Skip to content

Remove GITHUB_TOKEN env var support - #674

Merged
bluwy merged 1 commit into
mainfrom
no-github-token-env-var
Jun 30, 2026
Merged

bluwy merged 1 commit into
mainfrom
no-github-token-env-var

Conversation

@bluwy

@bluwy bluwy commented Jun 25, 2026

Copy link
Copy Markdown
Member

This aligns with the behaviour with the other sub-actions, but with an error if the old pattern is still used.

@changeset-bot

changeset-bot Bot commented Jun 25, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 6f1dfae

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@changesets/action Major

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Comment thread src/index.ts
core.setFailed("Please add the GITHUB_TOKEN to the changesets action");
return;
const githubToken = getRequiredInput("github-token");
if (process.env.GITHUB_TOKEN && process.env.GITHUB_TOKEN !== githubToken) {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If we have this "they have to match if both are specified" rule - shouldn't we kinda also enforce that in other subactions that use github-token?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is more for compat to push migration, so eventually in the next major we can remove this and we don't have to mind about GITHUB_TOKEN anymore.

@bluwy
bluwy added this pull request to the merge queue Jun 30, 2026
Merged via the queue into main with commit 164652b Jun 30, 2026
7 checks passed
@bluwy
bluwy deleted the no-github-token-env-var branch June 30, 2026 00:22
arshad-shah added a commit to arshad-shah/extforge that referenced this pull request Sep 1, 2026
The 1.0.0 and 1.1.0 releases published to npm but created no git tag and
no GitHub release, while the workflow reported success.

changesets/action v1 detects what was published by regex-matching
`changeset publish` stdout for `New tag: <pkg>@<version>`. #77 upgraded
@changesets/cli to v3, whose clack-style output no longer prints that
line, so the action concluded nothing had been published and skipped
both the tag push and the release creation without failing. Tags were
created on the runner and discarded with it — which is why
`git ls-remote --tags` still stops at 0.6.0.

Upstream replaced stdout parsing with a CHANGESETS_OUTPUT file in v2
(changesets/action#678) and v2 now rejects the CLI v2/action v1 mismatch
outright (changesets/action#699).

v2 renamed every input, so this is not a bare SHA bump:
version -> version-script, publish -> publish-script,
commit -> commit-message, title -> pr-title.

Both env vars are dropped. GITHUB_TOKEN is no longer read from the
environment (changesets/action#674); the `github-token` input defaults to
`github.token`, which is what was being passed. NPM_TOKEN is no longer
used to write an .npmrc (changesets/action#695) — publishing already goes
through OIDC trusted publishing, confirmed by the SLSA provenance
attestation on the published 1.1.0 tarball.

v2 pushes commits and tags through the GitHub API rather than the git
CLI, so `persist-credentials: false` stays safe and tags are signed with
GitHub's GPG key.


Claude-Session: https://claude.ai/code/session_01AZSFjNFjuoeXUjuFkA6Cha

Co-authored-by: Arshad shah <[email protected]>
Co-authored-by: Claude Opus 5 (1M context) <[email protected]>
rtorcato-bot added a commit to rtorcato/react-common that referenced this pull request Oct 8, 2026
🤖 *Automated — `@Megatron` 🐝 (Buzz agent) via ai-loop.*

This replaces Dependabot #168 (`changesets/action` v1 → v2). #168 only
changes the action ref, and with v2's renamed inputs **publishing would
silently stop**. Once this merges, #168 can be closed (left to Fizz).

**Stacked on #192**, which adds `.github/workflows/release.yml`, so the
base branch is `chore/repo-tooling-v5-190`. Merge #192 first. GitHub
then retargets this PR to `main` and CI runs on it.

**Release config.** This changes how `release.yml` versions and
publishes, so it needs owner sign-off.

## Changes
- **`release.yml`: `changesets/action@v1` → `@v2`**, with the v2 input
names (checked against v2's `action.yml` and the v2.0.0 release notes):
- `version` → `version-script`, `publish` → `publish-script`, `commit` →
`commit-message`, `title` → `pr-title`. v2 ignores the old names, so
without this the publish step never ran.
- `github-token: ${{ secrets.RELEASE_TOKEN || secrets.GITHUB_TOKEN }}`.
v2 no longer reads the `GITHUB_TOKEN` env (changesets/action#674).
Without this, `RELEASE_TOKEN` is silently replaced by the default token,
which can't push the "Version Packages" PR to a protected `main`.
- **`@changesets/cli` 2.31.1 → ^3.0.3.** Action v2 refuses to run on CLI
v2 (changesets/action#699). Action v1 can't detect what CLI v3
published, so the two have to land together. I took the CLI bump out of
#196 for that reason.

## Behaviour changes to know about (v2 / CLI 3 defaults, not changed
here)
- Release commits and tags are now pushed **through the GitHub API**
(`push-with-git-cli: false`). They are signed by GitHub and attributed
to the token's owner.
- CLI 3: `changeset version` exits 1 when there are no changesets. The
action only runs it when changesets exist. Private packages are no
longer versioned by default, and `@rtorcato/react-common-docs` is
private and already in `ignore`.
- I checked `.changeset/config.json` and the scripts for removed CLI 3
features (`changeset tag`, `--sinceMaster`, `prettier`). None are used.

## Verification (local)
- `pnpm install --frozen-lockfile`, `pnpm verify` (49 + 178 tests) and
`pnpm build` pass.
- `changeset status` and a real `pnpm version-packages` run on CLI 3.0.3
(reverted afterwards): the 3 pending changesets bump
`@rtorcato/shadcn-ui` by a patch, and the docs package is left alone.
- I couldn't exercise the action itself locally. The first `gh workflow
run release.yml` after merge is the real test.

---------

Co-authored-by: Woz (rtorcato-bot) <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants