-
Notifications
You must be signed in to change notification settings - Fork 4
ci: update GH actions #41
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
WalkthroughThe GitHub Actions workflow responsible for generating changelogs was updated to use version 4 of the Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Poem
Note ⚡️ Unit Test Generation is now available in beta!Learn more here, or try it out under "Finishing Touches" below. ✨ Finishing Touches🧪 Generate unit tests
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 0
🧹 Nitpick comments (1)
.github/workflows/changelog.yaml (1)
16-16: Pin the action to a full commit SHA to mitigate supply-chain riskUsing a floating
@v4tag exposes the workflow to upstream force-pushes.
Pin to a specific, audited commit SHA instead:- uses: orhun/git-cliff-action@v4 + # renovate: datasource=github-releases depName=orhun/git-cliff-action + uses: orhun/git-cliff-action@v4.0.0 # 2b3c4d5e6f…
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (1)
.github/workflows/changelog.yaml(1 hunks)
🔇 Additional comments (1)
.github/workflows/changelog.yaml (1)
16-22: All git-cliff-action@v4 inputs/outputs remain validAfter inspecting the v4
action.ymland README:• Inputs
–config(default:cliff.toml)
–args(default:-v)
are unchanged.• Env var
–OUTPUTis still supported (defaultgit-cliff/CHANGELOG.md).• Outputs
–changelog(alongsidecontentandversion) is still defined.No updates to the workflow are required.
Pull request
Proposed changes
Types of changes
Checklist
Summary by CodeRabbit