Conversation
v2 no longer accepts the GitHub credential from the GITHUB_TOKEN environment variable or from the remote that actions/checkout configures; it must arrive as the github-token input. Without it the action cannot open the release PR or push tags, and CI would not have caught it -- nothing in the test matrix exercises the release workflow. Release commits and tags now go through the GitHub API rather than the git CLI, which is v2's default and needs no configuration here. The commit-mode input this repo never set is the one that was replaced.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Supersedes #102, which was a bare version bump and would have broken the release pipeline.
Why the plain bump was not safe
changesets/action@v2changed how it receives the GitHub credential:release.ymlpassed it only viaenv: GITHUB_TOKEN, exactly the form v2 stopped accepting. #102 shows green CI, but that is misleading — no check in this repo exercises the release workflow, so the failure would only have appeared at the next publish, onmain, after the version bump had already landed. That is the same shape as the outage we just worked through in #111.This PR adds the
github-tokeninput alongside the bump.What else v2 changes, and why it is fine here
contents: writepermission is already granted.commit-modewas replaced bypush-with-git-cli. This workflow never setcommit-mode, so there is nothing to migrate..npmrchandling was dropped whenNPM_TOKENis set, in favour of trusted publishing. npm auth here already comes fromactions/setup-node'sregistry-urlplusNODE_AUTH_TOKEN, which is the arrangement v2 expects. TheNPM_TOKENenv entry stays because the changesets CLI reads it — removing it is what caused the silent OIDC fallback fixed in fix(release): pass NPM_TOKEN to changesets, and point the landing at v0.11 #111.Please merge this one deliberately
CI cannot prove this works; only a real release can. Worth merging when you can watch the next release run rather than letting it sit until a publish happens unattended. If it does fail, reverting to
@v1restores the current known-good pipeline.Related and not included: #109 (
@changesets/cli2 → 3) is blocked — v3 declares"engines": { "pnpm": ">=10.0.0" }and this repo is pinned topnpm@9.15.0viapackageManager. That needs a pnpm 9 → 10 upgrade first, which is its own change.