Repository navigation
Upgrade to Changesets v3 and split the release workflow - #28
Merged
Merged
Conversation
`changesets/action@v2` validates that the project is on `@changesets/cli`
v3, so the action and the CLI have to move together:
- `@changesets/cli` ^2.31.1 -> ^3.0.3
- `.changeset/config.json`: bump the schema to `@changesets/config@4.0.1`
and add `privatePackages: { version: true, tag: false }`. v3 stopped
versioning private packages by default, which made
`@3flabs/guardian-test-fixtures` implicitly ignored and turned
`retargetter-request-path` into a hard "mixed changeset" error. This
restores the previous behaviour: the fixtures package is versioned but
never tagged or published.
- `changeset:publish` -> `changeset:prepack` (`build` + the `workspace:*`
rewrite). Under the pack flow the rewrite has to run *before* tarballs
are built, because each tarball freezes its manifest and npm does not
understand the `workspace:` protocol.
release.yml goes from one job to four, each holding only what it needs:
select-mode contents: read
version contents: write, pull-requests: write
pack contents: read <- build runs here
publish id-token: write, contents: write
`id-token: write` now exists only in `publish`, and `publish` builds
nothing — it uploads the tarballs `pack` produced. Previously the build
ran in a job simultaneously holding OIDC, `contents: write` and
`pull-requests: write`.
Version commits are also signed now: `push-with-git-cli` defaults to
false, so the commit is created through the GitHub API and GitHub signs
it with its own GPG key. Nothing shells out to git for writes anymore,
so the `Authenticate git for the changesets push` step is gone.
Verified against this repo before committing: `changeset version`
produces correct bumps with `workspace:*` untouched, `publish-plan`
excludes the private fixtures package, and `changeset pack` emits three
tarballs with zero literal `workspace:` specifiers in their manifests.
🦋 Changeset detectedLatest commit: 109abf1 The changes in this PR will be included in the next version bump. This PR includes changesets to release 4 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
changesets/action@v2hard-validates that the project is on@changesets/cliv3 (and tells v2 users to stay on@v1), so the action and the CLI have to move together. The v2 default also gives us GitHub-signed version commits, which was the original motivation.Changes
@changesets/cli^2.31.1→^3.0.3.changeset/config.json— schema →@changesets/config@4.0.1, plus:This one is required, not cosmetic. v3 stopped versioning private packages by default, which made
@3flabs/guardian-test-fixturesimplicitly ignored and turned the existingretargetter-request-pathchangeset into a hard failure:The config restores the previous behaviour: fixtures gets versioned, never tagged or published.
changeset:publish→changeset:prepack(build+ theworkspace:*rewrite). Under the pack flow the rewrite has to run before tarballs are built — each tarball freezes its manifest, and npm doesn't understand theworkspace:protocol.Workflow: one job → four
select-modecontents: readversioncontents: write,pull-requests: writepackcontents: readpublishid-token: write,contents: writeid-token: writenow exists only inpublish, andpublishbuilds nothing — it uploads the tarballspackproduced. Previously the build ran in a job simultaneously holding OIDC,contents: writeandpull-requests: write.Version commits are signed as a side effect:
push-with-git-clidefaults tofalse, so the commit goes through the GitHub API and GitHub signs it with its own GPG key — it lands on the Version PR as Verified instead of unsigned. Nothing shells out to git for writes anymore, so theAuthenticate git for the changesets pushstep is deleted outright.Other v2 breaking changes, and why they're no-ops here:
env: GITHUB_TOKENno longer configures the action (we rely on thegithub-tokendefault);.npmrc/NPM_TOKENhandling was removed in favour of trusted publishing, which is already our setup; published-package detection moved from stdout parsing to aCHANGESETS_OUTPUTfile, which propagates fine throughbun run.Verification
v3's release notes only name npm/pnpm/yarn, so bun compatibility was the main risk. Ran the real flow against this repo's actual changesets in a scratch worktree:
changeset version→ correct bumps,workspace:*untouched, changelogs generated, no spurious reformattingchangeset publish-plan→ correctly excludes the private fixtures package, orders by dependencychangeset pack→ three tarballs, zero literalworkspace:specifiers in their manifests, integrity hashes recorded inpublish-plan.jsonLocally green: build, typecheck, lint, format, fixtures check, tests.
Note on the changeset in this PR
.changeset/changesets-v3-release.mdis apatchfor all four packages, added to exercise the new pipeline end to end. Merging this PR runs theversionpath; merging the resulting Version PR runspack→publish.The
publishhalf is the part I could not exercise without actually releasing — worth watching on the first run.Follow-up worth considering
The
publishjob still runsbun install --frozen-lockfilewhile holdingid-token: write, since it needs@changesets/clipresent. That's the one remaining place where lifecycle scripts and the OIDC credential coexist.--ignore-scriptswould close it; not done here because it needs testing against the dep tree.