Repository navigation
Expect publish output to be shared through a file - #678
Merged
Merged
Conversation
🦋 Changeset detectedLatest commit: 414d99c The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
beeequeue
reviewed
Jun 27, 2026
Andarist
marked this pull request as ready for review
June 30, 2026 07:44
bluwy
approved these changes
Jun 30, 2026
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
This was referenced Jul 1, 2026
Merged
Merged
6 of 7 tasks
arshad-shah
added a commit
to arshad-shah/extforge
that referenced
this pull request
Sep 1, 2026
The 1.0.0 and 1.1.0 releases published to npm but created no git tag and no GitHub release, while the workflow reported success. changesets/action v1 detects what was published by regex-matching `changeset publish` stdout for `New tag: <pkg>@<version>`. #77 upgraded @changesets/cli to v3, whose clack-style output no longer prints that line, so the action concluded nothing had been published and skipped both the tag push and the release creation without failing. Tags were created on the runner and discarded with it — which is why `git ls-remote --tags` still stops at 0.6.0. Upstream replaced stdout parsing with a CHANGESETS_OUTPUT file in v2 (changesets/action#678) and v2 now rejects the CLI v2/action v1 mismatch outright (changesets/action#699). v2 renamed every input, so this is not a bare SHA bump: version -> version-script, publish -> publish-script, commit -> commit-message, title -> pr-title. Both env vars are dropped. GITHUB_TOKEN is no longer read from the environment (changesets/action#674); the `github-token` input defaults to `github.token`, which is what was being passed. NPM_TOKEN is no longer used to write an .npmrc (changesets/action#695) — publishing already goes through OIDC trusted publishing, confirmed by the SLSA provenance attestation on the published 1.1.0 tarball. v2 pushes commits and tags through the GitHub API rather than the git CLI, so `persist-credentials: false` stays safe and tags are signed with GitHub's GPG key. Claude-Session: https://claude.ai/code/session_01AZSFjNFjuoeXUjuFkA6Cha Co-authored-by: Arshad shah <arshad.shah@hmhco.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
ByronDWall
pushed a commit
to commercetools/nimbus
that referenced
this pull request
Sep 23, 2026
…1995) * ci(release): upgrade changesets/action to v2 for @changesets/cli v3 @changesets/cli v3 no longer prints the "New tag: <pkg>@<version>" lines that changesets/action v1.9.0 scraped to learn which packages were published. The action therefore saw zero published packages: it pushed no git tags, created no GitHub releases, and set published=false -- while npm publishing itself succeeded. 3.6.0 reached npm with no GitHub release history because of this, and the publish step still reported success. Two v3 breaking changes combined to produce the failed run: - Published-package detection moved from stdout parsing to a shared output file named by CHANGESETS_OUTPUT (changesets/action#678). Action v1 has no such support and reported published=false, which skipped tagging and releases and also un-gated the canary step below. - `changeset version` now exits 1 when there are no unreleased changesets (changesets/changesets#1860); v2 exited 0 silently. That turned the un-gated canary step into a hard job failure. Upstream treats these as a matched pair and action v2 validates it, refusing CLI v2 (changesets/action#699). There is no equivalent check in v1 for CLI v3, which is why the mismatch degraded silently instead of failing fast. Changes: - changesets/action v1.9.0 -> v2.1.2, using v2's renamed kebab-case inputs and passing the app token through the `github-token` input, which is now required for custom tokens. `commitMode: github-api` is dropped because v2 uses the GitHub API by default. - Guard both canary steps on the presence of changeset files, so an emptied .changeset/ is a clean skip rather than exit 1. - Add a step asserting that the version present on npm has a matching git tag, so a silent tagging failure fails the job instead of reporting success. - Remove scripts/print_release_version.sh and its step. Its output was read nowhere in the workflow, its exit code was swallowed by the surrounding command substitution, and it ran `changeset version` followed by `git reset --hard` inside the release job. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * ci(release): trim the comments added with the changesets v2 upgrade The explanatory blocks restated the commit message and PR description, which git blame already reaches, and ran six to eight lines in a file whose idiom is one- to three-line constraint notes. Keep only what is not visible in the code and would be re-broken if removed: that the action and CLI majors move together, that the tag check is deliberately independent of the action's own report, and why the canary steps test for changeset files before versioning. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix #553