chore(deps): update changesets/action action to v2 - #1271
renovate[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub. 1 Skipped Deployment
|
Coverage Report
File CoverageNo changed files found. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
| - name: Create version pull request or publish to npm | ||
| id: changesets | ||
| uses: changesets/action@a45c4d594aa4e2c509dc14a9f2b3b67ba3780d0d # v1.9.0 | ||
| uses: changesets/action@22ccf9aa43179fe9e27dc62e575971d28cce197c # v2.0.0 |
There was a problem hiding this comment.
Action v2 needs CLI v3
High Severity
changesets/action@v2 requires Changesets CLI v3 and rejects CLI v2. This repo still depends on @changesets/cli v2 (^2.31.1), so the release job will fail its version check. Action v2 users on CLI v2 are expected to stay on changesets/action@v1 until the CLI is upgraded.
Reviewed by Cursor Bugbot for commit 47678e0. Configure here.
| - name: Create version pull request or publish to npm | ||
| id: changesets | ||
| uses: changesets/action@a45c4d594aa4e2c509dc14a9f2b3b67ba3780d0d # v1.9.0 | ||
| uses: changesets/action@22ccf9aa43179fe9e27dc62e575971d28cce197c # v2.0.0 |
There was a problem hiding this comment.
v1 action inputs left unchanged
High Severity
The workflow still passes v1 camelCase inputs (publish, title, commit, createGithubReleases, setupGitUser) and authenticates via the GITHUB_TOKEN env var. In v2 those become publish-script, pr-title, commit-message, create-github-releases, and the github-token input; unknown inputs and the env token are ignored. The publish script would not run, the app token would not be used, and GitHub releases would default back on without make_latest control.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 47678e0. Configure here.
ee23ecf to
0fcfa91
Compare
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
There are 3 total unresolved issues (including 2 from previous reviews).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 0fcfa91. Configure here.
| - name: Create version pull request or publish to npm | ||
| id: changesets | ||
| uses: changesets/action@a45c4d594aa4e2c509dc14a9f2b3b67ba3780d0d # v1.9.0 | ||
| uses: changesets/action@8488615a623b1b9c987934bb89eae8af6a946ac1 # v2.1.1 |
There was a problem hiding this comment.
App token no longer reaches action
High Severity
v2 requires custom tokens on the github-token input and no longer reads GITHUB_TOKEN. This job only grants contents: read to the default github.token, so version PRs and GitHub API pushes for release commits or tags will fail after the bump.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 0fcfa91. Configure here.
0fcfa91 to
eae88e6
Compare
5ae794f to
7e0c6ba
Compare
7e0c6ba to
08ce87d
Compare


This PR contains the following updates:
v1.9.0→v2.1.2Release Notes
changesets/action (changesets/action)
v2.1.2Compare Source
Patch Changes
#735
8833883Thanks @bluwy! - Handle error when pushing git tags with the git CLI#724
36f529fThanks @bluwy! - Improve log messages#724
36f529fThanks @bluwy! - Fix root action double error logs#729
ca85897Thanks @bluwy! - Always switch and reset branch when generating version commits, similar to ifpush-with-git-cliis enabledv2.1.1Compare Source
Patch Changes
da1ea29Thanks @KEBABSELLER6! - Fixed typo in renamed inputs from v1 to v2v2.1.0Compare Source
Minor Changes
3b7c71cThanks @bluwy! - Add acwdinput to the root action,/select-mode,/version,/pack, and/publishsub-actions to set the current working directory to execute Changesets in. This input existed in v1 but was incorrectly removed.Patch Changes
6f58ba3Thanks @bluwy! - Updatepr-statusmessage to link to the new faq pagev2.0.0Compare Source
Major Changes
#692
cb3f011Thanks @Andarist! - Release commits and tags are now pushed using the GitHub API by default.Replace the
commit-modeinput with the booleanpush-with-git-cliinput. Setpush-with-git-cli: trueto continue using the Git CLI.Regardless of the push mode, custom GitHub tokens must be passed explicitly through the
github-tokeninput. TheGITHUB_TOKENenvironment variable and credentials configured byactions/checkoutor embedded in remote URLs are not substitutes for this input. When the Git CLI is enabled,github-tokentakes precedence over those repository credentials.#680
ca57073Thanks @bluwy! - Add a newpush-git-tagsoption that complementscreate-github-releasesto control specifically if git tags should be created but not GitHub releases.If
create-github-releaseswas previously set tofalse, which also indirectly disabled git tag creation, git tags will now be created instead by default. If this is not desired, setpush-git-tagstofalseexplicitly.#657
4f718b5Thanks @Andarist! - Removed compatibility support for old Changesets v1.#681
7359107Thanks @bluwy! - Rename the root action inputs and outputs to better match the sub-actions' conventions.Inputs:
version->version-scriptpublish->publish-scriptcommit->commit-messagetitle->pr-titlebranch->pr-base-branchOutputs:
pull-request-number->pr-number#674
164652bThanks @bluwy! - Remove support for passing custom GitHub token through the GITHUB_TOKEN environment variable. It should be passed to thegithub-tokeninput instead.#659
5649ff4Thanks @bluwy! - Removecwdoption forchangesets/action. Use the stepworking-directoryoption instead to change the directory.#673
823cf74Thanks @bluwy! - Update to Changesets v3 packages#695
469993cThanks @bluwy! - Removed.npmrchandling when theNPM_TOKENenvironment variable is set.Authentication should be handled via Trusted Publishing instead. If a token is still needed, use
actions/setup-nodeto set it up instead via theregistry-urloption. Check out the updated action README for more information of setting up npm authentication in GitHub Actions.#668
0eae789Thanks @bluwy! - Rename the input and output names to kebab-case instead of camelCase to match the official GitHub actions patternMinor Changes
#656
a12d90dThanks @bluwy! - Add new/select-mode,/version, and/publishsub-actions to better control version and publish steps#678
f71ae04Thanks @Andarist! - Published packages detection done through stdout parsing was replaced with one based on the shared output file usingCHANGESETS_OUTPUTenvironment variable. When using custom scripts this environment variable should always be passed down to the Changesets CLI invocations.Patch Changes
#699
5b307d3Thanks @Andarist! - Validate that projects use Changesets CLI v3 and direct Changesets CLI v2 users tochangesets/action@v1.#697
84d78c6Thanks @Andarist! - Allow custom publish scripts to complete without a Changesets output file, warning that GitHub releases and git tags cannot be created when that file is missing.#670
5a8b9b7Thanks @Andarist! - Authenticate git CLI pushes with the configured GitHub token using Git extra headers instead of writing to a global.netrcfile.#670
5a8b9b7Thanks @Andarist! - Derive the Git server URL from the GitHub Actions context when configuring git CLI authentication to support GitHub Enterprise Server setups.#688
219ea82Thanks @Andarist! - Remove thesetup-git-userinput. Complete custom Git identities are now preserved automatically, whilegithub-actions[bot]is configured as a fallback before creating local release commits or tags.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate using a curated preset maintained by
. View repository job log here
Note
High Risk
This is a major bump on the job that versions packages and publishes to npm; action v2 has breaking behavior (inputs, GitHub token, Changesets CLI v3) that this diff does not migrate, so the release pipeline may fail or behave differently after merge.
Overview
Updates the Release workflow to pin
changesets/actionfrom v1.9.0 to v2.1.2 (new commit SHA only). The step’swithblock, env vars, and downstream release steps are unchanged in this diff.Reviewed by Cursor Bugbot for commit 08ce87d. Bugbot is set up for automated code reviews on this repo. Configure here.