Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
44 commits
Select commit Hold shift + click to select a range
feb3bf3
migrate to `pnpm` (#609)
github-actions[bot] Jun 9, 2026
0a80953
migrate to `pnpm` (#609)
github-actions[bot] Jun 9, 2026
c0e6fed
migrate to `pnpm` (#609)
github-actions[bot] Jun 9, 2026
192c4c4
migrate to `pnpm` (#609)
github-actions[bot] Jun 9, 2026
d0978fe
migrate to `pnpm` (#609)
github-actions[bot] Jun 9, 2026
bd9c950
migrate to `pnpm` (#609)
github-actions[bot] Jun 9, 2026
df886c1
migrate to `pnpm` (#609)
github-actions[bot] Jun 9, 2026
f3bdc4f
Migrate to oxfmt (#618)
github-actions[bot] Jun 9, 2026
edc2f21
Migrate to oxfmt (#618)
github-actions[bot] Jun 9, 2026
2dfcba5
Migrate to oxfmt (#618)
github-actions[bot] Jun 9, 2026
3109a17
Migrate to oxfmt (#618)
github-actions[bot] Jun 9, 2026
e0a8357
Migrate to oxfmt (#618)
github-actions[bot] Jun 9, 2026
013e4f8
Migrate to oxfmt (#618)
github-actions[bot] Jun 9, 2026
4f4ac82
Migrate to oxfmt (#618)
github-actions[bot] Jun 9, 2026
bfc733d
Migrate to oxfmt (#618)
github-actions[bot] Jun 9, 2026
e1eabea
Migrate to oxfmt (#618)
github-actions[bot] Jun 9, 2026
1e4131a
Migrate to oxfmt (#618)
github-actions[bot] Jun 9, 2026
e53fb94
Migrate to oxfmt (#618)
github-actions[bot] Jun 9, 2026
57ba901
Use rolldown for bundling (#621)
github-actions[bot] Jun 9, 2026
26109a7
Refactor to fs-fixture (#622)
github-actions[bot] Jun 9, 2026
2470a40
Refactor to fs-fixture (#622)
github-actions[bot] Jun 9, 2026
6818031
Refactor to fs-fixture (#622)
github-actions[bot] Jun 9, 2026
371cf5f
Refactor to fs-fixture (#622)
github-actions[bot] Jun 9, 2026
cbac693
Refactor to fs-fixture (#622)
github-actions[bot] Jun 9, 2026
d9cf5da
Refactor to fs-fixture (#622)
github-actions[bot] Jun 9, 2026
80b735f
Refactor to fs-fixture (#622)
github-actions[bot] Jun 9, 2026
0bff6be
Refactor to fs-fixture (#622)
github-actions[bot] Jun 9, 2026
ef197f2
Refactor to fs-fixture (#622)
github-actions[bot] Jun 9, 2026
a53cec6
Refactor to fs-fixture (#622)
github-actions[bot] Jun 9, 2026
05739b9
Fix version/publish arg parsing (#629)
github-actions[bot] Jun 9, 2026
e6c6b54
Update to typescript v6 (#633)
github-actions[bot] Jun 9, 2026
a79132f
Simplify getChangelogEntry (#632)
github-actions[bot] Jun 9, 2026
9a23eb9
Simplify getChangelogEntry (#632)
github-actions[bot] Jun 9, 2026
64fee2c
Simplify getChangelogEntry (#632)
github-actions[bot] Jun 9, 2026
e712ce1
Fixed an issue with GitHub releases not being created for successfull…
github-actions[bot] Jun 9, 2026
ab32ef7
Fixed an issue with GitHub releases not being created for successfull…
github-actions[bot] Jun 9, 2026
b534fdf
Comment changeset status in PRs (#625)
github-actions[bot] Jun 9, 2026
c3ef588
Add simple PR comment sub-action (#636)
github-actions[bot] Jun 9, 2026
8f01cc4
conflicted commits cherry-picked
Raj-StepSecurity Jun 29, 2026
9bc0903
conflicts resolved
Raj-StepSecurity Jun 29, 2026
e326712
build updated
Raj-StepSecurity Jun 29, 2026
b24faa2
comments addressed
Raj-StepSecurity Jun 30, 2026
bf5ce57
readme updated as per comment
Raj-StepSecurity Jun 30, 2026
aa93ce8
workflows added to be ignored by linting
Raj-StepSecurity Jun 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 9 additions & 2 deletions .github/actions/ci-setup/action.yml
Original file line number Diff line number Diff line change
@@ -1,13 +1,20 @@
name: Setup CI
description: Setup CI

inputs:
skip-cache:
description: "Whether to skip the cache"
required: false
default: "false"

runs:
using: composite
steps:
- name: Setup Node.js
uses: actions/setup-node@6044e13b5dc448c55e2357c09f80417699197238 # v6.2.0
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version-file: ".node-version"
cache: yarn
cache: ${{ inputs.skip-cache != 'true' && 'yarn' || '' }}

- name: Install dependencies
shell: bash
Expand Down
1 change: 0 additions & 1 deletion .github/workflows/auto_cherry_pick.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,3 @@

name: Auto Cherry-Pick from Upstream

on:
Expand Down
49 changes: 42 additions & 7 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,27 +1,37 @@
name: CI

on:
push:
pull_request:
# merge queue is required so all commits on target branches trigger this workflow
# despite lack of the push event trigger here
merge_group:
branches:
- main
pull_request:

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.sha }}
cancel-in-progress: true

jobs:
test:
name: Test
runs-on: ubuntu-latest
timeout-minutes: 20
runs-on: ubuntu-latest

steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@0634a2670c59f64b4a01f0f96f84700a4088b9f0 # v2.12.0
with:
egress-policy: audit

- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Check out repo
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false

- uses: ./.github/actions/ci-setup

- name: Test
Expand All @@ -38,17 +48,42 @@ jobs:
with:
egress-policy: audit

- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Check out repo
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false

- uses: ./.github/actions/ci-setup

- name: Typecheck
run: yarn typecheck

lint:
name: Lint
timeout-minutes: 20
runs-on: ubuntu-latest

steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@0634a2670c59f64b4a01f0f96f84700a4088b9f0 # v2.12.0
with:
egress-policy: audit

- name: Check out repo
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false

- uses: ./.github/actions/ci-setup

- name: Format
run: yarn format

ci-ok:
name: CI OK
runs-on: ubuntu-latest
if: always()
needs: [ test, typecheck ]
needs: [test, typecheck, lint]
steps:
- name: Harden the runner (Audit all outbound calls)
uses: step-security/harden-runner@ab7a9404c0f3da075243ca237b5fac12c98deaa5 # v2.19.3
Expand All @@ -57,4 +92,4 @@ jobs:

- name: Exit with error if some jobs are not successful
run: exit 1
if: ${{ always() && (contains(needs.*.result, 'failure') || contains(needs.*.result, 'skipped') || contains(needs.*.result, 'cancelled')) }}
if: ${{ always() && (contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled')) }}
2 changes: 1 addition & 1 deletion .github/workflows/scorecards.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ on:
# To guarantee Maintained check is occasionally updated. See
# https://github.com/ossf/scorecard/blob/main/docs/checks.md#maintained
schedule:
- cron: '20 7 * * 2'
- cron: "20 7 * * 2"
push:
branches: ["main"]

Expand Down
8 changes: 8 additions & 0 deletions .oxfmtrc.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
{
"$schema": "./node_modules/oxfmt/configuration_schema.json",
"printWidth": 80,
"ignorePatterns": ["dist/**", ".github/workflows/**"],
"sortImports": {
"newlinesBetween": false
}
}
26 changes: 13 additions & 13 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
@@ -1,14 +1,14 @@
repos:
- repo: https://github.com/gitleaks/gitleaks
rev: v8.16.3
hooks:
- id: gitleaks
- repo: https://github.com/pre-commit/mirrors-eslint
rev: v8.38.0
hooks:
- id: eslint
- repo: https://github.com/pre-commit/pre-commit-hooks
rev: v4.4.0
hooks:
- id: end-of-file-fixer
- id: trailing-whitespace
- repo: https://github.com/gitleaks/gitleaks
rev: v8.16.3
hooks:
- id: gitleaks
- repo: https://github.com/pre-commit/mirrors-eslint
rev: v8.38.0
hooks:
- id: eslint
- repo: https://github.com/pre-commit/pre-commit-hooks
rev: v4.4.0
hooks:
- id: end-of-file-fixer
- id: trailing-whitespace
67 changes: 36 additions & 31 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,11 @@

This action for [Changesets](https://github.com/changesets/changesets) creates a pull request with all of the package versions updated and changelogs updated and when there are new changesets on [your configured `baseBranch`](https://github.com/changesets/changesets/blob/main/docs/config-file-options.md#basebranch-git-branch-name), the PR will be updated. When you're ready, you can merge the pull request and you can either publish the packages to npm manually or setup the action to do it for you.

There are also sub-actions hosted in this repository. Check out their respective READMEs for more details:

- [pr-status](./pr-status/README.md): Generate changeset status in PRs.
- [pr-comment](./pr-comment/README.md): Comment on PRs.

## Usage

### Inputs
Expand All @@ -23,7 +28,7 @@ This action for [Changesets](https://github.com/changesets/changesets) creates a
- published - A boolean value to indicate whether a publishing has happened or not
- publishedPackages - A JSON array to present the published packages. The format is `[{"name": "@xx/xx", "version": "1.2.0"}, {"name": "@xx/xy", "version": "0.8.9"}]`

### Example workflow:
### Example workflow

#### Without Publishing

Expand All @@ -45,18 +50,18 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout Repo
uses: actions/checkout@v3
uses: actions/checkout@v6

- name: Setup Node.js 20
uses: actions/setup-node@v3
- name: Setup Node.js 26
uses: actions/setup-node@v6
with:
node-version: 20
node-version: 26

- name: Install Dependencies
run: yarn
run: yarn install --frozen-lockfile

- name: Create Release Pull Request
uses: step-security/action@v1
uses: step-security/changeset-action@v1
```

#### With Publishing
Expand All @@ -79,22 +84,22 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout Repo
uses: actions/checkout@v3
uses: actions/checkout@v6

- name: Setup Node.js 20.x
uses: actions/setup-node@v3
- name: Setup Node.js 26
uses: actions/setup-node@v6
with:
node-version: 20.x
node-version: 26

- name: Install Dependencies
run: yarn
run: yarn install --frozen-lockfile

- name: Create Release Pull Request or Publish to npm
id: changesets
uses: step-security/action@v1
uses: step-security/changeset-action@v1
with:
# This expects you to have a script called release which does a build for your packages and calls changeset publish
publish: yarn release
publish: pnpm release
env:
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}

Expand All @@ -106,7 +111,7 @@ jobs:

By default the GitHub Action creates a `.npmrc` file with the following content:

```
```txt
//registry.npmjs.org/:_authToken=${process.env.NPM_TOKEN}
```

Expand Down Expand Up @@ -143,24 +148,24 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout Repo
uses: actions/checkout@v3
uses: actions/checkout@v6

- name: Setup Node.js 20.x
uses: actions/setup-node@v3
- name: Setup Node.js 26
uses: actions/setup-node@v6
with:
node-version: 20.x
node-version: 26

- name: Install Dependencies
run: yarn
run: yarn install --frozen-lockfile

- name: Create Release Pull Request or Publish to npm
id: changesets
uses: step-security/action@v1
uses: step-security/changeset-action@v1

- name: Publish
if: steps.changesets.outputs.hasChangesets == 'false'
# You can do something when a publish should happen.
run: yarn publish
run: pnpm publish
```

#### With version script
Expand All @@ -185,30 +190,30 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Checkout Repo
uses: actions/checkout@v3
uses: actions/checkout@v6

- name: Setup Node.js 20.x
uses: actions/setup-node@v3
- name: Setup Node.js 26
uses: actions/setup-node@v6
with:
node-version: 20.x
node-version: 26

- name: Install Dependencies
run: yarn
run: yarn install --frozen-lockfile

- name: Create Release Pull Request
uses: step-security/action@v1
uses: step-security/changeset-action@v1
with:
# this expects you to have a npm script called version that runs some logic and then calls `changeset version`.
version: yarn version
version: pnpm version
```

#### With Yarn 2 / Plug'n'Play

If you are using [Yarn Plug'n'Play](https://yarnpkg.com/features/pnp), you should use a custom `version` command so that the action can resolve the `changeset` CLI:

```yaml
- uses: step-security/action@v1
- uses: step-security/changeset-action@v1
with:
version: yarn changeset version
...
# ...
```
4 changes: 0 additions & 4 deletions __fixtures__/ignored-package/.changeset/config.json
Original file line number Diff line number Diff line change
@@ -1,4 +0,0 @@
{
"$schema": "https://unpkg.com/@changesets/config@1.3.0/schema.json",
"ignore": ["ignored-package-pkg-a"]
}
8 changes: 0 additions & 8 deletions __fixtures__/ignored-package/package.json
Original file line number Diff line number Diff line change
@@ -1,8 +0,0 @@
{
"private": true,
"name": "ignored-package",
"version": "1.0.0",
"workspaces": [
"packages/*"
]
}
7 changes: 0 additions & 7 deletions __fixtures__/ignored-package/packages/pkg-a/package.json
Original file line number Diff line number Diff line change
@@ -1,7 +0,0 @@
{
"name": "ignored-package-pkg-a",
"version": "1.0.0",
"dependencies": {
"ignored-package-pkg-b": "1.0.0"
}
}
4 changes: 0 additions & 4 deletions __fixtures__/ignored-package/packages/pkg-b/package.json
Original file line number Diff line number Diff line change
@@ -1,4 +0,0 @@
{
"name": "ignored-package-pkg-b",
"version": "1.0.0"
}
3 changes: 0 additions & 3 deletions __fixtures__/simple-project/.changeset/config.json
Original file line number Diff line number Diff line change
@@ -1,3 +0,0 @@
{
"$schema": "https://unpkg.com/@changesets/config@1.3.0/schema.json"
}
8 changes: 0 additions & 8 deletions __fixtures__/simple-project/package.json
Original file line number Diff line number Diff line change
@@ -1,8 +0,0 @@
{
"private": true,
"name": "simple-project",
"version": "1.0.0",
"workspaces": [
"packages/*"
]
}
7 changes: 0 additions & 7 deletions __fixtures__/simple-project/packages/pkg-a/package.json
Original file line number Diff line number Diff line change
@@ -1,7 +0,0 @@
{
"name": "simple-project-pkg-a",
"version": "1.0.0",
"dependencies": {
"simple-project-pkg-b": "1.0.0"
}
}
4 changes: 0 additions & 4 deletions __fixtures__/simple-project/packages/pkg-b/package.json
Original file line number Diff line number Diff line change
@@ -1,4 +0,0 @@
{
"name": "simple-project-pkg-b",
"version": "1.0.0"
}
Loading
Loading