You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
ci: add commitlint, Husky, and release-please (rebased from #2339) #2406
PR #2339 introduced automated version management and commit message validation but has become stale with merge conflicts. This issue tracks reimplementing the work on top of current main.
Original Changes
commitlint for conventional commit message validation
Husky git hooks for pre-commit checks
release-please for automated version bumping and changelog generation
Workflow changes to trigger CLI releases on GitHub release events
Security Review Status
All security concerns from #2339 have been resolved:
Command injection risks properly mitigated using printf '%s\n' with file redirection
Assessment: This is a rebased implementation of previously reviewed work (#2339) with all security concerns already addressed:
No new code injection risks identified
GitHub App token scoping is proper
Shell variable handling is safe
Credential management is secure
Status: This is safe to work on. Implementation should cherry-pick or re-implement the reviewed changes from #2339 on top of current main, resolve any merge conflicts, and ensure full test suite + lint checks pass.
Priority: Medium — infrastructure improvement for automated versioning and release management.
Recommendation: Safe to assign to a team member for implementation.
Thanks for filing! This involves .github/workflows/*.yml changes which require manual review by the core team — outside scope for automated refactoring. Tagging for human review.
PR #2416 addresses the commitlint + Husky portions of this request. release-please was intentionally omitted as it requires workflow file changes that need manual core team review.
Summary
PR #2339 introduced automated version management and commit message validation but has become stale with merge conflicts. This issue tracks reimplementing the work on top of current main.
Original Changes
Security Review Status
All security concerns from #2339 have been resolved:
printf '%s\n'with file redirectionImplementation Notes
References