |

The version commit is `git add -A`, so a lockfile behind its manifests
would ship on `main`; the plugin's readback is what turns that into a
failed release instead. This moves the release onto the Bun that writes
them.

## Changes

- `packageManager` and every workflow's `bun-version` move to 1.4.2, the
version the gates already run on locally. Cache keys move with them.

## Review notes

Reproduced both versions against this repo in `oven/bun:1.4.0` and
`oven/bun:1.4.2` with the manifests bumped, which is the table above.
Merging this reruns Publish on the merge commit and opens the version PR
for `domainkit` 0.15.0.
S
Saatvik Arya committed
89863e3c34cf7a12cd29292406d7ebfee910848b
Parent: 8596c2b
Committed by GitHub <noreply@github.com> on 9/19/2026, 8:05:56 AM