fix(ci): use Craft action directly instead of reusable workflow - #33
Conversation
Semver Impact of This PR🟢 Patch (bug fixes) 📋 Changelog PreviewThis is how your changes will appear in the changelog. Bug Fixes 🐛
🤖 This preview updates automatically when you update the PR. |
b3f4df6 to
45e237d
Compare
The reusable workflow has a bug where it runs Craft's internal build jobs for external callers. Using the action directly avoids this issue. Uses the release bot token for proper permissions, matching sentry-python.
45e237d to
d91a736
Compare
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.
| env: | ||
| GITHUB_TOKEN: ${{ steps.token.outputs.token }} | ||
| with: | ||
| version: ${{ inputs.version }} |
There was a problem hiding this comment.
Missing version default could cause release failures
Medium Severity
The version input previously had default: 'auto', ensuring a valid value was always passed to the craft action. Now with required: false and no default, triggering the workflow without specifying a version passes an empty string to version: ${{ inputs.version }}. If the craft action doesn't treat empty string as equivalent to 'auto', the release could fail or behave unexpectedly. A fallback like ${{ inputs.version || 'auto' }} would preserve the previous behavior.
Additional Locations (1)
…s lockfile (#1332) ## Summary Fixes all 13 open Dependabot alerts. No GitHub security advisories are open. Bumps the published package minimum to **Node.js 20+** (from 18+) so the declared `engines.node` matches what the new transitive overrides (`@hono/node-server@2.0.12`, `brace-expansion@5.0.9`) actually install. ## Background Post-merge of PR #1254 ("chore: pre-shape repo into pnpm-workspace monorepo layout"), the docs workspace moved from `docs/` to `apps/cli-docs/`. The old `docs/package.json` was deleted, but `docs/pnpm-lock.yaml` was left tracked — referencing the obsolete Astro 6.x / Starlight 0.39 layout. This stale lockfile is the source of 9 of the 13 open alerts. The remaining 4 alerts are transitive vulnerabilities in the active root `pnpm-lock.yaml`: - `shell-quote@1.8.4` via `react-devtools-core` - `@hono/node-server@1.19.17` via `@modelcontextprotocol/sdk@1.29.0` → `@hono/mcp` → `@mastra/client-js` - `fast-uri@3.1.3` via `ajv` → MCP SDK chain - `brace-expansion@5.0.7` via `minimatch` → `glob` (via ultracite and @sentry/bundler-plugins) ## Changes 1. **Delete `docs/pnpm-lock.yaml`** — orphaned lockfile from pre-monorepo layout; closes alerts #25, #27, #29, #31, #33, #34, #35, #41, #54. 2. **`pnpm.overrides` in root `package.json`** for the 4 transitive alerts: ```diff -"shell-quote@<1.8.4": "1.8.4", +"shell-quote@<1.9.0": "1.9.0", `qs@>=6.11.1 <=6.15.1`: "6.15.2", `form-data@<4.0.6`: "4.0.6", `vite@>=8.0.0 <8.0.16`: "8.0.16`, +"@hono/node-server@<2.0.5": "2.0.12", +"fast-uri@<=3.1.3": "3.1.5", +"brace-expansion@<5.0.8": "5.0.9" ``` The previous `shell-quote@<1.8.4 → 1.8.4` override was itself vulnerable (alert #36: `shell-quote <= 1.8.4` is the vulnerable range, patched in 1.9.0), so it is bumped to `<1.9.0 → 1.9.0`. 3. **`engines.node` bump 18 → 20** in root `package.json` and `packages/cli/package.json`, plus doc updates in: - `apps/cli-docs/src/content/docs/library-usage.md` - `apps/cli-docs/src/content/docs/migrating-from-v3.md` - `packages/cli/README.md` (the auto-generated `library-prereq` block reads from `engines.node` via `generateLibraryPrereq()` in `generate-docs-sections.ts`, so it picked up the new floor automatically). The dev floor (`devEngines.runtime >=22.15`) is unchanged — Node 22.15+ remains the development minimum. The standalone binary continues to bundle its own Node 22.15+ runtime. ## Verification - `pnpm audit --prod` → no known vulnerabilities - `pnpm run check:deps` ✓ - `pnpm run lint` ✓ (951 files) - `pnpm run typecheck` ✓ - `pnpm test:unit` → 416 files, 8760 tests passing, 13 skipped - Resolved versions match or exceed each patched minimum: - shell-quote 1.9.0 (patched 1.9.0) - @hono/node-server 2.0.12 (patched 2.0.5) - fast-uri 3.1.5 (patched 3.1.4) - brace-expansion 5.0.9 (patched 5.0.8) ## Reviewer notes **Pin rationale for `@hono/node-server@2.0.12`** — the patched minimum is 2.0.5, but `packages/cli/package.json` already declares `"@hono/node-server": "^2.0.6"` as a direct devDependency. Pinning to 2.0.12 (the latest 2.x available at PR time) keeps the override and the direct declaration in the same major line and avoids a near-term minor bump. `2.0.5–2.0.11` had no further advisories at the time of writing. **Lockfile dedupe side effect** — `shell-quote@1.10.0` (already non-vulnerable, used by `launch-editor`) is consolidated to `1.9.0` because the override forces single-version resolution. No security regression; `launch-editor` does not pin a shell-quote range narrower than what 1.9.0 satisfies. **Node 18 deprecation** — addresses the F1 SHOULD-FIX from the initial review. The `>=18.0` floor had become inconsistent with the lockfile once the overrides pulled in `@hono/node-server@2.0.12` (engines `>=20`) and `brace-expansion@5.0.9` (engines `20 || >=22`). Both packages are dev-only transitive deps, so the only users impacted are source-install users who run the CLI via `node` instead of the standalone binary. `devEngines.runtime` already required `>=22.15`, so development environments are unaffected. ## Note `pnpm audit` (non-prod-only) flags one additional low-severity advisory — `@ai-sdk/provider-utils@2.2.8` (GHSA-866g-f22w-33x8, CVE-2026-8769, via @mastra/client-js) — that is not yet in Dependabot. Addressing it requires bumping @mastra/client-js to a newer major; left out of this PR to keep scope focused on the explicit GitHub security report. <sub>Comment `@sentry <feedback>` on this PR to have Autofix iterate on the changes.</sub>
Summary
The reusable Craft workflow has a bug where it runs Craft's internal build/test jobs for external callers (see getsentry/craft#727).
Use the
getsentry/craft@v2action directly instead, like sentry-python does.