From 31296ddfe8c81c3a2519c163bf13158c40557008 Mon Sep 17 00:00:00 2001 From: Sylwester Lachiewicz Date: Tue, 6 Oct 2026 21:14:40 +0200 Subject: [PATCH 1/2] Group repeated dependency bumps and link the full changelog Needs release-drafter 7.9.0: group-changes arrived in 7.8.0 and $RESOLVED_TAG in 7.9.0. 7.8.0 also made the token input default to github.token, so the GITHUB_TOKEN env is gone. --- .github/release-drafter.yml | 13 ++++++++++++- .github/workflows/release-drafter.yml | 2 -- 2 files changed, 12 insertions(+), 3 deletions(-) diff --git a/.github/release-drafter.yml b/.github/release-drafter.yml index 3b2abfe..f904165 100644 --- a/.github/release-drafter.yml +++ b/.github/release-drafter.yml @@ -65,8 +65,19 @@ categories: when: labels: [dependencies] -change-template: '- $TITLE ([#$NUMBER]($URL)) @$AUTHOR' +# Dependabot bumps the same dependency several times between releases, most +# often the plexus parent and plexus-testing. Group each dependency into one +# entry with the full version range; $NUMBERS lists every pull request of it. +# group_in keeps a bump in one module apart from the same bump in another. +group-changes: + - pattern: '/^Bump (?.+?) from (?\S+) to (?\S+)(? in \S+)?$/' + title-template: 'Bump $GROUP from $FIRST_FROM to $LAST_TO$GROUP_IN' +change-template: '- $TITLE ($NUMBERS) @$AUTHOR' + +# $RESOLVED_TAG is the tag-template a repo sets, so the link includes its prefix. template: | $CHANGES + + [Full changelog](https://github.com/$OWNER/$REPOSITORY/compare/$PREVIOUS_TAG...$RESOLVED_TAG) diff --git a/.github/workflows/release-drafter.yml b/.github/workflows/release-drafter.yml index a3d0199..9a0d048 100644 --- a/.github/workflows/release-drafter.yml +++ b/.github/workflows/release-drafter.yml @@ -7,5 +7,3 @@ jobs: runs-on: ubuntu-latest steps: - uses: release-drafter/release-drafter@v7.9.0 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} From b6a3717809bc4ca3628decd42f7cc8c0369e417d Mon Sep 17 00:00:00 2001 From: Sylwester Lachiewicz Date: Tue, 6 Oct 2026 21:21:35 +0200 Subject: [PATCH 2/2] Declare the permissions the release drafter needs --- .github/workflows/release-drafter.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/release-drafter.yml b/.github/workflows/release-drafter.yml index 9a0d048..fc4407e 100644 --- a/.github/workflows/release-drafter.yml +++ b/.github/workflows/release-drafter.yml @@ -5,5 +5,10 @@ on: jobs: update_release_draft: runs-on: ubuntu-latest + # The draft release needs contents: write, reading merged pull requests + # needs pull-requests: read. Every calling repo grants both by default. + permissions: + contents: write + pull-requests: read steps: - uses: release-drafter/release-drafter@v7.9.0