Skip to content

chore(deps): bump changesets/action from 1.7.0 to 2.1.2 - #426

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/changesets/action-2.1.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/changesets/action-2.1.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 12, 2026

Copy link
Copy Markdown

Bumps changesets/action from 1.7.0 to 2.1.2.

Release notes

Sourced from changesets/action's releases.

v2.1.2

Patch Changes

v2.1.1

Patch Changes

v2.1.0

Minor Changes

  • #718 3b7c71c Thanks @​bluwy! - Add a cwd input to the root action, /select-mode, /version, /pack, and /publish sub-actions to set the current working directory to execute Changesets in. This input existed in v1 but was incorrectly removed.

Patch Changes

v2.0.0

Major Changes

  • #692 cb3f011 Thanks @​Andarist! - Release commits and tags are now pushed using the GitHub API by default.

    Replace the commit-mode input with the boolean push-with-git-cli input. Set push-with-git-cli: true to continue using the Git CLI.

    Regardless of the push mode, custom GitHub tokens must be passed explicitly through the github-token input. The GITHUB_TOKEN environment variable and credentials configured by actions/checkout or embedded in remote URLs are not substitutes for this input. When the Git CLI is enabled, github-token takes precedence over those repository credentials.

  • #680 ca57073 Thanks @​bluwy! - Add a new push-git-tags option that complements create-github-releases to control specifically if git tags should be created but not GitHub releases.

    If create-github-releases was previously set to false, which also indirectly disabled git tag creation, git tags will now be created instead by default. If this is not desired, set push-git-tags to false explicitly.

  • #657 4f718b5 Thanks @​Andarist! - Removed compatibility support for old Changesets v1.

  • #681 7359107 Thanks @​bluwy! - Rename the root action inputs and outputs to better match the sub-actions' conventions.

    Inputs:

    • version -> version-script
    • publish -> publish-script
    • commit -> commit-message
    • title -> pr-title
    • branch -> pr-base-branch

... (truncated)

Changelog

Sourced from changesets/action's changelog.

@​changesets/action

2.1.2

Patch Changes

2.1.1

Patch Changes

2.1.0

Minor Changes

  • #718 3b7c71c Thanks @​bluwy! - Add a cwd input to the root action, /select-mode, /version, /pack, and /publish sub-actions to set the current working directory to execute Changesets in. This input existed in v1 but was incorrectly removed.

Patch Changes

2.0.0

Major Changes

  • #692 cb3f011 Thanks @​Andarist! - Release commits and tags are now pushed using the GitHub API by default.

    Replace the commit-mode input with the boolean push-with-git-cli input. Set push-with-git-cli: true to continue using the Git CLI.

    Regardless of the push mode, custom GitHub tokens must be passed explicitly through the github-token input. The GITHUB_TOKEN environment variable and credentials configured by actions/checkout or embedded in remote URLs are not substitutes for this input. When the Git CLI is enabled, github-token takes precedence over those repository credentials.

  • #680 ca57073 Thanks @​bluwy! - Add a new push-git-tags option that complements create-github-releases to control specifically if git tags should be created but not GitHub releases.

    If create-github-releases was previously set to false, which also indirectly disabled git tag creation, git tags will now be created instead by default. If this is not desired, set push-git-tags to false explicitly.

  • #657 4f718b5 Thanks @​Andarist! - Removed compatibility support for old Changesets v1.

  • #681 7359107 Thanks @​bluwy! - Rename the root action inputs and outputs to better match the sub-actions' conventions.

    Inputs:

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [changesets/action](https://github.com/changesets/action) from 1.7.0 to 2.1.2.
- [Release notes](https://github.com/changesets/action/releases)
- [Changelog](https://github.com/changesets/action/blob/main/CHANGELOG.md)
- [Commits](changesets/action@6a0a831...ae32849)

---
updated-dependencies:
- dependency-name: changesets/action
  dependency-version: 2.1.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 12, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, security. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from cramforce as a code owner September 12, 2026 13:52
@vercel

vercel Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
just-bash-website Ready Ready Preview, v0 Sep 12, 2026 1:53pm UTC
1 Skipped Deployment
Project Deployment Actions Updated
just-bash Ignored Ignored v0 Sep 12, 2026 1:53pm UTC

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgithub/​changesets/​action@​6a0a831ff30acef54f2c6aa1cbbc1096b066edaf ⏵ ae32849d5ba541f9ae29e40e22a623bc13562f5197 +10100100100100

View full report

@auto-maintain

auto-maintain Bot commented Sep 12, 2026

Copy link
Copy Markdown

🤖 auto-maintain review

Automated, advisory triage for @dependabot[bot]'s PR. Facts below are read from the GitHub API.

Check Result
Author's merged PRs (this repo) 0 — ⚠️ first-time contributor
Account established ⚠️ (age 2705d · 0 followers · 0 public repos)
Commits signed/verified ✅ 1/1
Changeset included ⚠️

Review panel: 🔴 high highest severity

just-bash maintainer code review: 🔴 high

The major-version bump is incomplete and breaks the release workflow until its inputs are migrated to the v2 API.

  • .github/workflows/release.yml:92 — v2 renamed these inputs and requires `github-token` under `with`; the workflow still uses v1 inputs (`version`, `publish`, `commit`, `title`, `commitMode`) and only exports `GITHUB_TOKEN`, so the release action will fail instead of creating/publishing a release.

General code review: 🔴 high

The major-version bump is not migrated to the v2 input contract and breaks the release workflow.

  • .github/workflows/release.yml:92 — The v2 action has breaking input changes, but the workflow still uses v1 inputs (`version`, `publish`, `commit`, `title`, `commitMode`) and supplies `GITHUB_TOKEN` only via `env`. v2 requires renamed inputs such as `version-script`/`publish-script` and an explicit `github-token`, so this release job will fail or ignore its custom release configuration.

Adversarial security: 🟡 medium

The dependency bump is incomplete and breaks the release workflow until its inputs are migrated to the v2 API.

  • .github/workflows/release.yml:92 — The v2 action has breaking input changes, but the workflow still uses v1 names and supplies GITHUB_TOKEN only via env. v2 requires `github-token` and renames `version`, `publish`, `commit`, and `title`, so the privileged release job will fail instead of publishing or creating release PRs.

Adversarial security (second opinion): 🔴 high

No supply-chain tampering: the diff is a single SHA-pinned action bump matching the published v2.1.2 commit, with no other files touched. However, the bump crosses a major version that renamed/removed every input this privileged release job passes, so the release and npm publish automation would silently degrade; the input migration must land with the bump.

  • .github/workflows/release.yml:94 — changesets/action v2.0.0 renamed the root action inputs (`version` -> `version-script`, `publish` -> `publish-script`). GitHub Actions silently ignores unknown `with:` keys, so after this bump `pnpm release` never runs — `changeset publish` is never invoked and the npm publish step becomes a no-op, while `changeset version` falls back to the action's default (skipping `pnpm install --lockfile-only`, leaving a drifted lockfile in the release PR). The bump must be accompanied by the input renames.
  • .github/workflows/release.yml:96 — `commit` and `title` were renamed to `commit-message` and `pr-title` in v2. As written they are ignored, so the release commit/PR silently loses its "chore: release" naming.
  • .github/workflows/release.yml:98 — `commitMode: github-api` was removed in v2 (replaced by the boolean `push-with-git-cli`). This is now a dead input, and the file's header comment (lines 4-7) still documents the verified-signature guarantee as coming from `commitMode`. Update the comment and drop/replace the input so the stated signing contract matches the actual configuration.
  • .github/workflows/release.yml:99 — v2 requires the token to be supplied through the `github-token` input; the `GITHUB_TOKEN` env var and actions/checkout credentials are explicitly no longer substitutes. This job uses `persist-credentials: false` and only sets `GITHUB_TOKEN` in `env:`, so the privileged push/PR path may lose authentication. Add an explicit `github-token: ${{ secrets.GITHUB_TOKEN }}` input.

Standard Bash and host portability: 🟡 medium

The major-version upgrade is incomplete because the workflow still uses removed v1 inputs.

  • .github/workflows/release.yml:94 — v2 renamed these inputs, so this entire v1-style block is ignored and the custom version/publish commands and release metadata are lost. Use `version-script`, `publish-script`, `commit-message`, and `pr-title`; remove the obsolete `commitMode`.

Posted by auto-maintain. This automated code review is advisory; a human maintainer makes the call.

This branch was successfully deployed

1 active deployment
Preview – just-bash-website a8f371d0 Deployed Sep 12, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants