Skip to content

ci: add PR bump preview workflow - #1957

Merged
bearomorphism merged 2 commits into
commitizen-tools:masterfrom
bearomorphism:feat/pr-bump-preview
May 19, 2026
Merged

ci: add PR bump preview workflow#1957
bearomorphism merged 2 commits into
commitizen-tools:masterfrom
bearomorphism:feat/pr-bump-preview

Conversation

@bearomorphism

@bearomorphism bearomorphism commented May 9, 2026

Copy link
Copy Markdown
Collaborator

Description

Adds a GitHub Actions workflow that runs cz bump --dry-run against every incoming pull request and posts (or updates) a sticky comment summarising the would-be version bump and changelog entries. Reviewers can spot unexpected version bumps before merging.

The pattern is also documented in docs/tutorials/github_actions.md so other projects can copy/paste the same workflow.

How it works

  • Trigger: pull_request_target (matches label_pr.yml) so the workflow has pull-requests: write even for fork PRs. The job only runs cz bump --dry-run, a read-only command, so PR-controlled scripts are not executed.
  • Setup: Uses commitizen-tools/setup-cz — no language-specific toolchain required.
  • Dry-run: Captures cz bump --dry-run --yes output and exit status. Exit code 21 (NoneIncrementExit) is treated as "no eligible bump" instead of an error; other non-zero codes are surfaced in the comment.
  • Sticky comment: A hidden <!-- commitizen-bump-preview --> marker lets peter-evans/create-or-update-comment edit the previous preview in place on every push instead of stacking comments.

Companion changes are being prepared for commitizen-tools/commitizen-action (replaces the draft #102 attempt) and commitizen-tools/setup-cz (examples/) so the same pattern is available to consumers of either action.

Closes #1510

Type of changes

  • CI/CD related
  • Documentation update

Steps to Test This Pull Request

The workflow self-tests once it lands on master: open a follow-up PR and confirm a 🔍 Commitizen bump preview comment appears and updates as you push commits.

Expected output

The workflow posts (and replaces on every push) a single sticky comment whose body depends on the dry-run exit code.

cz bump --dry-run --yes succeeds (status 0) — eligible bump:

Rendered comment

🔍 Commitizen bump preview

Merging this PR will produce the following bump:

bump: version 4.15.1 → 4.16.0
tag to create: v4.16.0
increment detected: MINOR
<!-- commitizen-bump-preview -->
## 🔍 Commitizen bump preview

Merging this PR will produce the following bump:

```
bump: version 4.15.1 → 4.16.0
tag to create: v4.16.0
increment detected: MINOR
```

NoneIncrementExit (status 21) — no eligible commits:

🔍 Commitizen bump preview

No commits in this PR are eligible for a version bump.

Any other non-zero status — error surfaced inside the comment:

🔍 Commitizen bump preview

⚠️ cz bump --dry-run exited with status 3:

NoCommitsFoundError

The status-0 example above is the literal output of cz bump --dry-run --yes against the current master of this repository (verified locally).

Checklist

Adds a workflow that runs cz bump --dry-run on incoming pull requests
and posts (or updates) a sticky comment summarising the would-be version
bump and changelog entries. This makes unexpected version bumps visible
to reviewers before merging, addressing commitizen-tools#1510.

The pattern is documented in docs/tutorials/github_actions.md so other
projects can copy/paste the same workflow.

Closes commitizen-tools#1510

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@codecov

codecov Bot commented May 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.23%. Comparing base (4b93a50) to head (52530b0).
⚠️ Report is 3 commits behind head on master.

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #1957   +/-   ##
=======================================
  Coverage   98.23%   98.23%           
=======================================
  Files          61       61           
  Lines        2779     2779           
=======================================
  Hits         2730     2730           
  Misses         49       49           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a GitHub Actions workflow to comment a “bump preview” on pull requests, and documents the pattern so downstream users can reuse it.

Changes:

  • Add .github/workflows/pr-bump-preview.yml to run cz bump --dry-run on PRs and post/update a sticky comment.
  • Document the new PR bump preview workflow in docs/tutorials/github_actions.md.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 4 comments.

File Description
docs/tutorials/github_actions.md Documents a reusable “PR bump preview” workflow and explains how it works.
.github/workflows/pr-bump-preview.yml New workflow that runs Commitizen in CI for PRs and posts/updates a sticky PR comment.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/pr-bump-preview.yml Outdated
Comment thread .github/workflows/pr-bump-preview.yml
Comment thread docs/tutorials/github_actions.md Outdated
Comment thread docs/tutorials/github_actions.md
@bearomorphism
bearomorphism marked this pull request as ready for review May 9, 2026 08:36
Address Copilot review feedback on commitizen-tools#1957:

* `cz bump` renders Jinja templates from the working directory whenever
  `update_changelog_on_bump` is set in config, using a non-sandboxed
  `FileSystemLoader('.')`. Under `pull_request_target` with a write
  token, executing those templates against fork-controlled files would
  risk RCE / token exfiltration. Gate the job to same-repo PRs by
  comparing `head.repo.full_name` to `base.repo.full_name`.
* Set `persist-credentials: false` on `actions/checkout` as
  defense in depth, so the workflow token is not written to
  `.git/config`.
* Adjust docs to drop the misleading `and changelog entries` claim
  (the dry-run only shows changelog entries when
  `update_changelog_on_bump` is enabled), and rewrite the safety
  explanation to reflect the real threat model.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
bearomorphism added a commit to bearomorphism/setup-cz that referenced this pull request May 9, 2026
Mirrors the security fix on commitizen-tools/commitizen#1957:

* `cz bump` can render Jinja templates from the working directory when
  `update_changelog_on_bump` is set in config, using a non-sandboxed
  loader. Under `pull_request_target` this would let a fork PR execute
  arbitrary code with a write token, so gate the job to same-repo PRs
  only (`head.repo == base.repo`).
* Add `persist-credentials: false` on `actions/checkout` as defense
  in depth.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
bearomorphism added a commit to bearomorphism/commitizen-action that referenced this pull request May 9, 2026
Mirrors the security fix on commitizen-tools/commitizen#1957:

* `cz bump` can render Jinja templates from the working directory when
  `update_changelog_on_bump` is set in config, using a non-sandboxed
  loader. Under `pull_request_target` this would let a fork PR execute
  arbitrary code with a write token, so gate the job to same-repo PRs
  only (`head.repo == base.repo`).
* Add `persist-credentials: false` on `actions/checkout` as defense
  in depth.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@bearomorphism

bearomorphism commented May 9, 2026

Copy link
Copy Markdown
Collaborator Author

Note for reviewers: the duplication across this repo, commitizen-action, and setup-cz is intentional for now. Tracked as a follow-up in #1959 (mirrored at commitizen-tools/setup-cz#20) — once these PRs are merged and we have one or two real bump-preview comments in production, we plan to promote the example into a reusable workflow in setup-cz and shrink the workflows in commitizen + commitizen-action to ~8-line wrappers pinned to a tagged setup-cz release.

@Lee-W Lee-W left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

love this! adding changelogs might also be a good idea

@bearomorphism bearomorphism changed the title feat(ci): add PR bump preview workflow May 19, 2026
@bearomorphism
bearomorphism merged commit fc263cd into commitizen-tools:master May 19, 2026
20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3 participants