Repository navigation
chore: add changesets release pipeline #617
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,17 @@ | ||
| # Changesets | ||
|
|
||
| This folder holds [changesets](https://github.com/changesets/changesets). Each | ||
| release-worthy change carries a changeset describing which packages to bump and | ||
| by how much. | ||
|
|
||
| When a PR changes a published package, add one: | ||
|
|
||
| ```bash | ||
| pnpm changeset | ||
| ``` | ||
|
|
||
| Pick the affected packages, the bump type (patch/minor/major), and write a short | ||
| summary — it becomes the changelog entry. Commit the generated file with your PR. | ||
|
|
||
| On merge to `main`, the release workflow opens a "Version Packages" PR that applies | ||
| the bumps and updates changelogs. Merging that PR builds and publishes to npm. |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,11 @@ | ||
| { | ||
| "$schema": "https://unpkg.com/@changesets/config@3.1.1/schema.json", | ||
| "changelog": "@changesets/cli/changelog", | ||
| "commit": false, | ||
| "fixed": [], | ||
| "linked": [], | ||
| "access": "public", | ||
| "baseBranch": "main", | ||
| "updateInternalDependencies": "patch", | ||
| "ignore": ["@corsair/demo-minimal", "corsair-mcp-demo"] | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,74 @@ | ||
| --- | ||
| "@corsair-dev/ahrefs": patch | ||
| "@corsair-dev/airtable": patch | ||
| "@corsair-dev/amplitude": patch | ||
| "@corsair-dev/asana": patch | ||
| "@corsair-dev/bitwarden": patch | ||
| "@corsair-dev/bluesky": patch | ||
| "@corsair-dev/box": patch | ||
| "@corsair-dev/cal": patch | ||
| "@corsair-dev/calendly": patch | ||
| "@corsair-dev/cli": patch | ||
| "@corsair-dev/cloudflare": patch | ||
| "@corsair-dev/cursor": patch | ||
| "@corsair-dev/discord": patch | ||
| "@corsair-dev/dodopayments": patch | ||
| "@corsair-dev/dropbox": patch | ||
| "@corsair-dev/exa": patch | ||
| "@corsair-dev/figma": patch | ||
| "@corsair-dev/firecrawl": patch | ||
| "@corsair-dev/fireflies": patch | ||
| "@corsair-dev/gitlab": patch | ||
| "@corsair-dev/gmail": patch | ||
| "@corsair-dev/googlecalendar": patch | ||
| "@corsair-dev/googledrive": patch | ||
| "@corsair-dev/googlemeet": patch | ||
| "@corsair-dev/googlesheets": patch | ||
| "@corsair-dev/grafana": patch | ||
| "@corsair-dev/hackernews": patch | ||
| "@corsair-dev/hubspot": patch | ||
| "@corsair-dev/insightoai": patch | ||
| "@corsair-dev/instagram": patch | ||
| "@corsair-dev/intercom": patch | ||
| "@corsair-dev/jira": patch | ||
| "@corsair-dev/linear": patch | ||
| "@corsair-dev/monday": patch | ||
| "@corsair-dev/notion": patch | ||
| "@corsair-dev/onedrive": patch | ||
| "@corsair-dev/openweathermap": patch | ||
| "@corsair-dev/oura": patch | ||
| "@corsair-dev/outlook": patch | ||
| "@corsair-dev/pagerduty": patch | ||
| "@corsair-dev/perplexityai": patch | ||
| "@corsair-dev/posthog": patch | ||
| "@corsair-dev/razorpay": patch | ||
| "@corsair-dev/reddit": patch | ||
| "@corsair-dev/resend": patch | ||
| "@corsair-dev/sentry": patch | ||
| "@corsair-dev/sharepoint": patch | ||
| "@corsair-dev/slack": patch | ||
| "@corsair-dev/spotify": patch | ||
| "@corsair-dev/strava": patch | ||
| "@corsair-dev/stripe": patch | ||
| "@corsair-dev/supabase": patch | ||
| "@corsair-dev/tally": patch | ||
| "@corsair-dev/tavily": patch | ||
| "@corsair-dev/teams": patch | ||
| "@corsair-dev/telegram": patch | ||
| "@corsair-dev/todoist": patch | ||
| "@corsair-dev/trello": patch | ||
| "@corsair-dev/twilio": patch | ||
| "@corsair-dev/twitter": patch | ||
| "@corsair-dev/twitterapiio": patch | ||
| "@corsair-dev/typeform": patch | ||
| "@corsair-dev/ui": patch | ||
| "@corsair-dev/vapi": patch | ||
| "@corsair-dev/vercel": patch | ||
| "@corsair-dev/xquik": patch | ||
| "@corsair-dev/youtube": patch | ||
| "@corsair-dev/zendesk": patch | ||
| "@corsair-dev/zohomail": patch | ||
| "@corsair-dev/zoom": patch | ||
| --- | ||
|
|
||
| Republish to align npm with `main`. Each of these packages had source merged after its last version bump (webhook tenant matchers, kebab-case file renames, BYO webhook auto-subscribe, and webhook-secret hardening) but was never published, so npm has been serving stale tarballs under the current version. This cuts a patch release so the already-merged work reaches consumers. No source changes are included here. |
| Original file line number | Diff line number | Diff line change | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
@@ -79,3 +79,32 @@ jobs: | |||||||||||||||
| run: node --experimental-strip-types scripts/pr-review/gate-main.ts | ||||||||||||||||
| env: | ||||||||||||||||
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||||||||||||||||
|
|
||||||||||||||||
| changesets: | ||||||||||||||||
| name: Changeset guard | ||||||||||||||||
| runs-on: ubuntu-24.04 | ||||||||||||||||
| steps: | ||||||||||||||||
| - uses: actions/checkout@v4 | ||||||||||||||||
| with: | ||||||||||||||||
| fetch-depth: 0 | ||||||||||||||||
|
|
||||||||||||||||
| - name: Guard changesets | ||||||||||||||||
| env: | ||||||||||||||||
| BASE: ${{ github.base_ref }} | ||||||||||||||||
| run: | | ||||||||||||||||
| git fetch origin "$BASE" -q | ||||||||||||||||
| base="origin/$BASE" | ||||||||||||||||
|
|
||||||||||||||||
| # Majors are bumped by hand — fail if any changeset requests one. | ||||||||||||||||
| majors=$(grep -rlE '^[[:space:]]*"[^"]+":[[:space:]]*major[[:space:]]*$' .changeset/*.md 2>/dev/null | grep -v 'README.md' || true) | ||||||||||||||||
| if [ -n "$majors" ]; then | ||||||||||||||||
| echo "::error::major bump requested in: $majors — bump major versions by hand and keep changesets to patch/minor" | ||||||||||||||||
| exit 1 | ||||||||||||||||
| fi | ||||||||||||||||
|
|
||||||||||||||||
| # Non-blocking nudge; the changeset-bot enforces this too. | ||||||||||||||||
| changed=$(git diff --name-only "$base"...HEAD) | ||||||||||||||||
| new_cs=$(echo "$changed" | grep -E '^\.changeset/.+\.md$' | grep -v 'README.md' || true) | ||||||||||||||||
| if echo "$changed" | grep -qE '^packages/' && [ -z "$new_cs" ]; then | ||||||||||||||||
|
Comment on lines
+106
to
+108
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win Count only newly added changesets.
Proposed fix- new_cs=$(echo "$changed" | grep -E '^\.changeset/.+\.md$' | grep -v 'README.md' || true)
+ new_cs=$(git diff --name-only --diff-filter=A "$base"...HEAD -- '.changeset/*.md' |
+ grep -vE '^\.changeset/README\.md$' || true)📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||||||||||||||
| echo "::warning::a package changed but no changeset was added — run 'pnpm changeset'" | ||||||||||||||||
| fi | ||||||||||||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,47 @@ | ||
| name: Release | ||
|
|
||
| on: | ||
| push: | ||
| branches: [main] | ||
|
|
||
| concurrency: | ||
| group: release | ||
| cancel-in-progress: false | ||
|
|
||
| permissions: | ||
| contents: write | ||
| pull-requests: write | ||
|
|
||
| jobs: | ||
| release: | ||
| name: Release | ||
| if: github.repository == 'corsairdev/corsair' | ||
| runs-on: ubuntu-24.04 | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| with: | ||
| persist-credentials: false | ||
|
|
||
| - uses: pnpm/action-setup@v4 | ||
| with: | ||
| version: 10.20.0 | ||
|
|
||
| - uses: actions/setup-node@v4 | ||
| with: | ||
| node-version: '24.x' | ||
| cache: 'pnpm' | ||
| registry-url: 'https://registry.npmjs.org' | ||
|
|
||
| - name: Install dependencies | ||
| run: pnpm install --frozen-lockfile | ||
|
|
||
| - name: Create release PR or publish | ||
| uses: changesets/action@a45c4d594aa4e2c509dc14a9f2b3b67ba3780d0d # v1.9.0 | ||
| with: | ||
| version: pnpm changeset version | ||
| publish: pnpm release | ||
| commit: 'chore: version packages' | ||
| title: 'chore: version packages' | ||
| github-token: ${{ secrets.GITHUB_TOKEN }} | ||
| env: | ||
| NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: corsairdev/corsair
Length of output: 17486
🏁 Script executed:
Repository: corsairdev/corsair
Length of output: 556
🌐 Web query:
Changesets documentation changeset file front matter package name quotes YAML single quoted unquoted💡 Result:
Changeset files are Markdown files that use YAML front matter to define which packages are being modified and their corresponding semantic versioning (semver) bump types [1][2][3]. Regarding the formatting of package names in the YAML front matter: - Official documentation and examples consistently use quoted strings for package names (e.g., "my-package": patch) [1][2][3]. - Using quotes is considered best practice as it ensures the YAML is parsed correctly, especially when package names contain special characters (such as the @ symbol in scoped packages) [1][2][3]. - While YAML allows for unquoted keys in many scenarios, Changesets validates that the front matter contains valid package names [4]. Because many modern monorepos rely heavily on scoped packages (e.g.,
@org/package), quoting these names is essential to prevent parsing errors [1][2]. If you are manually creating or editing a changeset file, you should ensure the YAML syntax is valid and follows the pattern [4]: --- "package-name": patch --- Summary of changes The Changeets parser requires these entries to be valid YAML, and using double quotes is the standard and safest approach to ensure compatibility with all package naming conventions [1][4][3].Citations:
🏁 Script executed:
Repository: corsairdev/corsair
Length of output: 1178
🏁 Script executed:
Repository: corsairdev/corsair
Length of output: 4016
Parse changeset front matter before enforcing the major-bump policy.
The grep matches only double-quoted keys.
@changesets/parseaccepts valid YAML forms such as'package-name': majorandpackage-name: major, so these entries can bypass the guard beforechangesets/actionversions and publishes packages.🤖 Prompt for AI Agents