Skip to content

chore: switch to changesets - #6511

Merged
KevinVandy merged 3 commits into
betafrom
changeset
Aug 4, 2026
Merged

chore: switch to changesets#6511
KevinVandy merged 3 commits into
betafrom
changeset

Conversation

@KevinVandy

@KevinVandy KevinVandy commented Aug 4, 2026

Copy link
Copy Markdown
Member

🎯 Changes

✅ Checklist

  • I have followed the steps in the Contributing guide.
  • I have tested this code locally with pnpm test:pr.

Summary by CodeRabbit

  • Release Process

    • Introduced Changesets-based versioning, changelog generation, release previews, and publishing.
    • Simplified automated releases for supported branches.
    • Added release comments to pull requests after publishing.
  • Documentation

    • Updated contribution guidance to require a changeset entry for release-impacting changes.
  • Developer Workflow

    • Added a pull request template with change, testing, and release-impact checklists.
    • Replaced the legacy publishing workflow and related configuration.

@KevinVandy
KevinVandy requested a review from a team as a code owner August 4, 2026 04:20
@nx-cloud

nx-cloud Bot commented Aug 4, 2026

Copy link
Copy Markdown

View your CI Pipeline Execution ↗ for commit 62d22ee

Command Status Duration Result
nx affected --targets=test:eslint,test:sherif,t... ✅ Succeeded 8m 19s View ↗
nx run-many --targets=build --exclude=examples/** ✅ Succeeded 1m 2s View ↗

☁️ Nx Cloud last updated this comment at 2026-08-04 04:50:07 UTC

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

🚀 Changeset Version Preview

No changeset entries found. Merging this PR will not cause a version bump for any packages.

@socket-security

socket-security Bot commented Aug 4, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​changesets/​changelog-github@​0.7.01001006893100
Added@​changesets/​cli@​2.31.19710010096100

View full report

@socket-security

socket-security Bot commented Aug 4, 2026

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 089e964b-f5e6-4422-b7fc-f18d73c36909

📥 Commits

Reviewing files that changed from the base of the PR and between 485d36c and ff00831.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (2)
  • .changeset/config.json
  • package.json
🚧 Files skipped from review as they are similar to previous changes (1)
  • .changeset/config.json

📝 Walkthrough

Walkthrough

The repository replaces its legacy publishing flow with Changesets. It adds release configuration, contributor guidance, pull request previews, and automated package versioning and publishing through GitHub Actions.

Changes

Changesets release workflow

Layer / File(s) Summary
Changesets foundation
.changeset/config.json, package.json, .github/pull_request_template.md, CONTRIBUTING.md
Adds Changesets configuration, package scripts, dependencies, pull request release options, and contributor instructions.
Pull request preview automation
.github/workflows/pr.yml
Includes .changeset/** in workflow triggers and adds a job that runs the Changesets Preview action.
Release workflow migration
.github/workflows/release.yml, scripts/config.js
Replaces manual publishing steps with the Changesets action and removes the legacy branch publication configuration.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Suggested reviewers: sheraff

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: switching the project to Changesets.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch changeset

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Aug 4, 2026

Copy link
Copy Markdown
More templates

@tanstack/alpine-table

npm i https://pkg.pr.new/TanStack/table/@tanstack/alpine-table@6511

@tanstack/angular-table

npm i https://pkg.pr.new/TanStack/table/@tanstack/angular-table@6511

@tanstack/angular-table-devtools

npm i https://pkg.pr.new/TanStack/table/@tanstack/angular-table-devtools@6511

@tanstack/ember-table

npm i https://pkg.pr.new/TanStack/table/@tanstack/ember-table@6511

@tanstack/lit-table

npm i https://pkg.pr.new/TanStack/table/@tanstack/lit-table@6511

@tanstack/match-sorter-utils

npm i https://pkg.pr.new/TanStack/table/@tanstack/match-sorter-utils@6511

@tanstack/octane-table

npm i https://pkg.pr.new/TanStack/table/@tanstack/octane-table@6511

@tanstack/preact-table

npm i https://pkg.pr.new/TanStack/table/@tanstack/preact-table@6511

@tanstack/preact-table-devtools

npm i https://pkg.pr.new/TanStack/table/@tanstack/preact-table-devtools@6511

@tanstack/react-table

npm i https://pkg.pr.new/TanStack/table/@tanstack/react-table@6511

@tanstack/react-table-devtools

npm i https://pkg.pr.new/TanStack/table/@tanstack/react-table-devtools@6511

@tanstack/solid-table

npm i https://pkg.pr.new/TanStack/table/@tanstack/solid-table@6511

@tanstack/solid-table-devtools

npm i https://pkg.pr.new/TanStack/table/@tanstack/solid-table-devtools@6511

@tanstack/svelte-table

npm i https://pkg.pr.new/TanStack/table/@tanstack/svelte-table@6511

@tanstack/table-core

npm i https://pkg.pr.new/TanStack/table/@tanstack/table-core@6511

@tanstack/table-devtools

npm i https://pkg.pr.new/TanStack/table/@tanstack/table-devtools@6511

@tanstack/vue-table

npm i https://pkg.pr.new/TanStack/table/@tanstack/vue-table@6511

@tanstack/vue-table-devtools

npm i https://pkg.pr.new/TanStack/table/@tanstack/vue-table-devtools@6511

commit: ff00831

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/pr.yml:
- Around line 74-88: Update the “Changeset Preview” step in the version-preview
job to reference an action revision of TanStack/config/.github/changeset-preview
that includes a committed lockfile and uses npm ci, then pin the workflow to
that immutable revision while preserving the existing permissions and step
behavior.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: d1400b69-02a1-4c81-a008-483a9f82eeb1

📥 Commits

Reviewing files that changed from the base of the PR and between d0f2ef7 and 485d36c.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (9)
  • .changeset/config.json
  • .github/pull_request_template.md
  • .github/workflows/pr.yml
  • .github/workflows/release.yml
  • CONTRIBUTING.md
  • package.json
  • scripts/config.js
  • scripts/publish.js
  • scripts/types.d.ts
💤 Files with no reviewable changes (3)
  • scripts/types.d.ts
  • scripts/publish.js
  • scripts/config.js

Comment thread .github/workflows/pr.yml
Comment on lines +74 to +88
version-preview:
name: Version Preview
permissions:
contents: read
pull-requests: write
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1
with:
persist-credentials: false
- name: Setup Tools
uses: tanstack/config/.github/setup@e4b48f16568324f76f467aa4c2aac2f05db632c3 # main
- name: Changeset Preview
uses: TanStack/config/.github/changeset-preview@e4b48f16568324f76f467aa4c2aac2f05db632c3 # main

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

ref='e4b48f16568324f76f467aa4c2aac2f05db632c3'
base="https://raw.githubusercontent.com/TanStack/config/${ref}/.github/changeset-preview"

curl -fsSL "${base}/action.yml" | sed -n '8,16p'
curl -fsSL "${base}/package.json" | jq '.dependencies'

Repository: TanStack/table

Length of output: 411


🏁 Script executed:

#!/bin/bash
set -euo pipefail

ref='e4b48f16568324f76f467aa4c2aac2f05db68f16568324f76f467aa4c2aac2f05db632c3'

# Avoid URL collisions with malformed ref; show only results for the actual pinned ref.
for r in e4b48f16568324f76f467aa4c2aac2f05db632c3; do
  base="https://raw.githubusercontent.com/TanStack/config/${r}/.github/changeset-preview"
  echo "== ref: ${r} =="
  echo "--- action.yml ---"
  curl -fsSL "${base}/action.yml" | nl -ba | sed -n '1,80p'
  echo "--- package files ---"
  for f in package.json package-lock.json npm-shrinkwrap.json yarn.lock pnpm-lock.yaml; do
    if curl -fsSL "${base}/${f}" | head -c 1 > /dev/null 2>&1; then
      echo "### ${f}"
      if [ "$f" = "package.json" ]; then
        curl -fsSL "${base}/${f}" | jq '{scripts, dependencies, devDependencies}'
      elif [ "$f" = "package-lock.json" ]; then
        curl -fsSL "${base}/${f}" | jq '{lockfileVersion, requiresRootLockfile, packages[""].version, packages[""].dependencies, packages[""].devDependencies, has lockfileVersion}'
      else
        curl -fsSL "${base}/${f}" | head -n 80
      fi
    else
      echo "### ${f} missing"
    fi
  done
done

echo "== workflow snippet =="
sed -n '70,90p' .github/workflows/pr.yml | nl -ba

Repository: TanStack/table

Length of output: 290


🏁 Script executed:

#!/bin/bash
set -euo pipefail

ref='e4b48f16568324f76f467aa4c2aac2f05db632c3'

echo "== action.yml first 80 lines =="
for line in $(seq 1 80); do
  printf '%d: ' "$line"
  curl -fsSL "https://raw.githubusercontent.com/TanStack/config/${ref}/.github/changeset-preview/action.yml" 2>/dev/null | sed -n "${line},${line}p"
done

echo
echo "== package metadata and lockfiles =="
for f in package.json package-lock.json npm-shrinkwrap.json yarn.lock pnpm-lock.yaml; do
  url="https://raw.githubusercontent.com/TanStack/config/${ref}/.github/changeset-preview/${f}"
  if curl -fsSLI "$url" >/dev/null 2>&1; then
    echo "### ${f} exists"
    if [ "$f" = "package.json" ]; then
      curl -fsSL "$url" | sed -n '1,220p'
    else
      curl -fsSL "$url" | sed -n '1,40p'
    fi
  else
    echo "### ${f} missing"
  fi
done

echo
echo "== workflow preview job =="
awk 'NR>=70 && NR<=90 {printf "%d: %s\n", NR, $0}' .github/workflows/pr.yml

Repository: TanStack/table

Length of output: 1318


Pin the preview action runtime dependencies.

TanStack/config/.github/changeset-preview runs npm install and declares @changesets/get-release-plan@^4.0.16 without a lockfile. This lets npm resolve a mutable dependency for each PR, while the job has pull-requests: write. Use an action revision with a committed lockfile and npm ci, then pin the workflow to that revision.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/pr.yml around lines 74 - 88, Update the “Changeset
Preview” step in the version-preview job to reference an action revision of
TanStack/config/.github/changeset-preview that includes a committed lockfile and
uses npm ci, then pin the workflow to that immutable revision while preserving
the existing permissions and step behavior.

@KevinVandy
KevinVandy merged commit 9e523bc into beta Aug 4, 2026
11 checks passed
@KevinVandy
KevinVandy deleted the changeset branch August 4, 2026 04:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant