{
  "id": 835062,
  "title": "My Publish Script Checks for Duplicates Before It Posts. Nothing Stops Two Checks From Passing at Once.",
  "url": "https://urgent.news/2026/08/14/my-publish-script-checks-for-duplicates-before-it-posts-nothing-stops",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-14T03:49:23.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/enjoy_kumawat/my-publish-script-checks-for-duplicates-before-it-posts-nothing-stops-two-checks-from-passing-at-3d7f"
  },
  "original_language": "en",
  "account": "The publish script for DEV.to checks if an article title has already been published to prevent duplicates. However, this guard is vulnerable to a race condition where two checks can pass at the same time. The idempotency guard, which aims to survive and treat the situation as safe to publish, only checks the newest 30 titles and fails to account for titles on further pages. This means that if two instances of the script run concurrently, both could potentially publish the same article title. The script was tested in a live environment with two threads, a shared fake server, and a threading.Barrier to ensure both checks were completed before either could post. Despite the guard's functionality, the script does not include a lock file to prevent concurrent invocations from publishing the same article, as the architecture of the pipeline uses fresh containers and pinned commits, meaning each instance operates on a separate filesystem.",
  "summary": "This repo's publish_devto.py has had two real bugs fixed in its idempotency guard already. On 2026-08-08, already_published() was found failing open on URLError — the exact ambiguous \"did my last POST actually land or not\" failure the guard exists to survive, silently treated as \"safe to publish anyway.\" A day earlier than that, the same function was found checking only the newest 30 titles…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}