You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The job follows publish-homebrew and uses the same bot identity and signing key. It differs in one way: it always rebuilds the single branch release/cloudsmith-cli from the action's master and updates the open PR in place. A newer CLI release therefore replaces an unmerged bump, and two PRs never carry the same action version. Both jobs now share the signing setup through a new setup-cloudsmith-bot-git composite action. Without the ACTION_PUSH_TOKEN secret, the job only logs a skip.
Add the ACTION_PUSH_TOKEN secret. It must be a cloudsmith-bot token with contents and pull-request write access to cloudsmith-cli-action. A dedicated secret keeps TAP_PUSH_TOKEN limited to the tap. If that token already covers both repos, you can store the same value under the new name.
Local verification:
I ran the job's shell steps against a local clone, with a throwaway key and no push. The result was a commit from Cloudsmith Bot <vftbot@cloudsmith.io> with a valid SSH signature and the expected action.yml and CHANGELOG.md diff. A re-run made no changes.
Add a publish-action release job. It clones cloudsmith-cli-action as
cloudsmith-bot and runs the action's scripts/bump-cli-version.sh. Then it
makes a signed commit and opens a pull request, as publish-homebrew does
for the tap. Without the ACTION_PUSH_TOKEN secret, the job skips.
Move the Cloudsmith Bot commit-signing setup into the
setup-cloudsmith-bot-git composite action, which both jobs use.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Rebuild one release/cloudsmith-cli branch from the action master on each
CLI release, and update the open pull request. Two CLI releases before a
merge then cannot produce two pull requests with the same action version.
Run the job in one concurrency group.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Read the pin on the open release/cloudsmith-cli pull request before the
bump. When that pin is newer than this release, skip the job, so that a
re-run of an older CLI release cannot replace a newer pending bump.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR adds a
publish-actionjob to the release workflow. When the GitHub release is published, the job does these steps ascloudsmith-bot:cloudsmith-io/cloudsmith-cli-action.scripts/bump-cli-version.sh. The script pins the defaultcli-versionto the new release and adds a CHANGELOG release section.When that PR merges, the action repo tests the change and releases it. It also moves
v3. That logic is in cloudsmith-io/cloudsmith-cli-action#49.The job follows
publish-homebrewand uses the same bot identity and signing key. It differs in one way: it always rebuilds the single branchrelease/cloudsmith-clifrom the action'smasterand updates the open PR in place. A newer CLI release therefore replaces an unmerged bump, and two PRs never carry the same action version. Both jobs now share the signing setup through a newsetup-cloudsmith-bot-gitcomposite action. Without theACTION_PUSH_TOKENsecret, the job only logs a skip.Type of Change
Additional Notes
ACTION_PUSH_TOKENsecret. It must be acloudsmith-bottoken with contents and pull-request write access tocloudsmith-cli-action. A dedicated secret keepsTAP_PUSH_TOKENlimited to the tap. If that token already covers both repos, you can store the same value under the new name.Cloudsmith Bot <vftbot@cloudsmith.io>with a valid SSH signature and the expectedaction.ymlandCHANGELOG.mddiff. A re-run made no changes.🤖 Generated with Claude Code