fix(ci): put the command word in the Claude trigger phrase so /focus … #178
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # SPDX-License-Identifier: MIT | |
| # Version Packages PR for @taskless/cli. Adapted from the pattern in | |
| # thecodedrift/firebot-script-music-to-my-ears. | |
| # | |
| # THIS WORKFLOW CANNOT PUBLISH, and that is its entire security property. | |
| # | |
| # It reads contributor-authored changesets (UNTRUSTED text) and folds them into | |
| # a CHANGELOG and a pull request body. It holds NO npm credential and NO OIDC | |
| # identity, so a crafted changeset or PR body has nothing here to steal and | |
| # nothing to escape into. The changeset TEXT is fully consumed at this stage and | |
| # never reaches a credentialed job: by the time `release-cli.yml` publishes, the | |
| # Version Packages PR has merged and there are no changesets left to read. | |
| # | |
| # That is why the publish lives in its own file rather than a job below. Keeping | |
| # untrusted text and an OIDC identity in one file invites a later edit that | |
| # hands one to the other — e.g. an `outputs:` carrying changeset-derived text | |
| # into a `run:` in a job holding `id-token: write`. | |
| # | |
| # There is no `publish:` input on the changesets action, deliberately. Supplying | |
| # one would turn this job into a publisher while it is still holding untrusted | |
| # input, which is the arrangement the split exists to prevent. | |
| # | |
| # CONCURRENCY is required here specifically. Two pushes racing on the | |
| # `changeset-release/main` branch is a real failure: both would force the branch | |
| # and one PR would end up describing versions the other computed. | |
| # | |
| # Action refs are pinned to commit SHAs (supply-chain hardening); the trailing | |
| # comment records the human-readable tag. | |
| name: Release CLI Version PR | |
| on: | |
| push: | |
| branches: [main] | |
| # Serialize so two pushes can't race the Version Packages PR branch. | |
| concurrency: release-${{ github.ref }} | |
| # No workflow-wide grants; the job requests exactly what it needs. | |
| permissions: {} | |
| jobs: | |
| version: | |
| name: Version Packages PR | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write # push the changeset-release/main branch | |
| pull-requests: write # open/update the Version Packages PR | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version-file: .nvmrc | |
| cache: pnpm | |
| - run: pnpm install --frozen-lockfile --ignore-scripts | |
| # `version: pnpm bump` runs `changeset version` AND `sync-skill-versions`, | |
| # so the bumped version is propagated into skills/recipes in the same PR. | |
| # It also runs `changelog-compare-links`, which adds the | |
| # `vPREV...vNEXT` compare link under the new CHANGELOG heading. That link | |
| # is dead until `release-cli.yml` creates the tag after publishing, which | |
| # is expected: the notes and the link they describe belong in the same PR. | |
| # No `publish:` input — this job can never publish. | |
| - uses: changesets/action@a45c4d594aa4e2c509dc14a9f2b3b67ba3780d0d # v1.9.0 | |
| with: | |
| version: pnpm bump | |
| commit: "chore: version packages" | |
| title: "chore: version packages" | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} |