Skip to content

fix(ci): harden version bump workflow - #46

Merged
trsdn merged 9 commits into
mainfrom
version-bump/v1.2.2
Aug 24, 2026
Merged

trsdn merged 9 commits into
mainfrom
version-bump/v1.2.2

Conversation

@github-actions

@github-actions github-actions Bot commented Jun 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • generate changelog headings with the resolved version and UTC release date
  • pass commit-derived changelog and commit-message values through step-level environment bindings
  • build generated Markdown with printf/echo so dynamic text is treated as data instead of shell source
  • restore the malformed v1.2.2 changelog heading produced by the previous workflow logic

Security

Closes shell-injection paths in changelog generation, automated PR body creation, and merge commit-message parsing.

Validation

  • workflow YAML parses successfully
  • git diff --check passes
  • adversarial shell payloads remain literal and are not executed

This patch version bump includes:
- 5 commits since last release
- Automated changelog generation
- Version update in pyproject.toml

Release will be triggered automatically when this PR is merged.
@github-actions
github-actions Bot requested a review from trsdn as a code owner June 10, 2026 11:12
@github-actions github-actions Bot added release Release-related pull requests and issues automated Automatically generated content labels Jun 10, 2026
Restore the v1.2.2 changelog heading and pass generated changelog data through environment bindings to prevent shell interpolation.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: f2308b45-f29c-417e-afb0-79cd3b2d3d33

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the GitHub Actions version-bump workflow to generate CHANGELOG.md and the PR body without interpolating commit-derived text directly into shell source, aiming to make the automation safer and more robust.

Changes:

  • Move NEW_VERSION, CHANGELOG, and related values into step-level env: and emit markdown via printf/echo instead of heredocs/envsubst.
  • Simplify CHANGELOG.md update logic by removing the temporary new_entry.md file.
  • Keep the merge-tag job’s commit-message handling out of shell source by binding COMMIT_MESSAGE via env:.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/version-bump.yml
@trsdn trsdn changed the title chore: bump version to v1.2.2 fix(ci): harden version bump workflow Aug 20, 2026
trsdn
trsdn previously approved these changes Aug 20, 2026
trsdn added 2 commits August 24, 2026 23:59
Remove pull request path filters that prevented branch-protection checks from being reported for workflow-only changes.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: f2308b45-f29c-417e-afb0-79cd3b2d3d33
@github-actions

Copy link
Copy Markdown
Contributor Author

🔍 CI Quality Gates Summary

Overall Status: ✅ All Passed

Check Status Details Action Required
🎨 Format ✅ Passed ruff format check None
🔧 Lint ✅ Passed ruff linting None
📝 Types ✅ Passed mypy type checking None
🧪 Tests ✅ Passed Unit tests None
📊 Coverage 81.8% Minimum: 80% None
🔌 MCP ✅ Valid Protocol compliance None
🔒 Security ✅ Clean Dependency audit None

🔗 Quick Links

🛠️ Quick Fix Commands

# Fix most issues automatically
ruff format .
ruff check . --fix

# Run tests locally
pytest tests/unit/ --cov=markitdown_mcp

# Check types
mypy markitdown_mcp

Last updated: 2026-08-24 22:44:56 UTC

@github-actions

Copy link
Copy Markdown
Contributor Author

🔍 PR Quality Summary

CI Status

✅ Quality: success
✅ Security: success

Metrics

Metric Value Trend
📊 Coverage N/A -
🧪 Tests Test results unavailable -
⏱️ Performance No performance data -

Quality Checks

  • Format & Lint: Ruff formatting and linting
  • Type Safety: MyPy strict type checking
  • Security: Bandit, Safety, GitLeaks scanning
  • MCP Protocol: Tool schema validation
  • Documentation: Docstring coverage (80%+)

MCP Tools

  • convert_file - Convert individual files to Markdown
  • convert_directory - Batch convert directories
  • list_supported_formats - Query supported file types

🤖 Auto-generated by CI • Last updated: 2026-08-24 22:45 UTC

@trsdn
trsdn merged commit 2febb43 into main Aug 24, 2026
16 checks passed
@trsdn
trsdn deleted the version-bump/v1.2.2 branch August 24, 2026 22:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automatically generated content release Release-related pull requests and issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants