Skip to content

ci: repair the release workflow for changesets/action v2 - #433

Merged
matthewhudson merged 1 commit into
mainfrom
claude/changesets-v3
Sep 28, 2026
Merged

matthewhudson merged 1 commit into
mainfrom
claude/changesets-v3

Conversation

@matthewhudson

@matthewhudson matthewhudson commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Summary

The Release workflow has failed on the last three pushes to main (runs 47, 48, 49), so the pending 2.5.0 version PR (#432) cannot be updated or published. Two different causes:

  1. Runs 48 and 49: Dependabot's bump to changesets/action@v2 (build(deps): bump changesets/action from 1 to 2 #431). v2 requires Changesets CLI 3 and renamed all its inputs (publish → publish-script, commit → commit-message, title → pr-title, createGithubReleases → create-github-releases). The action aborts with "This version of the Changesets action is designed to work with Changesets CLI v3".
  2. Run 47: with the action still on v1, updating the version-PR branch was rejected: refusing to allow a GitHub App to create or update workflow .github/workflows/release.yml without workflows permission. The version branch is rebuilt from main, and ci: run the type check and tests before publishing a release #425 had just changed release.yml, which the default GITHUB_TOKEN may not push. This will recur every time a workflow file changes on main while a version PR is open.

Changes

  • @changesets/cli 2.29.8 → 3.0.3 and @changesets/changelog-github 0.5.2 → 1.0.1; .changeset/config.json schema → @changesets/config@4.0.1. CLI 3 needs Node ^22.11 or ^24 and pnpm ≥ 10, which .nvmrc (24) and packageManager (pnpm 10.30.1) satisfy. Its breaking changes (changeset tag → git-tag, prettier config option → format, private packages not versioned by default, version exits 1 with no changesets) do not affect this repo: the config uses none of those options and the action checks for changesets before running version. The existing changeset files need no changes (pnpm changeset status reads them and reports the pending minor bump).
  • release.yml uses the v2 input names.
  • The action's github-token and the GITHUB_TOKEN env fall back through secrets.CHANGESETS_TOKEN || secrets.GITHUB_TOKEN, with a comment explaining why. Nothing changes until the secret exists.
  • .claude/settings.json (new): Claude Code sessions on this repo no longer append the Claude Code footer or session link to pull request descriptions.

This also clears the remaining 8 pnpm audit advisories (js-yaml via @changesets/cli 2); only the dev-only esbuild one via tsup remains.

What you need to do

  • Recommended: create a fine-grained PAT scoped to this repository with Contents, Pull requests and Workflows read/write, and add it as the CHANGESETS_TOKEN repository secret. That fixes cause 2 permanently and also makes CI run on the "chore: version packages" PRs, which the audit flagged (§4.4). With the secret in place, the next push to main after merging this PR should update chore: version packages #432 successfully.
  • Without the secret: close chore: version packages #432 and delete the changeset-release/main branch before or right after merging, so the action can create a fresh version PR. Creating the branch works because the only new commit is the version commit, which touches no workflow file; updating it after a future workflow change will fail again until a token with the Workflows permission is used.

No changeset: tooling only.

Test plan

  • pnpm install, pnpm changeset status (CLI 3.0.3 reads the pending changesets: one minor bump), pnpm run typecheck, pnpm run test (642 passed, 1 expected failure)
  • Input names checked against changesets/action's action.yml on main
  • After merge: the Release run on main gets past "Create Release Pull Request or Publish" and updates or recreates the version PR

Dependabot bumped changesets/action to v2 (#431), which requires
Changesets CLI 3 and renamed its inputs, so every Release run since
fails before doing anything. Bump @changesets/cli to 3.0.3 and
@changesets/changelog-github to 1.0.1, point the config schema at
@changesets/config 4, and use the v2 input names.

Also let the action use a CHANGESETS_TOKEN secret when present: the
default GITHUB_TOKEN cannot push a branch that changes a workflow file
(release run #47 failed updating the version PR after #425 touched
release.yml) and PRs it opens don't trigger CI.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VR63CHdvbRNYKvpNqMWVdm
@matthewhudson
matthewhudson merged commit e0ec7e0 into main Sep 28, 2026
3 checks passed
@matthewhudson
matthewhudson deleted the claude/changesets-v3 branch September 28, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant