Skip to content

fix(PL-6101): use upstream TriPSs/conventional-changelog-action#274

Merged
nwaller-nesto merged 1 commit into
masterfrom
fix/PL-6101-upstream-conventional-changelog-action
Jun 8, 2026
Merged

fix(PL-6101): use upstream TriPSs/conventional-changelog-action#274
nwaller-nesto merged 1 commit into
masterfrom
fix/PL-6101-upstream-conventional-changelog-action

Conversation

@nwaller-nesto

@nwaller-nesto nwaller-nesto commented Jun 8, 2026

Copy link
Copy Markdown
Contributor

What

Switch from nestoca/conventional-changelog-action to TriPSs/conventional-changelog-action@3c4970b6 # releases/v5 (upstream).

Why

Maintaining the nestoca fork is unnecessary overhead. Pinning an action to a specific upstream commit SHA gives the same supply-chain guarantee as maintaining a fork — making the fork unnecessary. We're dropping the fork in favour of pinning directly to the upstream release branch.

References


Note

Low Risk
Single CI dependency swap with the same step configuration; release behavior could differ only if v5 outputs differ from the fork, but scope is limited to changelog generation on master.

Overview
The publish job in build-test.yaml now runs TriPSs/conventional-changelog-action at commit 3c4970b6 (releases/v5) instead of the nestoca fork that pointed at releases/v4.

All with: inputs for the “Generate changelog and tag release” step are unchanged; only the action source and pinned SHA differ.

Reviewed by Cursor Bugbot for commit f5cfac6. Bugbot is set up for automated code reviews on this repo. Configure here.

Switch from nestoca fork to upstream TriPSs/conventional-changelog-action
pinned to commit SHA for supply-chain safety.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@nwaller-nesto nwaller-nesto marked this pull request as ready for review June 8, 2026 18:20
@nwaller-nesto nwaller-nesto merged commit eaf9c60 into master Jun 8, 2026
4 checks passed
@nwaller-nesto nwaller-nesto deleted the fix/PL-6101-upstream-conventional-changelog-action branch June 8, 2026 18:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants