Skip to content

build: update pinned ci-tools to bdfe993 - #196

Merged
marc0olo merged 1 commit into
mainfrom
chore/bump-ci-tools
Sep 18, 2026
Merged

marc0olo merged 1 commit into
mainfrom
chore/bump-ci-tools

Conversation

@marc0olo

Copy link
Copy Markdown
Member

The pinned ci-tools commit was twelve commits and close to six months behind.

afeee4fb  2026-03-23      <- was pinned
bdfe993   2026-09-17      <- ci-tools main

Behaviour changes

  • assemble-docs sorts versions.json numerically. It sorted as strings, so v10.0 landed below v4.0 instead of directly under latest — this is why the v10.0.0 release appeared at the bottom of the documentation version dropdown. That is the copy of the action this repository runs, so nothing else fixes it here.
  • Changelog pull requests stop accumulating: one self-updating pull request instead of a new one per push to main, closed once there is nothing left to propose, and runs serialised per branch.
  • Release commits no longer fail the changelog job. create-release-pr produces chore: release <version>, which now matches the skip pattern rather than failing when Commitizen has nothing to add — the failure reported for this repo's releases.
  • create-pr no longer builds git commands through a shell, so a branch name, commit message or author value cannot be read as shell syntax. It also refuses a branch_name equal to base_branch_name and ends option parsing before the branch on git push.
  • Commitizen is pinned to 4.18.1 rather than upgraded on every run.

The rebuilt bundles from dfinity/ci-tools#79 and #83, which cleared the undici and brace-expansion advisories, also become the ones that actually run.

For the reviewer

The existing bad order on icp-pages heals itself. It is still wrong today:

latest, v9.0, v8.0, v7.1, v7.0, v6.2, v6.1, v6.0, v5.0, v4.2, v4.1, v4.0, v10.0

upsert-versions-json re-sorts the whole array on every run rather than only inserting, so the next docs publish rewrites the file in the right order. No manual fix to icp-pages is needed.

create-release-pr is unaffected by reuse_branch: it defaults to false on the action, and release branches are already unique per version.

Verified before bumping that all 24 referenced actions and workflows exist at the new commit and still declare every input and secret this repository passes.

🤖 Generated with Claude Code

The pin was twelve commits and close to six months behind. Most
consequential here: assemble-docs sorted versions.json as strings, so
the v10.0.0 release landed below v4.0 in the documentation version
dropdown rather than below latest.

Also picks up the changelog workflow keeping one self-updating pull
request and skipping release commits, create-pr no longer building git
commands through a shell, and a pinned Commitizen.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 18, 2026 07:00
@marc0olo
marc0olo requested a review from a team as a code owner September 18, 2026 07:00

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

All reviewed changes have no unresolved blocking issues.

Pull request overview

Updates pinned ci-tools references to commit bdfe993 across CI, release, changelog, and documentation workflows.

Changes:

  • Updated 24 action and reusable workflow references.
  • Enables documented sorting, release, changelog, and security fixes.
File summaries
File Description
.github/workflows/test.yml Updated PNPM setup action.
.github/workflows/release.yml Updated release tooling actions.
.github/workflows/publish-docs.yml Updated documentation tooling.
.github/workflows/generate-changelog.yml Updated changelog workflow.
.github/workflows/create-release-pr.yml Updated release PR tooling.
.github/workflows/commitizen.yml Updated commit validation workflows.
.github/workflows/codestyle.yml Updated PNPM setup action.
.github/workflows/audit.yml Updated PNPM setup action.
Review details
  • Files reviewed: 8/8 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@marc0olo
marc0olo merged commit 40e03cd into main Sep 18, 2026
11 checks passed
@marc0olo
marc0olo deleted the chore/bump-ci-tools branch September 18, 2026 07:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants