Skip to content

chore(deps): bump changesets/action from 1 to 2 - #115

Open
totigm wants to merge 1 commit into
mainfrom
chore/changesets-action-v2
Open

totigm wants to merge 1 commit into
mainfrom
chore/changesets-action-v2

Conversation

@totigm

@totigm totigm commented Aug 30, 2026

Copy link
Copy Markdown
Owner

Supersedes #102, which was a bare version bump and would have broken the release pipeline.

Why the plain bump was not safe

changesets/action@v2 changed how it receives the GitHub credential:

Regardless of the push mode, custom GitHub tokens must be passed explicitly through the github-token input. The GITHUB_TOKEN environment variable and credentials configured by actions/checkout or embedded in remote URLs are not substitutes for this input.

release.yml passed it only via env: GITHUB_TOKEN, exactly the form v2 stopped accepting. #102 shows green CI, but that is misleading — no check in this repo exercises the release workflow, so the failure would only have appeared at the next publish, on main, after the version bump had already landed. That is the same shape as the outage we just worked through in #111.

This PR adds the github-token input alongside the bump.

What else v2 changes, and why it is fine here

  • Release commits and tags now push through the GitHub API by default. No configuration needed; the contents: write permission is already granted.
  • commit-mode was replaced by push-with-git-cli. This workflow never set commit-mode, so there is nothing to migrate.
  • .npmrc handling was dropped when NPM_TOKEN is set, in favour of trusted publishing. npm auth here already comes from actions/setup-node's registry-url plus NODE_AUTH_TOKEN, which is the arrangement v2 expects. The NPM_TOKEN env entry stays because the changesets CLI reads it — removing it is what caused the silent OIDC fallback fixed in fix(release): pass NPM_TOKEN to changesets, and point the landing at v0.11 #111.

Please merge this one deliberately

CI cannot prove this works; only a real release can. Worth merging when you can watch the next release run rather than letting it sit until a publish happens unattended. If it does fail, reverting to @v1 restores the current known-good pipeline.

Related and not included: #109 (@changesets/cli 2 → 3) is blocked — v3 declares "engines": { "pnpm": ">=10.0.0" } and this repo is pinned to pnpm@9.15.0 via packageManager. That needs a pnpm 9 → 10 upgrade first, which is its own change.

v2 no longer accepts the GitHub credential from the GITHUB_TOKEN
environment variable or from the remote that actions/checkout configures;
it must arrive as the github-token input. Without it the action cannot
open the release PR or push tags, and CI would not have caught it --
nothing in the test matrix exercises the release workflow.

Release commits and tags now go through the GitHub API rather than the
git CLI, which is v2's default and needs no configuration here. The
commit-mode input this repo never set is the one that was replaced.
@vercel

vercel Bot commented Aug 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
humanjs Ready Ready Preview Aug 30, 2026 10:41am

This branch was successfully deployed

1 active deployment
Preview — 243db1d7 Deployed Aug 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant