Repository navigation
ci: repair the release workflow for changesets/action v2 - #433
Merged
Merged
Conversation
Dependabot bumped changesets/action to v2 (#431), which requires Changesets CLI 3 and renamed its inputs, so every Release run since fails before doing anything. Bump @changesets/cli to 3.0.3 and @changesets/changelog-github to 1.0.1, point the config schema at @changesets/config 4, and use the v2 input names. Also let the action use a CHANGESETS_TOKEN secret when present: the default GITHUB_TOKEN cannot push a branch that changes a workflow file (release run #47 failed updating the version PR after #425 touched release.yml) and PRs it opens don't trigger CI. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VR63CHdvbRNYKvpNqMWVdm
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The Release workflow has failed on the last three pushes to
main(runs 47, 48, 49), so the pending 2.5.0 version PR (#432) cannot be updated or published. Two different causes:changesets/action@v2(build(deps): bump changesets/action from 1 to 2 #431). v2 requires Changesets CLI 3 and renamed all its inputs (publish→publish-script,commit→commit-message,title→pr-title,createGithubReleases→create-github-releases). The action aborts with "This version of the Changesets action is designed to work with Changesets CLI v3".refusing to allow a GitHub App to create or update workflow .github/workflows/release.yml without workflows permission. The version branch is rebuilt frommain, and ci: run the type check and tests before publishing a release #425 had just changedrelease.yml, which the defaultGITHUB_TOKENmay not push. This will recur every time a workflow file changes onmainwhile a version PR is open.Changes
@changesets/cli2.29.8 → 3.0.3 and@changesets/changelog-github0.5.2 → 1.0.1;.changeset/config.jsonschema →@changesets/config@4.0.1. CLI 3 needs Node ^22.11 or ^24 and pnpm ≥ 10, which.nvmrc(24) andpackageManager(pnpm 10.30.1) satisfy. Its breaking changes (changeset tag→git-tag,prettierconfig option →format, private packages not versioned by default,versionexits 1 with no changesets) do not affect this repo: the config uses none of those options and the action checks for changesets before runningversion. The existing changeset files need no changes (pnpm changeset statusreads them and reports the pending minor bump).release.ymluses the v2 input names.github-tokenand theGITHUB_TOKENenv fall back throughsecrets.CHANGESETS_TOKEN || secrets.GITHUB_TOKEN, with a comment explaining why. Nothing changes until the secret exists..claude/settings.json(new): Claude Code sessions on this repo no longer append the Claude Code footer or session link to pull request descriptions.This also clears the remaining 8
pnpm auditadvisories (js-yamlvia@changesets/cli2); only the dev-onlyesbuildone via tsup remains.What you need to do
CHANGESETS_TOKENrepository secret. That fixes cause 2 permanently and also makes CI run on the "chore: version packages" PRs, which the audit flagged (§4.4). With the secret in place, the next push tomainafter merging this PR should update chore: version packages #432 successfully.changeset-release/mainbranch before or right after merging, so the action can create a fresh version PR. Creating the branch works because the only new commit is the version commit, which touches no workflow file; updating it after a future workflow change will fail again until a token with the Workflows permission is used.No changeset: tooling only.
Test plan
pnpm install,pnpm changeset status(CLI 3.0.3 reads the pending changesets: one minor bump),pnpm run typecheck,pnpm run test(642 passed, 1 expected failure)changesets/action'saction.ymlonmainmaingets past "Create Release Pull Request or Publish" and updates or recreates the version PR