Skip to content

feat(ENG-14534): open a cloudsmith-cli-action bump PR on each release - #451

Open
cloudsmith-iduffy wants to merge 3 commits into
masterfrom
eng-14534-auto-release-cloudsmith-cli-action-on-every-cloudsmith-cli
Open

cloudsmith-iduffy wants to merge 3 commits into
masterfrom
eng-14534-auto-release-cloudsmith-cli-action-on-every-cloudsmith-cli

Conversation

@cloudsmith-iduffy

@cloudsmith-iduffy cloudsmith-iduffy commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Description

This PR adds a publish-action job to the release workflow. When the GitHub release is published, the job does these steps as cloudsmith-bot:

  1. It clones cloudsmith-io/cloudsmith-cli-action.
  2. It runs that repo's scripts/bump-cli-version.sh. The script pins the default cli-version to the new release and adds a CHANGELOG release section.
  3. It makes an SSH-signed commit and opens a PR.

When that PR merges, the action repo tests the change and releases it. It also moves v3. That logic is in cloudsmith-io/cloudsmith-cli-action#49.

The job follows publish-homebrew and uses the same bot identity and signing key. It differs in one way: it always rebuilds the single branch release/cloudsmith-cli from the action's master and updates the open PR in place. A newer CLI release therefore replaces an unmerged bump, and two PRs never carry the same action version. Both jobs now share the signing setup through a new setup-cloudsmith-bot-git composite action. Without the ACTION_PUSH_TOKEN secret, the job only logs a skip.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Refactoring
  • Other (please describe)

Additional Notes

  • Merge feat(ENG-14534): pin the CLI version and release on each CLI bump cloudsmith-cli-action#49 first. This job runs a script that exists only after Bump pyyaml from 5.1 to 5.4 in /requirements #49 merges.
  • Add the ACTION_PUSH_TOKEN secret. It must be a cloudsmith-bot token with contents and pull-request write access to cloudsmith-cli-action. A dedicated secret keeps TAP_PUSH_TOKEN limited to the tap. If that token already covers both repos, you can store the same value under the new name.
  • Local verification:
    • I ran the job's shell steps against a local clone, with a throwaway key and no push. The result was a commit from Cloudsmith Bot <vftbot@cloudsmith.io> with a valid SSH signature and the expected action.yml and CHANGELOG.md diff. A re-run made no changes.
    • zizmor passes.

🤖 Generated with Claude Code

Add a publish-action release job. It clones cloudsmith-cli-action as
cloudsmith-bot and runs the action's scripts/bump-cli-version.sh. Then it
makes a signed commit and opens a pull request, as publish-homebrew does
for the tap. Without the ACTION_PUSH_TOKEN secret, the job skips.

Move the Cloudsmith Bot commit-signing setup into the
setup-cloudsmith-bot-git composite action, which both jobs use.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 21:49
@cloudsmith-iduffy
cloudsmith-iduffy requested a review from a team as a code owner October 1, 2026 21:49
Comment thread .github/workflows/release.yml Dismissed
Comment thread .github/workflows/release.yml Dismissed

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Concurrent releases can generate duplicate action versions and prevent the later action release.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds automation to update cloudsmith-cli-action after each CLI release.

Changes:

  • Adds a release job that opens a signed version-bump PR.
  • Extracts shared bot signing setup into a composite action.
File Description
.github/​workflows/​release.yml Adds action-repository publishing and reuses signing setup.
.github/​actions/​setup-cloudsmith-bot-git/​action.yml Configures Cloudsmith Bot identity and SSH signing.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/release.yml
Rebuild one release/cloudsmith-cli branch from the action master on each
CLI release, and update the open pull request. Two CLI releases before a
merge then cannot produce two pull requests with the same action version.
Run the job in one concurrency group.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Older release reruns can overwrite a newer unmerged action bump.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Low severity Add required copyright comment to new source file

.github/​actions/​setup-cloudsmith-bot-git/​action.yml:1

This new source file is missing the repository-required copyright comment near the top.

Comment thread .github/workflows/release.yml
Read the pin on the open release/cloudsmith-cli pull request before the
bump. When that pin is newer than this release, skip the job, so that a
re-run of an older CLI release cannot replace a newer pending bump.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Release queue replacement and a PR-merge race can cause action bumps to be lost.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
Resolved since last review (1)

Comment on lines +675 to +677
concurrency:
group: publish-action
cancel-in-progress: false
Comment on lines +725 to +731
if [ -z "${PR_NUMBER}" ]; then
gh pr create --repo "${ACTION_REPO}" \
--head "${BRANCH}" --base master \
--title "${TITLE}" --body "${BODY}"
else
gh pr edit "${PR_NUMBER}" --repo "${ACTION_REPO}" \
--title "${TITLE}" --body "${BODY}"

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants