Skip to content

chore(deps): bump the production-dependencies group with 2 updates #85

chore(deps): bump the production-dependencies group with 2 updates

chore(deps): bump the production-dependencies group with 2 updates #85

name: Changelog Generate
on:
pull_request:
types: [labeled]
concurrency: ${{ github.workflow }}-${{ github.event.number }}
permissions: {}
jobs:
generate:
if: startsWith(github.event.label.name, 'changelog:') && github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
environment: release
permissions:
id-token: write
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
- name: Determine PR source
id: source
env:
HEAD_REPO: ${{ github.event.pull_request.head.repo.full_name }}
THIS_REPO: ${{ github.repository }}
run: |
if [ "$HEAD_REPO" = "$THIS_REPO" ]; then
echo "same_repo=true" >> "$GITHUB_OUTPUT"
else
echo "same_repo=false" >> "$GITHUB_OUTPUT"
fi
- name: Validate branch ref
if: steps.source.outputs.same_repo == 'true'
id: ref
env:
HEAD_REF: ${{ github.event.pull_request.head.ref }}
run: |
set -euo pipefail
REF="$HEAD_REF"
if [[ ! "$REF" =~ ^[A-Za-z0-9._/-]+$ ]]; then
echo "Invalid branch ref: $REF" >&2
exit 1
fi
echo "ref=$REF" >> "$GITHUB_OUTPUT"
- name: Fetch GitHub token via STS
if: steps.source.outputs.same_repo == 'true'
id: app-token
uses: tempoxyz/gh-actions/actions/github-sts@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
with:
policy: release
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
if: steps.source.outputs.same_repo == 'true'
with:
repository: ${{ github.event.pull_request.head.repo.full_name }}
ref: ${{ github.event.pull_request.head.sha }}
fetch-depth: 0
token: ${{ steps.app-token.outputs.token }}
persist-credentials: false
- name: Fetch base branch for diff comparison
if: steps.source.outputs.same_repo == 'true'
env:
BASE_REF: ${{ github.base_ref }}
run: git fetch origin "$BASE_REF"
- name: Check for existing changelog
if: steps.source.outputs.same_repo == 'true'
id: existing
env:
BASE_REF: ${{ github.base_ref }}
run: |
if git diff "origin/${BASE_REF}...HEAD" --name-only | grep -q '^\.changelog/.*\.md$'; then
echo "found=true" >> "$GITHUB_OUTPUT"
else
echo "found=false" >> "$GITHUB_OUTPUT"
fi
- name: Install changelog dependencies
if: steps.source.outputs.same_repo == 'true' && steps.existing.outputs.found == 'false'
# zizmor: ignore[adhoc-packages] -- workflow-only CLI
run: |
corepack enable
corepack prepare pnpm@11.0.8 --activate
pnpm install --frozen-lockfile
npm install -g @anthropic-ai/claude-code@1.0.3
- name: Extract bump level from label
if: steps.source.outputs.same_repo == 'true' && steps.existing.outputs.found == 'false'
id: bump
env:
LABEL: ${{ github.event.label.name }}
run: |
LEVEL="${LABEL#changelog:}"
case "$LEVEL" in
major|minor|patch|none) echo "level=$LEVEL" >> "$GITHUB_OUTPUT" ;;
*) echo "Unsupported changelog bump label: $LABEL" >&2; exit 1 ;;
esac
- name: Generate changelog
if: steps.source.outputs.same_repo == 'true' && steps.existing.outputs.found == 'false'
env:
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
BASE_REF: ${{ github.base_ref }}
BUMP_LEVEL: ${{ steps.bump.outputs.level }}
PR_NUMBER: ${{ github.event.number }}
PR_TITLE: ${{ github.event.pull_request.title }}
run: |
set -euo pipefail
mkdir -p .changelog
OUT=".changelog/pr-${PR_NUMBER}.md"
git diff "origin/${BASE_REF}...HEAD" > /tmp/changelog.diff
if [ -n "${ANTHROPIC_API_KEY:-}" ] && command -v claude >/dev/null 2>&1; then
cat > /tmp/changelog-prompt.md << 'PROMPT'
Generate a changelog entry for this git diff.
Available package: wallet-cli
Respond with ONLY a markdown file in this exact format. No explanation, no code fences:
---
wallet-cli: BUMP_LEVEL
---
Brief description of changes.
Rules:
- Use "BUMP_LEVEL" as the bump level. Do not use a higher bump level.
- Keep the summary concise (1-3 sentences)
- Do NOT wrap the output in code fences
Git diff:
PROMPT
sed -i "s/BUMP_LEVEL/${BUMP_LEVEL}/g" /tmp/changelog-prompt.md
cat /tmp/changelog.diff >> /tmp/changelog-prompt.md
claude -p "$(cat /tmp/changelog-prompt.md)" > "$OUT" || rm -f "$OUT"
fi
if [ ! -s "$OUT" ] || ! head -n 1 "$OUT" | grep -qx -- '---'; then
cat > "$OUT" << EOF
---
wallet-cli: ${BUMP_LEVEL}
---
${PR_TITLE}
EOF
fi
- name: Validate generated changelog
if: steps.source.outputs.same_repo == 'true' && steps.existing.outputs.found == 'false'
run: pnpm changelog:validate
- name: Commit and push changelog
if: steps.source.outputs.same_repo == 'true' && steps.existing.outputs.found == 'false'
env:
APP_TOKEN: ${{ steps.app-token.outputs.token }}
VALIDATED_REF: ${{ steps.ref.outputs.ref }}
run: |
set -euo pipefail
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add .changelog/
git commit -m "chore: add changelog"
git push "https://x-access-token:${APP_TOKEN}@github.com/${GITHUB_REPOSITORY}.git" "HEAD:${VALIDATED_REF}"
pr-feedback:
name: PR feedback
needs: generate
if: always() && startsWith(github.event.label.name, 'changelog:')
runs-on: ubuntu-latest
permissions:
id-token: write
pull-requests: write
steps:
- name: Secure runner
uses: tempoxyz/gh-actions/actions/secure-runner@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
- name: Comment for fork PRs
if: github.event.pull_request.head.repo.full_name != github.repository
env:
GH_TOKEN: ${{ github.token }}
PR_NUMBER: ${{ github.event.number }}
REPO: ${{ github.repository }}
run: |
gh pr comment "$PR_NUMBER" --repo "$REPO" --body "Changelog auto-generation is only supported for same-repo branches. For fork PRs, please add a changelog file manually under .changelog/."
- name: Remove label
if: always()
env:
GH_TOKEN: ${{ github.token }}
LABEL: ${{ github.event.label.name }}
PR_NUMBER: ${{ github.event.number }}
REPO: ${{ github.repository }}
run: gh pr edit "$PR_NUMBER" --repo "$REPO" --remove-label "$LABEL"