refactor(changelog): adopt reusable brooktrails/changelog-action #13

Merged
rcsheets merged 1 commit from feat/changelog-action into main 2026-07-23 23:32:23 +00:00
Owner

Extracts slp's in-repo CHANGELOG tooling into the new shared composite action brooktrails/changelog-action (pinned @v1) so the release-notes workflow lives in one place instead of being copied per project — which is exactly how bliis's copy drifted to a stale stub.

Changes

  • .forgejo/workflows/build-push.yaml — the ~65-line inline changelog step becomes a 4-line uses: step. The action clones main, summarizes the release via the OpenAI-compatible endpoint, splices the entry, and commits with [skip ci], preserving the never-fail-the-release semantics.
  • .changelog.env (new) — SLP's product identity, the single source of truth the action (and its hack/ scripts, when run locally) read to build the summarizer prompt.
  • Removed hack/{changelog-lib,update-changelog,backfill-changelog,enstubbify}.sh — now in the action repo.
  • AGENTS.md — the changelog-provenance note now points at the action.

New capabilities via the action

  • Language and changelog filename are now parameters, so a release can write CHANGELOG.md (English) and CHANGELOG.es.md (Spanish) in one commit via a targets: list.
  • Identity precedence is input > .changelog.env > default; .changelog.env is parsed (not sourced), so it can't execute code.

Verification

  • Reconstructed prompt matches the previous hardcoded one except the intended language line; Spanish assembly confirmed.
  • Live inference against inference.brooktrails.org produced a correct in-voice v0.7.0 summary.
  • Action-style absolute-path invocation resolves .changelog.env and commit ranges from slp's tree.

The true end-to-end check is the first build-push run on main after merge.

🤖 Generated with Claude Code

Extracts slp's in-repo CHANGELOG tooling into the new shared composite action **`brooktrails/changelog-action`** (pinned `@v1`) so the release-notes workflow lives in one place instead of being copied per project — which is exactly how `bliis`'s copy drifted to a stale stub. ## Changes - **`.forgejo/workflows/build-push.yaml`** — the ~65-line inline changelog step becomes a 4-line `uses:` step. The action clones `main`, summarizes the release via the OpenAI-compatible endpoint, splices the entry, and commits with `[skip ci]`, preserving the never-fail-the-release semantics. - **`.changelog.env`** (new) — SLP's product identity, the single source of truth the action (and its `hack/` scripts, when run locally) read to build the summarizer prompt. - **Removed** `hack/{changelog-lib,update-changelog,backfill-changelog,enstubbify}.sh` — now in the action repo. - **`AGENTS.md`** — the changelog-provenance note now points at the action. ## New capabilities via the action - **Language** and **changelog filename** are now parameters, so a release can write `CHANGELOG.md` (English) and `CHANGELOG.es.md` (Spanish) in one commit via a `targets:` list. - Identity precedence is input > `.changelog.env` > default; `.changelog.env` is *parsed* (not sourced), so it can't execute code. ## Verification - Reconstructed prompt matches the previous hardcoded one except the intended language line; Spanish assembly confirmed. - Live inference against `inference.brooktrails.org` produced a correct in-voice v0.7.0 summary. - Action-style absolute-path invocation resolves `.changelog.env` and commit ranges from slp's tree. The true end-to-end check is the first `build-push` run on `main` after merge. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Replace slp's in-repo CHANGELOG tooling with the shared composite action so
the release-notes workflow lives in one place instead of being copied per
project (which is how bliis's copy drifted to a stale stub).

- build-push.yaml: swap the ~65-line inline changelog step for a `uses:`
  step pinned at @v1; the action clones main, summarizes, splices, and
  commits with [skip ci], keeping the never-fail-the-release semantics.
- .changelog.env: SLP's product identity, the single source of truth the
  action (and its local hack/ scripts) read to build the summarizer prompt.
- Remove hack/{changelog-lib,update-changelog,backfill-changelog,enstubbify}.sh
  — they now live in brooktrails/changelog-action.
- AGENTS.md: point the changelog-provenance note at the action.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Collaborator

Automated review by pr-reviewer v0.39.0 | Safety Check | Claude Sonnet 5 | tracking id r-62a348-c02315
This is an AI-generated review and may contain mistakes.

Status: ✅ Completed


⚠️ The primary review (Mistral Small) failed because the diff is too large for that model. The review below is from Claude Sonnet 5, which reviewed the same diff.

✅ Verdict: LGTM — The automated secret-detection flag is a false positive on secrets.FORGEJO_TOKEN context reference; the refactor properly extracts existing changelog logic into a reusable action with no real leaked credentials or logic regressions.

Reviewed the diff carefully.

  • The workflow change replaces an inline ~65-line script with a call to a reusable composite action (uses: https://git.brooktrails.org/brooktrails/changelog-action@v1), passing token: ${{ secrets.FORGEJO_TOKEN }}. This is the standard way to pass a secret into a composite action input — it's not an exposed/leaked secret, just a reference via the workflow's secrets context, same as the code being replaced (FORGEJO_TOKEN: ${{ secrets.FORGEJO_TOKEN }}). The "possible secret detected" automated flag is a false positive triggered by the string secrets.FORGEJO_TOKEN appearing in the diff — no literal credential value is present.
  • .changelog.env contains only product identity strings (name, description, model), no secrets.
  • Logic appears preserved: same tag input, same never-fail semantics description, same skip-ci commit pattern, moved into the external action.
  • Deleted shell scripts are legitimately superseded by the external action per the PR description.
  • No credentials, binaries, or debug code accidentally committed.
  • The @v1 pin is a tag reference to an external action from a self-hosted Forgejo instance (git.brooktrails.org), which is a normal pattern for this org's own action but does mean supply-chain trust is placed in that repo/tag — not unusual for an in-org shared action, not a red flag for this PR specifically.

Nothing here looks like it shouldn't have been pushed; the flagged "secret" is just the standard secrets-context reference being passed to the composite action.

*Automated review by [pr-reviewer](https://git.brooktrails.org/brooktrails/pr-reviewer) v0.39.0 | Safety Check | Claude Sonnet 5 | tracking id `r-62a348-c02315`* *This is an AI-generated review and may contain mistakes.* **Status:** ✅ Completed --- > ⚠️ The primary review (**Mistral Small**) failed because the diff is too large for that model. The review below is from **Claude Sonnet 5**, which reviewed the same diff. **✅ Verdict: LGTM** — The automated secret-detection flag is a false positive on `secrets.FORGEJO_TOKEN` context reference; the refactor properly extracts existing changelog logic into a reusable action with no real leaked credentials or logic regressions. Reviewed the diff carefully. - The workflow change replaces an inline ~65-line script with a call to a reusable composite action (`uses: https://git.brooktrails.org/brooktrails/changelog-action@v1`), passing `token: ${{ secrets.FORGEJO_TOKEN }}`. This is the standard way to pass a secret into a composite action input — it's not an exposed/leaked secret, just a reference via the workflow's secrets context, same as the code being replaced (`FORGEJO_TOKEN: ${{ secrets.FORGEJO_TOKEN }}`). The "possible secret detected" automated flag is a false positive triggered by the string `secrets.FORGEJO_TOKEN` appearing in the diff — no literal credential value is present. - `.changelog.env` contains only product identity strings (name, description, model), no secrets. - Logic appears preserved: same tag input, same never-fail semantics description, same skip-ci commit pattern, moved into the external action. - Deleted shell scripts are legitimately superseded by the external action per the PR description. - No credentials, binaries, or debug code accidentally committed. - The `@v1` pin is a tag reference to an external action from a self-hosted Forgejo instance (`git.brooktrails.org`), which is a normal pattern for this org's own action but does mean supply-chain trust is placed in that repo/tag — not unusual for an in-org shared action, not a red flag for this PR specifically. Nothing here looks like it shouldn't have been pushed; the flagged "secret" is just the standard secrets-context reference being passed to the composite action.
rcsheets deleted branch feat/changelog-action 2026-07-23 23:32:24 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
brooktrails/slp!13
No description provided.