refactor(changelog): adopt reusable brooktrails/changelog-action #13
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/changelog-action"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Extracts slp's in-repo CHANGELOG tooling into the new shared composite action
brooktrails/changelog-action(pinned@v1) so the release-notes workflow lives in one place instead of being copied per project — which is exactly howbliis's copy drifted to a stale stub.Changes
.forgejo/workflows/build-push.yaml— the ~65-line inline changelog step becomes a 4-lineuses:step. The action clonesmain, summarizes the release via the OpenAI-compatible endpoint, splices the entry, and commits with[skip ci], preserving the never-fail-the-release semantics..changelog.env(new) — SLP's product identity, the single source of truth the action (and itshack/scripts, when run locally) read to build the summarizer prompt.hack/{changelog-lib,update-changelog,backfill-changelog,enstubbify}.sh— now in the action repo.AGENTS.md— the changelog-provenance note now points at the action.New capabilities via the action
CHANGELOG.md(English) andCHANGELOG.es.md(Spanish) in one commit via atargets:list..changelog.env> default;.changelog.envis parsed (not sourced), so it can't execute code.Verification
inference.brooktrails.orgproduced a correct in-voice v0.7.0 summary..changelog.envand commit ranges from slp's tree.The true end-to-end check is the first
build-pushrun onmainafter merge.🤖 Generated with Claude Code
Replace slp's in-repo CHANGELOG tooling with the shared composite action so the release-notes workflow lives in one place instead of being copied per project (which is how bliis's copy drifted to a stale stub). - build-push.yaml: swap the ~65-line inline changelog step for a `uses:` step pinned at @v1; the action clones main, summarizes, splices, and commits with [skip ci], keeping the never-fail-the-release semantics. - .changelog.env: SLP's product identity, the single source of truth the action (and its local hack/ scripts) read to build the summarizer prompt. - Remove hack/{changelog-lib,update-changelog,backfill-changelog,enstubbify}.sh — they now live in brooktrails/changelog-action. - AGENTS.md: point the changelog-provenance note at the action. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>Automated review by pr-reviewer v0.39.0 | Safety Check | Claude Sonnet 5 | tracking id
r-62a348-c02315This is an AI-generated review and may contain mistakes.
Status: ✅ Completed
✅ Verdict: LGTM — The automated secret-detection flag is a false positive on
secrets.FORGEJO_TOKENcontext reference; the refactor properly extracts existing changelog logic into a reusable action with no real leaked credentials or logic regressions.Reviewed the diff carefully.
uses: https://git.brooktrails.org/brooktrails/changelog-action@v1), passingtoken: ${{ secrets.FORGEJO_TOKEN }}. This is the standard way to pass a secret into a composite action input — it's not an exposed/leaked secret, just a reference via the workflow's secrets context, same as the code being replaced (FORGEJO_TOKEN: ${{ secrets.FORGEJO_TOKEN }}). The "possible secret detected" automated flag is a false positive triggered by the stringsecrets.FORGEJO_TOKENappearing in the diff — no literal credential value is present..changelog.envcontains only product identity strings (name, description, model), no secrets.@v1pin is a tag reference to an external action from a self-hosted Forgejo instance (git.brooktrails.org), which is a normal pattern for this org's own action but does mean supply-chain trust is placed in that repo/tag — not unusual for an in-org shared action, not a red flag for this PR specifically.Nothing here looks like it shouldn't have been pushed; the flagged "secret" is just the standard secrets-context reference being passed to the composite action.