| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
Adds a workflow that runs cz bump --dry-run on incoming pull requests and posts (or updates) a sticky comment summarising the would-be version bump and changelog entries. This makes unexpected version bumps visible to reviewers before merging, addressing commitizen-tools#1510. The pattern is documented in docs/tutorials/github_actions.md so other projects can copy/paste the same workflow. Closes commitizen-tools#1510 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Codecov Report✅ All modified and coverable lines are covered by tests. @@ Coverage Diff @@
## master #1957 +/- ##
=======================================
Coverage 98.23% 98.23%
=======================================
Files 61 61
Lines 2779 2779
=======================================
Hits 2730 2730
Misses 49 49 ☔ View full report in Codecov by Sentry. |
Sorry, something went wrong.
There was a problem hiding this comment.
Adds a GitHub Actions workflow to comment a “bump preview” on pull requests, and documents the pattern so downstream users can reuse it.
Changes:
Copilot reviewed 2 out of 2 changed files in this pull request and generated 4 comments.
| File | Description |
|---|---|
| docs/tutorials/github_actions.md | Documents a reusable “PR bump preview” workflow and explains how it works. |
| .github/workflows/pr-bump-preview.yml | New workflow that runs Commitizen in CI for PRs and posts/updates a sticky PR comment. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Sorry, something went wrong.
Address Copilot review feedback on commitizen-tools#1957: * `cz bump` renders Jinja templates from the working directory whenever `update_changelog_on_bump` is set in config, using a non-sandboxed `FileSystemLoader('.')`. Under `pull_request_target` with a write token, executing those templates against fork-controlled files would risk RCE / token exfiltration. Gate the job to same-repo PRs by comparing `head.repo.full_name` to `base.repo.full_name`. * Set `persist-credentials: false` on `actions/checkout` as defense in depth, so the workflow token is not written to `.git/config`. * Adjust docs to drop the misleading `and changelog entries` claim (the dry-run only shows changelog entries when `update_changelog_on_bump` is enabled), and rewrite the safety explanation to reflect the real threat model. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Mirrors the security fix on commitizen-tools/commitizen#1957: * `cz bump` can render Jinja templates from the working directory when `update_changelog_on_bump` is set in config, using a non-sandboxed loader. Under `pull_request_target` this would let a fork PR execute arbitrary code with a write token, so gate the job to same-repo PRs only (`head.repo == base.repo`). * Add `persist-credentials: false` on `actions/checkout` as defense in depth. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Mirrors the security fix on commitizen-tools/commitizen#1957: * `cz bump` can render Jinja templates from the working directory when `update_changelog_on_bump` is set in config, using a non-sandboxed loader. Under `pull_request_target` this would let a fork PR execute arbitrary code with a write token, so gate the job to same-repo PRs only (`head.repo == base.repo`). * Add `persist-credentials: false` on `actions/checkout` as defense in depth. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Note for reviewers: the duplication across this repo, commitizen-action, and setup-cz is intentional for now. Tracked as a follow-up in #1959 (mirrored at commitizen-tools/setup-cz#20) — once these PRs are merged and we have one or two real bump-preview comments in production, we plan to promote the example into a reusable workflow in setup-cz and shrink the workflows in commitizen + commitizen-action to ~8-line wrappers pinned to a tagged setup-cz release. |
Sorry, something went wrong.
There was a problem hiding this comment.
love this! adding changelogs might also be a good idea
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Description
Adds a GitHub Actions workflow that runs cz bump --dry-run against every incoming pull request and posts (or updates) a sticky comment summarising the would-be version bump and changelog entries. Reviewers can spot unexpected version bumps before merging.
The pattern is also documented in docs/tutorials/github_actions.md so other projects can copy/paste the same workflow.
How it works
Companion changes are being prepared for commitizen-tools/commitizen-action (replaces the draft #102 attempt) and commitizen-tools/setup-cz (examples/) so the same pattern is available to consumers of either action.
Closes #1510
Type of changes
Steps to Test This Pull Request
The workflow self-tests once it lands on master: open a follow-up PR and confirm a 🔍 Commitizen bump preview comment appears and updates as you push commits.
Expected output
The workflow posts (and replaces on every push) a single sticky comment whose body depends on the dry-run exit code.
cz bump --dry-run --yes succeeds (status 0) — eligible bump:
Rendered commentNoneIncrementExit (status 21) — no eligible commits:
Any other non-zero status — error surfaced inside the comment:
The status-0 example above is the literal output of cz bump --dry-run --yes against the current master of this repository (verified locally).
Checklist