Problem
When using step-security/changeset-action@v1.7.0 in a monorepo, if one package fails to publish (e.g., due to missing npm permissions for a new package), the entire action fails because getExecOutput throws on the non-zero exit code from changeset publish.
This means that even though changeset publish successfully publishes other packages and creates their git tags (New tag: lines in stdout), the action never processes those tags — no GitHub releases are created, and the published output is never set to true.
Upstream fix
This was fixed in upstream changesets/action@v1.9.0 (released June 3, 2026) via PR #535 by @Andarist:
Fixed an issue with GitHub releases not being created for successfully published packages when some packages failed to be published to the registry.
The fix adds ignoreReturnCode: true to the getExecOutput call in runPublish, allowing the action to still process New tag: lines and set the published output even when changeset publish exits with a non-zero code.
Request
Could you sync with upstream changesets/action@v1.9.0 to incorporate this fix?
Problem
When using
step-security/changeset-action@v1.7.0in a monorepo, if one package fails to publish (e.g., due to missing npm permissions for a new package), the entire action fails becausegetExecOutputthrows on the non-zero exit code fromchangeset publish.This means that even though
changeset publishsuccessfully publishes other packages and creates their git tags (New tag:lines in stdout), the action never processes those tags — no GitHub releases are created, and thepublishedoutput is never set totrue.Upstream fix
This was fixed in upstream
changesets/action@v1.9.0(released June 3, 2026) via PR #535 by @Andarist:The fix adds
ignoreReturnCode: trueto thegetExecOutputcall inrunPublish, allowing the action to still processNew tag:lines and set thepublishedoutput even whenchangeset publishexits with a non-zero code.Request
Could you sync with upstream
changesets/action@v1.9.0to incorporate this fix?