Skip to content

fix(ci): bump @changesets/cli to v3 and update release workflow for changesets/action v2 - #52

Merged
toiroakr merged 1 commit into
mainfrom
fix/changesets-v3-action-v2
Aug 24, 2026
Merged

toiroakr merged 1 commit into
mainfrom
fix/changesets-v3-action-v2

Conversation

@toiroakr

@toiroakr toiroakr commented Aug 19, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Bumped @changesets/cli from 2.31.1 to 3.0.0. changesets/action v2
    validates at startup that the project is on Changesets CLI v3 and fails
    otherwise, so the cli bump and the workflow rewrite below ship together in
    this one PR to avoid a broken intermediate state on main.
  • Bumped changesets/action from v1 to v2, which renamed its root inputs
    to kebab-case with different names:
    • version -> version-script
    • publish -> publish-script
    • title -> pr-title
    • commit -> commit-message
    • createGithubReleases -> create-github-releases
  • Dropped commitMode: "github-api", which is not a valid v2 input — pushing
    commits/tags via the GitHub API is now the default (push-with-git-cli: false).
  • Moved the token from env: GITHUB_TOKEN to with: github-token, since v2
    no longer reads the GITHUB_TOKEN environment variable for authentication.

Summary by CodeRabbit

  • Chores
    • Updated the release automation to use newer, securely pinned tooling.
    • Upgraded Changesets support for improved release and publishing workflows.
    • Updated the Changesets command-line tooling to the latest major version.

…hangesets/action v2

changesets/action v2 validates that the project uses Changesets CLI v3 at
startup and fails otherwise, so the cli bump and the workflow rewrite must
ship together. Renamed the action inputs to the v2 kebab-case schema
(version -> version-script, publish -> publish-script, title -> pr-title,
commit -> commit-message, createGithubReleases -> create-github-releases),
dropped commitMode (removed; GitHub API push is now the default), and moved
the token from env: GITHUB_TOKEN to with: github-token, which v2 requires.
@coderabbitai

coderabbitai Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 04eb1f67-9537-4543-b8f9-77848396d2d9

📥 Commits

Reviewing files that changed from the base of the PR and between 19bbfee and 0b8527b.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (2)
  • .github/workflows/release.yml
  • package.json

📝 Walkthrough

Walkthrough

The release tooling updates pinned GitHub Actions, migrates the Changesets action inputs to v2.1.1, and upgrades @changesets/cli to 3.0.0.

Changes

Release tooling

Layer / File(s) Summary
Release workflow and Changesets update
.github/workflows/release.yml, package.json
The workflow pins third-party actions to commit SHAs. It uses the Changesets v2 input names and github-token. The development dependency upgrades to @changesets/cli 3.0.0.

Estimated code review effort: 2 (Simple) | ~10 minutes

Poem

A rabbit checks the release gate,
With pinned tools that now stay straight.
Changesets hops to version three,
New inputs guide the workflow tree.
NPM_CONFIG_PROVENANCE keeps its place.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/changesets-v3-action-v2

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

Coverage Summary

File               | % Stmts | % Branch | % Funcs | % Lines | Uncovered Line #s 
-------------------|---------|----------|---------|---------|-------------------
All files          |   70.89 |    57.74 |      40 |   70.89 |                   
 zod-empty         |       0 |        0 |       0 |       0 |                   
  tsdown.config.ts |       0 |        0 |       0 |       0 | 1-9               
 ...-hook-form/src |       0 |        0 |       0 |       0 |                   
  App.tsx          |       0 |        0 |       0 |       0 | 1-38              
  main.tsx         |       0 |        0 |       0 |       0 | 1-10              
 zod-empty/src     |   82.97 |    58.99 |     100 |   82.97 |                   
  index.ts         |   82.97 |    58.99 |     100 |   82.97 | ...62,364,366-372 
-------------------|---------|----------|---------|---------|-------------------

@pkg-pr-new

pkg-pr-new Bot commented Aug 19, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/zod-empty@52

commit: 0b8527b

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​changesets/​cli@​2.31.1 ⏵ 3.0.099 +210074 -2597 +2100

View full report

@toiroakr
toiroakr marked this pull request as ready for review August 24, 2026 02:28
@toiroakr
toiroakr merged commit 010bf17 into main Aug 24, 2026
13 checks passed
@toiroakr
toiroakr deleted the fix/changesets-v3-action-v2 branch August 24, 2026 02:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant