build: update pinned ci-tools to bdfe993 - #196
Merged
Merged
Conversation
The pin was twelve commits and close to six months behind. Most consequential here: assemble-docs sorted versions.json as strings, so the v10.0.0 release landed below v4.0 in the documentation version dropdown rather than below latest. Also picks up the changelog workflow keeping one self-updating pull request and skipping release commits, create-pr no longer building git commands through a shell, and a pinned Commitizen. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
🟢 Approval recommended
All reviewed changes have no unresolved blocking issues.
Pull request overview
Updates pinned ci-tools references to commit bdfe993 across CI, release, changelog, and documentation workflows.
Changes:
- Updated 24 action and reusable workflow references.
- Enables documented sorting, release, changelog, and security fixes.
File summaries
| File | Description |
|---|---|
.github/workflows/test.yml |
Updated PNPM setup action. |
.github/workflows/release.yml |
Updated release tooling actions. |
.github/workflows/publish-docs.yml |
Updated documentation tooling. |
.github/workflows/generate-changelog.yml |
Updated changelog workflow. |
.github/workflows/create-release-pr.yml |
Updated release PR tooling. |
.github/workflows/commitizen.yml |
Updated commit validation workflows. |
.github/workflows/codestyle.yml |
Updated PNPM setup action. |
.github/workflows/audit.yml |
Updated PNPM setup action. |
Review details
- Files reviewed: 8/8 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
MRmarioruci
approved these changes
Sep 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The pinned
ci-toolscommit was twelve commits and close to six months behind.Behaviour changes
assemble-docssortsversions.jsonnumerically. It sorted as strings, sov10.0landed belowv4.0instead of directly underlatest— this is why the v10.0.0 release appeared at the bottom of the documentation version dropdown. That is the copy of the action this repository runs, so nothing else fixes it here.main, closed once there is nothing left to propose, and runs serialised per branch.create-release-prproduceschore: release <version>, which now matches the skip pattern rather than failing when Commitizen has nothing to add — the failure reported for this repo's releases.create-prno longer builds git commands through a shell, so a branch name, commit message or author value cannot be read as shell syntax. It also refuses abranch_nameequal tobase_branch_nameand ends option parsing before the branch ongit push.4.18.1rather than upgraded on every run.The rebuilt bundles from dfinity/ci-tools#79 and #83, which cleared the undici and brace-expansion advisories, also become the ones that actually run.
For the reviewer
The existing bad order on
icp-pagesheals itself. It is still wrong today:upsert-versions-jsonre-sorts the whole array on every run rather than only inserting, so the next docs publish rewrites the file in the right order. No manual fix toicp-pagesis needed.create-release-pris unaffected byreuse_branch: it defaults tofalseon the action, and release branches are already unique per version.Verified before bumping that all 24 referenced actions and workflows exist at the new commit and still declare every input and secret this repository passes.
🤖 Generated with Claude Code