Skip to content

ci(repo): dogfood snapi api checks - #8621

Merged
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi
May 27, 2026
Merged

ci(repo): dogfood snapi api checks#8621
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi

Conversation

@jacekradko

@jacekradkojacekradko commented May 21, 2026

Copy link
Copy Markdown
Contributor

Stands up snapi API-change detection for backend, clerk-js, nextjs, react, shared, and ui. On push to main and the release branches a publish-baseline job writes the snapshot to a sha-keyed GHA cache; PR runs restore from it, falling back to rebuilding from a worktree at pull_request.base.sha on a full miss. Snapi itself is pulled from pkg.pr.new because clerk/snapi is private.

continue-on-error: true on the job keeps the workflow non-blocking while we shake it out.

Here is an example PR with breaking changes in clerk/snapi: clerk/break-check#21

Here is a sample of a breaking-change report:

Screenshot 2026-05-23 at 11 09 41 AMScreenshot 2026-05-23 at 11 09 52 AMScreenshot 2026-05-23 at 11 10 02 AMScreenshot 2026-05-23 at 11 10 14 AM

@changeset-bot

changeset-botBot commented May 21, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: a182d1c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 21, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 27, 2026 3:44pm

Request Review

@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR adds SNAPI-based API change detection: a new snapi.config.json lists four packages to scan and snapshot settings; a GitHub Actions workflow (api-changes.yml) now runs on push and pull_request for main and release branches, adds a publish-baseline job for push that builds declarations and caches baseline snapshots, and reworks the check-api job for PRs to restore or build baseline snapshots, run snapi detect (failing on breaking changes), and upload api-changes-report.md. The UI package gains a declarations-only tsconfig and a build:declarations script. A changeset entry was updated.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'ci(repo): dogfood snapi api checks' clearly and concisely describes the main change—setting up the snapi API-checks workflow for testing purposes in the repository.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description clearly explains the purpose of the changes: setting up snapi API-change detection for multiple packages with a GitHub Actions workflow that uses caching and fallback mechanisms.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Line 67: The workflow generates current snapshots to ".api-snapshots-current"
but snapi.config.json uses snapshotDir ".api-snapshots", so update the pnpm dlx
snapi snapshot invocation or the snapi.detect invocation to use the same
directory: either change the snapshot command (the run line that calls "pnpm dlx
--package \"$SNAPI_PACKAGE\" snapi snapshot --output .api-snapshots-current") to
output to ".api-snapshots" or pass the explicit --current flag/--output value to
the "snapi detect" step so it points at ".api-snapshots-current", ensuring the
snapshot generation and detection commands reference the same directory.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 9f43cc8f-f375-42fc-a605-7463dfc82b40

📥 Commits

Reviewing files that changed from the base of the PR and between 2f003bc and 741ad85.

📒 Files selected for processing (3)
  • .changeset/dogfood-snapi.md
  • .github/workflows/api-changes.yml
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml Outdated
@pkg-pr-new

pkg-pr-newBot commented May 22, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8621

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8621

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8621

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8621

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8621

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8621

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8621

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8621

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8621

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8621

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8621

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8621

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8621

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8621

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8621

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8621

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8621

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8621

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8621

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8621

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8621

commit: a182d1c

Publish the API baseline to a GHA cache on push to main and the release
branches, keyed by commit sha. PR runs restore from that cache with a
prefix-match fallback, and only rebuild the baseline via worktree on a
full miss.
Add @clerk/ui to the watched package set with a tsc-based
build:declarations task matching @clerk/shared's pattern.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 124-127: The fallback fetch uses a moving ref
(origin/${GITHUB_BASE_REF}) which can drift; change the git fetch invocation(s)
that currently use GITHUB_BASE_REF to fetch the immutable PR base SHA
(github.event.pull_request.base.sha) instead so the fallback baseline matches
the PR base commit; update both occurrences of the fetch command in the workflow
to use the PR base SHA when populating refs/remotes/origin/${GITHUB_BASE_REF}.
- Around line 57-61: Update the workflow steps that use actions to pin their
versions to specific commit SHAs and disable persisted credentials: replace both
uses of actions/checkout@v4 (the "Checkout Repo" steps) with the corresponding
actions/checkout@<commit-sha> and add persist-credentials: false under their
with blocks; likewise replace actions/cache/save@v4 and actions/cache/restore@v4
with their pinned commit SHAs (actions/cache/save@<commit-sha>,
actions/cache/restore@<commit-sha>). Ensure you only change the version
specifiers and add the persist-credentials: false key to the checkout steps
while keeping existing keys like filter and show-progress intact.
- Around line 112-120: The baseline cache restore step (id baseline-cache using
actions/cache/restore@v4) must gate rebuilds on an exact cache hit, not partial
matches: change the rebuild condition to check
steps.baseline-cache.outputs.cache-hit != 'true' so any non-exact hit (including
partial matches) triggers the rebuild; when rebuilding, ensure the checkout used
to create the baseline worktree checks out the immutable PR base SHA (use ref:
${{ github.event.pull_request.base.sha }} or GITHUB event value) instead of
GITHUB_BASE_REF; set persist-credentials: false on both actions/checkout steps
to avoid leaking tokens; and pin external actions (actions/cache,
actions/checkout, etc.) to specific commit SHAs instead of floating `@v4` tags.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: c19b2a18-6732-4ac4-a1ee-d17aff1504ca

📥 Commits

Reviewing files that changed from the base of the PR and between dd6e886 and 7b226d2.

📒 Files selected for processing (4)
  • .github/workflows/api-changes.yml
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json
✅ Files skipped from review due to trivial changes (3)
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml Outdated
snapi's baseline worktree checks out the PR's base branch but uses
HEAD's snapi config. When a watched package's build:declarations task
is added in the same PR that starts watching it, the baseline tree
doesn't yet have the task and the fallback build fails. Copy ui's
package.json and tsconfig.declarations.json from HEAD into the
worktree before installing, matching the existing pattern for
snapi.config.json.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 138-139: The workflow currently copies the entire
packages/ui/package.json into .worktrees/snapi-baseline/packages/ui/package.json
which imports PR-head manifest changes; instead update only the
scripts.build:declarations entry in the baseline package.json. In the
.github/workflows/api-changes.yml replace the two cp commands that reference
packages/ui/package.json and .worktrees/snapi-baseline/packages/ui/package.json
with a command that reads packages/ui/package.json, extracts the
"build:declarations" script, and patches
.worktrees/snapi-baseline/packages/ui/package.json to set
.scripts["build:declarations"] to that value (preserving all other fields).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: cc276cc0-8fbe-4284-9389-6221b9dcb1cb

📥 Commits

Reviewing files that changed from the base of the PR and between 7b226d2 and b54cb52.

📒 Files selected for processing (1)
  • .github/workflows/api-changes.yml

Comment thread.github/workflows/api-changes.yml Outdated
pnpm 10 mishandles `pnpm --dir <path> <non-builtin> ...`, treating the
path as the command to execute and erroring with
ERR_PNPM_RECURSIVE_EXEC_FIRST_FAIL. Switching the worktree-fallback
install/build/snapshot steps to GHA's `working-directory:` avoids the
flag entirely.
clerk/snapi is private, so pnpm dlx --package "github:clerk/snapi#..."
fails on Actions runners with no SSH key. Switch to the public
pkg.pr.new tarball URL pinned to the latest snapi PR build.
Also pin the worktree-fallback baseline to the immutable
pull_request.base.sha instead of origin/<base-branch>; if the base
branch advances during the run, this prevents drift between the
cached baseline lookup key and what the worktree actually checks out.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@alexcarpenter@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
ci(repo): dogfood snapi api checks by jacekradko · Pull Request #8621 · clerk/javascript · GitHub
Skip to content

ci(repo): dogfood snapi api checks - #8621

Merged
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi
May 27, 2026
Merged

ci(repo): dogfood snapi api checks#8621
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi

Conversation

@jacekradko

@jacekradkojacekradko commented May 21, 2026

Copy link
Copy Markdown
Contributor

Stands up snapi API-change detection for backend, clerk-js, nextjs, react, shared, and ui. On push to main and the release branches a publish-baseline job writes the snapshot to a sha-keyed GHA cache; PR runs restore from it, falling back to rebuilding from a worktree at pull_request.base.sha on a full miss. Snapi itself is pulled from pkg.pr.new because clerk/snapi is private.

continue-on-error: true on the job keeps the workflow non-blocking while we shake it out.

Here is an example PR with breaking changes in clerk/snapi: clerk/break-check#21

Here is a sample of a breaking-change report:

Screenshot 2026-05-23 at 11 09 41 AMScreenshot 2026-05-23 at 11 09 52 AMScreenshot 2026-05-23 at 11 10 02 AMScreenshot 2026-05-23 at 11 10 14 AM

@changeset-bot

changeset-botBot commented May 21, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: a182d1c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 21, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 27, 2026 3:44pm

Request Review

@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR adds SNAPI-based API change detection: a new snapi.config.json lists four packages to scan and snapshot settings; a GitHub Actions workflow (api-changes.yml) now runs on push and pull_request for main and release branches, adds a publish-baseline job for push that builds declarations and caches baseline snapshots, and reworks the check-api job for PRs to restore or build baseline snapshots, run snapi detect (failing on breaking changes), and upload api-changes-report.md. The UI package gains a declarations-only tsconfig and a build:declarations script. A changeset entry was updated.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'ci(repo): dogfood snapi api checks' clearly and concisely describes the main change—setting up the snapi API-checks workflow for testing purposes in the repository.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description clearly explains the purpose of the changes: setting up snapi API-change detection for multiple packages with a GitHub Actions workflow that uses caching and fallback mechanisms.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Line 67: The workflow generates current snapshots to ".api-snapshots-current"
but snapi.config.json uses snapshotDir ".api-snapshots", so update the pnpm dlx
snapi snapshot invocation or the snapi.detect invocation to use the same
directory: either change the snapshot command (the run line that calls "pnpm dlx
--package \"$SNAPI_PACKAGE\" snapi snapshot --output .api-snapshots-current") to
output to ".api-snapshots" or pass the explicit --current flag/--output value to
the "snapi detect" step so it points at ".api-snapshots-current", ensuring the
snapshot generation and detection commands reference the same directory.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 9f43cc8f-f375-42fc-a605-7463dfc82b40

📥 Commits

Reviewing files that changed from the base of the PR and between 2f003bc and 741ad85.

📒 Files selected for processing (3)
  • .changeset/dogfood-snapi.md
  • .github/workflows/api-changes.yml
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml Outdated
@pkg-pr-new

pkg-pr-newBot commented May 22, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8621

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8621

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8621

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8621

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8621

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8621

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8621

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8621

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8621

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8621

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8621

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8621

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8621

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8621

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8621

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8621

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8621

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8621

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8621

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8621

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8621

commit: a182d1c

Publish the API baseline to a GHA cache on push to main and the release
branches, keyed by commit sha. PR runs restore from that cache with a
prefix-match fallback, and only rebuild the baseline via worktree on a
full miss.
Add @clerk/ui to the watched package set with a tsc-based
build:declarations task matching @clerk/shared's pattern.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 124-127: The fallback fetch uses a moving ref
(origin/${GITHUB_BASE_REF}) which can drift; change the git fetch invocation(s)
that currently use GITHUB_BASE_REF to fetch the immutable PR base SHA
(github.event.pull_request.base.sha) instead so the fallback baseline matches
the PR base commit; update both occurrences of the fetch command in the workflow
to use the PR base SHA when populating refs/remotes/origin/${GITHUB_BASE_REF}.
- Around line 57-61: Update the workflow steps that use actions to pin their
versions to specific commit SHAs and disable persisted credentials: replace both
uses of actions/checkout@v4 (the "Checkout Repo" steps) with the corresponding
actions/checkout@<commit-sha> and add persist-credentials: false under their
with blocks; likewise replace actions/cache/save@v4 and actions/cache/restore@v4
with their pinned commit SHAs (actions/cache/save@<commit-sha>,
actions/cache/restore@<commit-sha>). Ensure you only change the version
specifiers and add the persist-credentials: false key to the checkout steps
while keeping existing keys like filter and show-progress intact.
- Around line 112-120: The baseline cache restore step (id baseline-cache using
actions/cache/restore@v4) must gate rebuilds on an exact cache hit, not partial
matches: change the rebuild condition to check
steps.baseline-cache.outputs.cache-hit != 'true' so any non-exact hit (including
partial matches) triggers the rebuild; when rebuilding, ensure the checkout used
to create the baseline worktree checks out the immutable PR base SHA (use ref:
${{ github.event.pull_request.base.sha }} or GITHUB event value) instead of
GITHUB_BASE_REF; set persist-credentials: false on both actions/checkout steps
to avoid leaking tokens; and pin external actions (actions/cache,
actions/checkout, etc.) to specific commit SHAs instead of floating `@v4` tags.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: c19b2a18-6732-4ac4-a1ee-d17aff1504ca

📥 Commits

Reviewing files that changed from the base of the PR and between dd6e886 and 7b226d2.

📒 Files selected for processing (4)
  • .github/workflows/api-changes.yml
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json
✅ Files skipped from review due to trivial changes (3)
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml Outdated
snapi's baseline worktree checks out the PR's base branch but uses
HEAD's snapi config. When a watched package's build:declarations task
is added in the same PR that starts watching it, the baseline tree
doesn't yet have the task and the fallback build fails. Copy ui's
package.json and tsconfig.declarations.json from HEAD into the
worktree before installing, matching the existing pattern for
snapi.config.json.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 138-139: The workflow currently copies the entire
packages/ui/package.json into .worktrees/snapi-baseline/packages/ui/package.json
which imports PR-head manifest changes; instead update only the
scripts.build:declarations entry in the baseline package.json. In the
.github/workflows/api-changes.yml replace the two cp commands that reference
packages/ui/package.json and .worktrees/snapi-baseline/packages/ui/package.json
with a command that reads packages/ui/package.json, extracts the
"build:declarations" script, and patches
.worktrees/snapi-baseline/packages/ui/package.json to set
.scripts["build:declarations"] to that value (preserving all other fields).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: cc276cc0-8fbe-4284-9389-6221b9dcb1cb

📥 Commits

Reviewing files that changed from the base of the PR and between 7b226d2 and b54cb52.

📒 Files selected for processing (1)
  • .github/workflows/api-changes.yml

Comment thread.github/workflows/api-changes.yml Outdated
pnpm 10 mishandles `pnpm --dir <path> <non-builtin> ...`, treating the
path as the command to execute and erroring with
ERR_PNPM_RECURSIVE_EXEC_FIRST_FAIL. Switching the worktree-fallback
install/build/snapshot steps to GHA's `working-directory:` avoids the
flag entirely.
clerk/snapi is private, so pnpm dlx --package "github:clerk/snapi#..."
fails on Actions runners with no SSH key. Switch to the public
pkg.pr.new tarball URL pinned to the latest snapi PR build.
Also pin the worktree-fallback baseline to the immutable
pull_request.base.sha instead of origin/<base-branch>; if the base
branch advances during the run, this prevents drift between the
cached baseline lookup key and what the worktree actually checks out.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@alexcarpenter@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci(repo): dogfood snapi api checks by jacekradko · Pull Request #8621 · clerk/javascript · GitHub
Skip to content

ci(repo): dogfood snapi api checks - #8621

Merged
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi
May 27, 2026
Merged

ci(repo): dogfood snapi api checks#8621
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi

Conversation

@jacekradko

@jacekradkojacekradko commented May 21, 2026

Copy link
Copy Markdown
Contributor

Stands up snapi API-change detection for backend, clerk-js, nextjs, react, shared, and ui. On push to main and the release branches a publish-baseline job writes the snapshot to a sha-keyed GHA cache; PR runs restore from it, falling back to rebuilding from a worktree at pull_request.base.sha on a full miss. Snapi itself is pulled from pkg.pr.new because clerk/snapi is private.

continue-on-error: true on the job keeps the workflow non-blocking while we shake it out.

Here is an example PR with breaking changes in clerk/snapi: clerk/break-check#21

Here is a sample of a breaking-change report:

Screenshot 2026-05-23 at 11 09 41 AMScreenshot 2026-05-23 at 11 09 52 AMScreenshot 2026-05-23 at 11 10 02 AMScreenshot 2026-05-23 at 11 10 14 AM

@changeset-bot

changeset-botBot commented May 21, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: a182d1c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 21, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 27, 2026 3:44pm

Request Review

@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR adds SNAPI-based API change detection: a new snapi.config.json lists four packages to scan and snapshot settings; a GitHub Actions workflow (api-changes.yml) now runs on push and pull_request for main and release branches, adds a publish-baseline job for push that builds declarations and caches baseline snapshots, and reworks the check-api job for PRs to restore or build baseline snapshots, run snapi detect (failing on breaking changes), and upload api-changes-report.md. The UI package gains a declarations-only tsconfig and a build:declarations script. A changeset entry was updated.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'ci(repo): dogfood snapi api checks' clearly and concisely describes the main change—setting up the snapi API-checks workflow for testing purposes in the repository.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description clearly explains the purpose of the changes: setting up snapi API-change detection for multiple packages with a GitHub Actions workflow that uses caching and fallback mechanisms.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Line 67: The workflow generates current snapshots to ".api-snapshots-current"
but snapi.config.json uses snapshotDir ".api-snapshots", so update the pnpm dlx
snapi snapshot invocation or the snapi.detect invocation to use the same
directory: either change the snapshot command (the run line that calls "pnpm dlx
--package \"$SNAPI_PACKAGE\" snapi snapshot --output .api-snapshots-current") to
output to ".api-snapshots" or pass the explicit --current flag/--output value to
the "snapi detect" step so it points at ".api-snapshots-current", ensuring the
snapshot generation and detection commands reference the same directory.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 9f43cc8f-f375-42fc-a605-7463dfc82b40

📥 Commits

Reviewing files that changed from the base of the PR and between 2f003bc and 741ad85.

📒 Files selected for processing (3)
  • .changeset/dogfood-snapi.md
  • .github/workflows/api-changes.yml
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml Outdated
@pkg-pr-new

pkg-pr-newBot commented May 22, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8621

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8621

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8621

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8621

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8621

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8621

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8621

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8621

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8621

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8621

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8621

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8621

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8621

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8621

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8621

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8621

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8621

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8621

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8621

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8621

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8621

commit: a182d1c

Publish the API baseline to a GHA cache on push to main and the release
branches, keyed by commit sha. PR runs restore from that cache with a
prefix-match fallback, and only rebuild the baseline via worktree on a
full miss.
Add @clerk/ui to the watched package set with a tsc-based
build:declarations task matching @clerk/shared's pattern.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 124-127: The fallback fetch uses a moving ref
(origin/${GITHUB_BASE_REF}) which can drift; change the git fetch invocation(s)
that currently use GITHUB_BASE_REF to fetch the immutable PR base SHA
(github.event.pull_request.base.sha) instead so the fallback baseline matches
the PR base commit; update both occurrences of the fetch command in the workflow
to use the PR base SHA when populating refs/remotes/origin/${GITHUB_BASE_REF}.
- Around line 57-61: Update the workflow steps that use actions to pin their
versions to specific commit SHAs and disable persisted credentials: replace both
uses of actions/checkout@v4 (the "Checkout Repo" steps) with the corresponding
actions/checkout@<commit-sha> and add persist-credentials: false under their
with blocks; likewise replace actions/cache/save@v4 and actions/cache/restore@v4
with their pinned commit SHAs (actions/cache/save@<commit-sha>,
actions/cache/restore@<commit-sha>). Ensure you only change the version
specifiers and add the persist-credentials: false key to the checkout steps
while keeping existing keys like filter and show-progress intact.
- Around line 112-120: The baseline cache restore step (id baseline-cache using
actions/cache/restore@v4) must gate rebuilds on an exact cache hit, not partial
matches: change the rebuild condition to check
steps.baseline-cache.outputs.cache-hit != 'true' so any non-exact hit (including
partial matches) triggers the rebuild; when rebuilding, ensure the checkout used
to create the baseline worktree checks out the immutable PR base SHA (use ref:
${{ github.event.pull_request.base.sha }} or GITHUB event value) instead of
GITHUB_BASE_REF; set persist-credentials: false on both actions/checkout steps
to avoid leaking tokens; and pin external actions (actions/cache,
actions/checkout, etc.) to specific commit SHAs instead of floating `@v4` tags.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: c19b2a18-6732-4ac4-a1ee-d17aff1504ca

📥 Commits

Reviewing files that changed from the base of the PR and between dd6e886 and 7b226d2.

📒 Files selected for processing (4)
  • .github/workflows/api-changes.yml
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json
✅ Files skipped from review due to trivial changes (3)
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml Outdated
snapi's baseline worktree checks out the PR's base branch but uses
HEAD's snapi config. When a watched package's build:declarations task
is added in the same PR that starts watching it, the baseline tree
doesn't yet have the task and the fallback build fails. Copy ui's
package.json and tsconfig.declarations.json from HEAD into the
worktree before installing, matching the existing pattern for
snapi.config.json.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 138-139: The workflow currently copies the entire
packages/ui/package.json into .worktrees/snapi-baseline/packages/ui/package.json
which imports PR-head manifest changes; instead update only the
scripts.build:declarations entry in the baseline package.json. In the
.github/workflows/api-changes.yml replace the two cp commands that reference
packages/ui/package.json and .worktrees/snapi-baseline/packages/ui/package.json
with a command that reads packages/ui/package.json, extracts the
"build:declarations" script, and patches
.worktrees/snapi-baseline/packages/ui/package.json to set
.scripts["build:declarations"] to that value (preserving all other fields).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: cc276cc0-8fbe-4284-9389-6221b9dcb1cb

📥 Commits

Reviewing files that changed from the base of the PR and between 7b226d2 and b54cb52.

📒 Files selected for processing (1)
  • .github/workflows/api-changes.yml

Comment thread.github/workflows/api-changes.yml Outdated
pnpm 10 mishandles `pnpm --dir <path> <non-builtin> ...`, treating the
path as the command to execute and erroring with
ERR_PNPM_RECURSIVE_EXEC_FIRST_FAIL. Switching the worktree-fallback
install/build/snapshot steps to GHA's `working-directory:` avoids the
flag entirely.
clerk/snapi is private, so pnpm dlx --package "github:clerk/snapi#..."
fails on Actions runners with no SSH key. Switch to the public
pkg.pr.new tarball URL pinned to the latest snapi PR build.
Also pin the worktree-fallback baseline to the immutable
pull_request.base.sha instead of origin/<base-branch>; if the base
branch advances during the run, this prevents drift between the
cached baseline lookup key and what the worktree actually checks out.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@alexcarpenter@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci(repo): dogfood snapi api checks by jacekradko · Pull Request #8621 · clerk/javascript · GitHub
Skip to content

ci(repo): dogfood snapi api checks - #8621

Merged
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi
May 27, 2026
Merged

ci(repo): dogfood snapi api checks#8621
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi

Conversation

@jacekradko

@jacekradkojacekradko commented May 21, 2026

Copy link
Copy Markdown
Contributor

Stands up snapi API-change detection for backend, clerk-js, nextjs, react, shared, and ui. On push to main and the release branches a publish-baseline job writes the snapshot to a sha-keyed GHA cache; PR runs restore from it, falling back to rebuilding from a worktree at pull_request.base.sha on a full miss. Snapi itself is pulled from pkg.pr.new because clerk/snapi is private.

continue-on-error: true on the job keeps the workflow non-blocking while we shake it out.

Here is an example PR with breaking changes in clerk/snapi: clerk/break-check#21

Here is a sample of a breaking-change report:

Screenshot 2026-05-23 at 11 09 41 AMScreenshot 2026-05-23 at 11 09 52 AMScreenshot 2026-05-23 at 11 10 02 AMScreenshot 2026-05-23 at 11 10 14 AM

@changeset-bot

changeset-botBot commented May 21, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: a182d1c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 21, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 27, 2026 3:44pm

Request Review

@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR adds SNAPI-based API change detection: a new snapi.config.json lists four packages to scan and snapshot settings; a GitHub Actions workflow (api-changes.yml) now runs on push and pull_request for main and release branches, adds a publish-baseline job for push that builds declarations and caches baseline snapshots, and reworks the check-api job for PRs to restore or build baseline snapshots, run snapi detect (failing on breaking changes), and upload api-changes-report.md. The UI package gains a declarations-only tsconfig and a build:declarations script. A changeset entry was updated.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'ci(repo): dogfood snapi api checks' clearly and concisely describes the main change—setting up the snapi API-checks workflow for testing purposes in the repository.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description clearly explains the purpose of the changes: setting up snapi API-change detection for multiple packages with a GitHub Actions workflow that uses caching and fallback mechanisms.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Line 67: The workflow generates current snapshots to ".api-snapshots-current"
but snapi.config.json uses snapshotDir ".api-snapshots", so update the pnpm dlx
snapi snapshot invocation or the snapi.detect invocation to use the same
directory: either change the snapshot command (the run line that calls "pnpm dlx
--package \"$SNAPI_PACKAGE\" snapi snapshot --output .api-snapshots-current") to
output to ".api-snapshots" or pass the explicit --current flag/--output value to
the "snapi detect" step so it points at ".api-snapshots-current", ensuring the
snapshot generation and detection commands reference the same directory.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 9f43cc8f-f375-42fc-a605-7463dfc82b40

📥 Commits

Reviewing files that changed from the base of the PR and between 2f003bc and 741ad85.

📒 Files selected for processing (3)
  • .changeset/dogfood-snapi.md
  • .github/workflows/api-changes.yml
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml Outdated
@pkg-pr-new

pkg-pr-newBot commented May 22, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8621

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8621

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8621

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8621

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8621

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8621

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8621

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8621

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8621

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8621

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8621

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8621

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8621

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8621

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8621

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8621

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8621

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8621

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8621

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8621

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8621

commit: a182d1c

Publish the API baseline to a GHA cache on push to main and the release
branches, keyed by commit sha. PR runs restore from that cache with a
prefix-match fallback, and only rebuild the baseline via worktree on a
full miss.
Add @clerk/ui to the watched package set with a tsc-based
build:declarations task matching @clerk/shared's pattern.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 124-127: The fallback fetch uses a moving ref
(origin/${GITHUB_BASE_REF}) which can drift; change the git fetch invocation(s)
that currently use GITHUB_BASE_REF to fetch the immutable PR base SHA
(github.event.pull_request.base.sha) instead so the fallback baseline matches
the PR base commit; update both occurrences of the fetch command in the workflow
to use the PR base SHA when populating refs/remotes/origin/${GITHUB_BASE_REF}.
- Around line 57-61: Update the workflow steps that use actions to pin their
versions to specific commit SHAs and disable persisted credentials: replace both
uses of actions/checkout@v4 (the "Checkout Repo" steps) with the corresponding
actions/checkout@<commit-sha> and add persist-credentials: false under their
with blocks; likewise replace actions/cache/save@v4 and actions/cache/restore@v4
with their pinned commit SHAs (actions/cache/save@<commit-sha>,
actions/cache/restore@<commit-sha>). Ensure you only change the version
specifiers and add the persist-credentials: false key to the checkout steps
while keeping existing keys like filter and show-progress intact.
- Around line 112-120: The baseline cache restore step (id baseline-cache using
actions/cache/restore@v4) must gate rebuilds on an exact cache hit, not partial
matches: change the rebuild condition to check
steps.baseline-cache.outputs.cache-hit != 'true' so any non-exact hit (including
partial matches) triggers the rebuild; when rebuilding, ensure the checkout used
to create the baseline worktree checks out the immutable PR base SHA (use ref:
${{ github.event.pull_request.base.sha }} or GITHUB event value) instead of
GITHUB_BASE_REF; set persist-credentials: false on both actions/checkout steps
to avoid leaking tokens; and pin external actions (actions/cache,
actions/checkout, etc.) to specific commit SHAs instead of floating `@v4` tags.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: c19b2a18-6732-4ac4-a1ee-d17aff1504ca

📥 Commits

Reviewing files that changed from the base of the PR and between dd6e886 and 7b226d2.

📒 Files selected for processing (4)
  • .github/workflows/api-changes.yml
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json
✅ Files skipped from review due to trivial changes (3)
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml Outdated
snapi's baseline worktree checks out the PR's base branch but uses
HEAD's snapi config. When a watched package's build:declarations task
is added in the same PR that starts watching it, the baseline tree
doesn't yet have the task and the fallback build fails. Copy ui's
package.json and tsconfig.declarations.json from HEAD into the
worktree before installing, matching the existing pattern for
snapi.config.json.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 138-139: The workflow currently copies the entire
packages/ui/package.json into .worktrees/snapi-baseline/packages/ui/package.json
which imports PR-head manifest changes; instead update only the
scripts.build:declarations entry in the baseline package.json. In the
.github/workflows/api-changes.yml replace the two cp commands that reference
packages/ui/package.json and .worktrees/snapi-baseline/packages/ui/package.json
with a command that reads packages/ui/package.json, extracts the
"build:declarations" script, and patches
.worktrees/snapi-baseline/packages/ui/package.json to set
.scripts["build:declarations"] to that value (preserving all other fields).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: cc276cc0-8fbe-4284-9389-6221b9dcb1cb

📥 Commits

Reviewing files that changed from the base of the PR and between 7b226d2 and b54cb52.

📒 Files selected for processing (1)
  • .github/workflows/api-changes.yml

Comment thread.github/workflows/api-changes.yml Outdated
pnpm 10 mishandles `pnpm --dir <path> <non-builtin> ...`, treating the
path as the command to execute and erroring with
ERR_PNPM_RECURSIVE_EXEC_FIRST_FAIL. Switching the worktree-fallback
install/build/snapshot steps to GHA's `working-directory:` avoids the
flag entirely.
clerk/snapi is private, so pnpm dlx --package "github:clerk/snapi#..."
fails on Actions runners with no SSH key. Switch to the public
pkg.pr.new tarball URL pinned to the latest snapi PR build.
Also pin the worktree-fallback baseline to the immutable
pull_request.base.sha instead of origin/<base-branch>; if the base
branch advances during the run, this prevents drift between the
cached baseline lookup key and what the worktree actually checks out.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@alexcarpenter@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' ci(repo): dogfood snapi api checks by jacekradko · Pull Request #8621 · clerk/javascript · GitHub
Skip to content

ci(repo): dogfood snapi api checks - #8621

Merged
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi
May 27, 2026
Merged

ci(repo): dogfood snapi api checks#8621
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi

Conversation

@jacekradko

@jacekradkojacekradko commented May 21, 2026

Copy link
Copy Markdown
Contributor

Stands up snapi API-change detection for backend, clerk-js, nextjs, react, shared, and ui. On push to main and the release branches a publish-baseline job writes the snapshot to a sha-keyed GHA cache; PR runs restore from it, falling back to rebuilding from a worktree at pull_request.base.sha on a full miss. Snapi itself is pulled from pkg.pr.new because clerk/snapi is private.

continue-on-error: true on the job keeps the workflow non-blocking while we shake it out.

Here is an example PR with breaking changes in clerk/snapi: clerk/break-check#21

Here is a sample of a breaking-change report:

Screenshot 2026-05-23 at 11 09 41 AMScreenshot 2026-05-23 at 11 09 52 AMScreenshot 2026-05-23 at 11 10 02 AMScreenshot 2026-05-23 at 11 10 14 AM

@changeset-bot

changeset-botBot commented May 21, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: a182d1c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 21, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 27, 2026 3:44pm

Request Review

@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR adds SNAPI-based API change detection: a new snapi.config.json lists four packages to scan and snapshot settings; a GitHub Actions workflow (api-changes.yml) now runs on push and pull_request for main and release branches, adds a publish-baseline job for push that builds declarations and caches baseline snapshots, and reworks the check-api job for PRs to restore or build baseline snapshots, run snapi detect (failing on breaking changes), and upload api-changes-report.md. The UI package gains a declarations-only tsconfig and a build:declarations script. A changeset entry was updated.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'ci(repo): dogfood snapi api checks' clearly and concisely describes the main change—setting up the snapi API-checks workflow for testing purposes in the repository.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description clearly explains the purpose of the changes: setting up snapi API-change detection for multiple packages with a GitHub Actions workflow that uses caching and fallback mechanisms.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Line 67: The workflow generates current snapshots to ".api-snapshots-current"
but snapi.config.json uses snapshotDir ".api-snapshots", so update the pnpm dlx
snapi snapshot invocation or the snapi.detect invocation to use the same
directory: either change the snapshot command (the run line that calls "pnpm dlx
--package \"$SNAPI_PACKAGE\" snapi snapshot --output .api-snapshots-current") to
output to ".api-snapshots" or pass the explicit --current flag/--output value to
the "snapi detect" step so it points at ".api-snapshots-current", ensuring the
snapshot generation and detection commands reference the same directory.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 9f43cc8f-f375-42fc-a605-7463dfc82b40

📥 Commits

Reviewing files that changed from the base of the PR and between 2f003bc and 741ad85.

📒 Files selected for processing (3)
  • .changeset/dogfood-snapi.md
  • .github/workflows/api-changes.yml
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml Outdated
@pkg-pr-new

pkg-pr-newBot commented May 22, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8621

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8621

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8621

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8621

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8621

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8621

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8621

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8621

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8621

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8621

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8621

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8621

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8621

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8621

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8621

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8621

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8621

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8621

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8621

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8621

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8621

commit: a182d1c

Publish the API baseline to a GHA cache on push to main and the release
branches, keyed by commit sha. PR runs restore from that cache with a
prefix-match fallback, and only rebuild the baseline via worktree on a
full miss.
Add @clerk/ui to the watched package set with a tsc-based
build:declarations task matching @clerk/shared's pattern.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 124-127: The fallback fetch uses a moving ref
(origin/${GITHUB_BASE_REF}) which can drift; change the git fetch invocation(s)
that currently use GITHUB_BASE_REF to fetch the immutable PR base SHA
(github.event.pull_request.base.sha) instead so the fallback baseline matches
the PR base commit; update both occurrences of the fetch command in the workflow
to use the PR base SHA when populating refs/remotes/origin/${GITHUB_BASE_REF}.
- Around line 57-61: Update the workflow steps that use actions to pin their
versions to specific commit SHAs and disable persisted credentials: replace both
uses of actions/checkout@v4 (the "Checkout Repo" steps) with the corresponding
actions/checkout@<commit-sha> and add persist-credentials: false under their
with blocks; likewise replace actions/cache/save@v4 and actions/cache/restore@v4
with their pinned commit SHAs (actions/cache/save@<commit-sha>,
actions/cache/restore@<commit-sha>). Ensure you only change the version
specifiers and add the persist-credentials: false key to the checkout steps
while keeping existing keys like filter and show-progress intact.
- Around line 112-120: The baseline cache restore step (id baseline-cache using
actions/cache/restore@v4) must gate rebuilds on an exact cache hit, not partial
matches: change the rebuild condition to check
steps.baseline-cache.outputs.cache-hit != 'true' so any non-exact hit (including
partial matches) triggers the rebuild; when rebuilding, ensure the checkout used
to create the baseline worktree checks out the immutable PR base SHA (use ref:
${{ github.event.pull_request.base.sha }} or GITHUB event value) instead of
GITHUB_BASE_REF; set persist-credentials: false on both actions/checkout steps
to avoid leaking tokens; and pin external actions (actions/cache,
actions/checkout, etc.) to specific commit SHAs instead of floating `@v4` tags.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: c19b2a18-6732-4ac4-a1ee-d17aff1504ca

📥 Commits

Reviewing files that changed from the base of the PR and between dd6e886 and 7b226d2.

📒 Files selected for processing (4)
  • .github/workflows/api-changes.yml
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json
✅ Files skipped from review due to trivial changes (3)
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml Outdated
snapi's baseline worktree checks out the PR's base branch but uses
HEAD's snapi config. When a watched package's build:declarations task
is added in the same PR that starts watching it, the baseline tree
doesn't yet have the task and the fallback build fails. Copy ui's
package.json and tsconfig.declarations.json from HEAD into the
worktree before installing, matching the existing pattern for
snapi.config.json.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 138-139: The workflow currently copies the entire
packages/ui/package.json into .worktrees/snapi-baseline/packages/ui/package.json
which imports PR-head manifest changes; instead update only the
scripts.build:declarations entry in the baseline package.json. In the
.github/workflows/api-changes.yml replace the two cp commands that reference
packages/ui/package.json and .worktrees/snapi-baseline/packages/ui/package.json
with a command that reads packages/ui/package.json, extracts the
"build:declarations" script, and patches
.worktrees/snapi-baseline/packages/ui/package.json to set
.scripts["build:declarations"] to that value (preserving all other fields).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: cc276cc0-8fbe-4284-9389-6221b9dcb1cb

📥 Commits

Reviewing files that changed from the base of the PR and between 7b226d2 and b54cb52.

📒 Files selected for processing (1)
  • .github/workflows/api-changes.yml

Comment thread.github/workflows/api-changes.yml Outdated
pnpm 10 mishandles `pnpm --dir <path> <non-builtin> ...`, treating the
path as the command to execute and erroring with
ERR_PNPM_RECURSIVE_EXEC_FIRST_FAIL. Switching the worktree-fallback
install/build/snapshot steps to GHA's `working-directory:` avoids the
flag entirely.
clerk/snapi is private, so pnpm dlx --package "github:clerk/snapi#..."
fails on Actions runners with no SSH key. Switch to the public
pkg.pr.new tarball URL pinned to the latest snapi PR build.
Also pin the worktree-fallback baseline to the immutable
pull_request.base.sha instead of origin/<base-branch>; if the base
branch advances during the run, this prevents drift between the
cached baseline lookup key and what the worktree actually checks out.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@alexcarpenter@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci(repo): dogfood snapi api checks by jacekradko · Pull Request #8621 · clerk/javascript · GitHub
Skip to content

ci(repo): dogfood snapi api checks - #8621

Merged
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi
May 27, 2026
Merged

ci(repo): dogfood snapi api checks#8621
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi

Conversation

@jacekradko

@jacekradkojacekradko commented May 21, 2026

Copy link
Copy Markdown
Contributor

Stands up snapi API-change detection for backend, clerk-js, nextjs, react, shared, and ui. On push to main and the release branches a publish-baseline job writes the snapshot to a sha-keyed GHA cache; PR runs restore from it, falling back to rebuilding from a worktree at pull_request.base.sha on a full miss. Snapi itself is pulled from pkg.pr.new because clerk/snapi is private.

continue-on-error: true on the job keeps the workflow non-blocking while we shake it out.

Here is an example PR with breaking changes in clerk/snapi: clerk/break-check#21

Here is a sample of a breaking-change report:

Screenshot 2026-05-23 at 11 09 41 AMScreenshot 2026-05-23 at 11 09 52 AMScreenshot 2026-05-23 at 11 10 02 AMScreenshot 2026-05-23 at 11 10 14 AM

@changeset-bot

changeset-botBot commented May 21, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: a182d1c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 21, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 27, 2026 3:44pm

Request Review

@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR adds SNAPI-based API change detection: a new snapi.config.json lists four packages to scan and snapshot settings; a GitHub Actions workflow (api-changes.yml) now runs on push and pull_request for main and release branches, adds a publish-baseline job for push that builds declarations and caches baseline snapshots, and reworks the check-api job for PRs to restore or build baseline snapshots, run snapi detect (failing on breaking changes), and upload api-changes-report.md. The UI package gains a declarations-only tsconfig and a build:declarations script. A changeset entry was updated.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'ci(repo): dogfood snapi api checks' clearly and concisely describes the main change—setting up the snapi API-checks workflow for testing purposes in the repository.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description clearly explains the purpose of the changes: setting up snapi API-change detection for multiple packages with a GitHub Actions workflow that uses caching and fallback mechanisms.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Line 67: The workflow generates current snapshots to ".api-snapshots-current"
but snapi.config.json uses snapshotDir ".api-snapshots", so update the pnpm dlx
snapi snapshot invocation or the snapi.detect invocation to use the same
directory: either change the snapshot command (the run line that calls "pnpm dlx
--package \"$SNAPI_PACKAGE\" snapi snapshot --output .api-snapshots-current") to
output to ".api-snapshots" or pass the explicit --current flag/--output value to
the "snapi detect" step so it points at ".api-snapshots-current", ensuring the
snapshot generation and detection commands reference the same directory.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 9f43cc8f-f375-42fc-a605-7463dfc82b40

📥 Commits

Reviewing files that changed from the base of the PR and between 2f003bc and 741ad85.

📒 Files selected for processing (3)
  • .changeset/dogfood-snapi.md
  • .github/workflows/api-changes.yml
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml Outdated
@pkg-pr-new

pkg-pr-newBot commented May 22, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8621

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8621

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8621

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8621

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8621

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8621

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8621

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8621

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8621

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8621

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8621

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8621

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8621

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8621

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8621

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8621

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8621

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8621

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8621

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8621

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8621

commit: a182d1c

Publish the API baseline to a GHA cache on push to main and the release
branches, keyed by commit sha. PR runs restore from that cache with a
prefix-match fallback, and only rebuild the baseline via worktree on a
full miss.
Add @clerk/ui to the watched package set with a tsc-based
build:declarations task matching @clerk/shared's pattern.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 124-127: The fallback fetch uses a moving ref
(origin/${GITHUB_BASE_REF}) which can drift; change the git fetch invocation(s)
that currently use GITHUB_BASE_REF to fetch the immutable PR base SHA
(github.event.pull_request.base.sha) instead so the fallback baseline matches
the PR base commit; update both occurrences of the fetch command in the workflow
to use the PR base SHA when populating refs/remotes/origin/${GITHUB_BASE_REF}.
- Around line 57-61: Update the workflow steps that use actions to pin their
versions to specific commit SHAs and disable persisted credentials: replace both
uses of actions/checkout@v4 (the "Checkout Repo" steps) with the corresponding
actions/checkout@<commit-sha> and add persist-credentials: false under their
with blocks; likewise replace actions/cache/save@v4 and actions/cache/restore@v4
with their pinned commit SHAs (actions/cache/save@<commit-sha>,
actions/cache/restore@<commit-sha>). Ensure you only change the version
specifiers and add the persist-credentials: false key to the checkout steps
while keeping existing keys like filter and show-progress intact.
- Around line 112-120: The baseline cache restore step (id baseline-cache using
actions/cache/restore@v4) must gate rebuilds on an exact cache hit, not partial
matches: change the rebuild condition to check
steps.baseline-cache.outputs.cache-hit != 'true' so any non-exact hit (including
partial matches) triggers the rebuild; when rebuilding, ensure the checkout used
to create the baseline worktree checks out the immutable PR base SHA (use ref:
${{ github.event.pull_request.base.sha }} or GITHUB event value) instead of
GITHUB_BASE_REF; set persist-credentials: false on both actions/checkout steps
to avoid leaking tokens; and pin external actions (actions/cache,
actions/checkout, etc.) to specific commit SHAs instead of floating `@v4` tags.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: c19b2a18-6732-4ac4-a1ee-d17aff1504ca

📥 Commits

Reviewing files that changed from the base of the PR and between dd6e886 and 7b226d2.

📒 Files selected for processing (4)
  • .github/workflows/api-changes.yml
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json
✅ Files skipped from review due to trivial changes (3)
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml Outdated
snapi's baseline worktree checks out the PR's base branch but uses
HEAD's snapi config. When a watched package's build:declarations task
is added in the same PR that starts watching it, the baseline tree
doesn't yet have the task and the fallback build fails. Copy ui's
package.json and tsconfig.declarations.json from HEAD into the
worktree before installing, matching the existing pattern for
snapi.config.json.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 138-139: The workflow currently copies the entire
packages/ui/package.json into .worktrees/snapi-baseline/packages/ui/package.json
which imports PR-head manifest changes; instead update only the
scripts.build:declarations entry in the baseline package.json. In the
.github/workflows/api-changes.yml replace the two cp commands that reference
packages/ui/package.json and .worktrees/snapi-baseline/packages/ui/package.json
with a command that reads packages/ui/package.json, extracts the
"build:declarations" script, and patches
.worktrees/snapi-baseline/packages/ui/package.json to set
.scripts["build:declarations"] to that value (preserving all other fields).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: cc276cc0-8fbe-4284-9389-6221b9dcb1cb

📥 Commits

Reviewing files that changed from the base of the PR and between 7b226d2 and b54cb52.

📒 Files selected for processing (1)
  • .github/workflows/api-changes.yml

Comment thread.github/workflows/api-changes.yml Outdated
pnpm 10 mishandles `pnpm --dir <path> <non-builtin> ...`, treating the
path as the command to execute and erroring with
ERR_PNPM_RECURSIVE_EXEC_FIRST_FAIL. Switching the worktree-fallback
install/build/snapshot steps to GHA's `working-directory:` avoids the
flag entirely.
clerk/snapi is private, so pnpm dlx --package "github:clerk/snapi#..."
fails on Actions runners with no SSH key. Switch to the public
pkg.pr.new tarball URL pinned to the latest snapi PR build.
Also pin the worktree-fallback baseline to the immutable
pull_request.base.sha instead of origin/<base-branch>; if the base
branch advances during the run, this prevents drift between the
cached baseline lookup key and what the worktree actually checks out.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@alexcarpenter@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci(repo): dogfood snapi api checks by jacekradko · Pull Request #8621 · clerk/javascript · GitHub
Skip to content

ci(repo): dogfood snapi api checks - #8621

Merged
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi
May 27, 2026
Merged

ci(repo): dogfood snapi api checks#8621
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi

Conversation

@jacekradko

@jacekradkojacekradko commented May 21, 2026

Copy link
Copy Markdown
Contributor

Stands up snapi API-change detection for backend, clerk-js, nextjs, react, shared, and ui. On push to main and the release branches a publish-baseline job writes the snapshot to a sha-keyed GHA cache; PR runs restore from it, falling back to rebuilding from a worktree at pull_request.base.sha on a full miss. Snapi itself is pulled from pkg.pr.new because clerk/snapi is private.

continue-on-error: true on the job keeps the workflow non-blocking while we shake it out.

Here is an example PR with breaking changes in clerk/snapi: clerk/break-check#21

Here is a sample of a breaking-change report:

Screenshot 2026-05-23 at 11 09 41 AMScreenshot 2026-05-23 at 11 09 52 AMScreenshot 2026-05-23 at 11 10 02 AMScreenshot 2026-05-23 at 11 10 14 AM

@changeset-bot

changeset-botBot commented May 21, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: a182d1c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 21, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 27, 2026 3:44pm

Request Review

@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR adds SNAPI-based API change detection: a new snapi.config.json lists four packages to scan and snapshot settings; a GitHub Actions workflow (api-changes.yml) now runs on push and pull_request for main and release branches, adds a publish-baseline job for push that builds declarations and caches baseline snapshots, and reworks the check-api job for PRs to restore or build baseline snapshots, run snapi detect (failing on breaking changes), and upload api-changes-report.md. The UI package gains a declarations-only tsconfig and a build:declarations script. A changeset entry was updated.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'ci(repo): dogfood snapi api checks' clearly and concisely describes the main change—setting up the snapi API-checks workflow for testing purposes in the repository.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description clearly explains the purpose of the changes: setting up snapi API-change detection for multiple packages with a GitHub Actions workflow that uses caching and fallback mechanisms.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Line 67: The workflow generates current snapshots to ".api-snapshots-current"
but snapi.config.json uses snapshotDir ".api-snapshots", so update the pnpm dlx
snapi snapshot invocation or the snapi.detect invocation to use the same
directory: either change the snapshot command (the run line that calls "pnpm dlx
--package \"$SNAPI_PACKAGE\" snapi snapshot --output .api-snapshots-current") to
output to ".api-snapshots" or pass the explicit --current flag/--output value to
the "snapi detect" step so it points at ".api-snapshots-current", ensuring the
snapshot generation and detection commands reference the same directory.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 9f43cc8f-f375-42fc-a605-7463dfc82b40

📥 Commits

Reviewing files that changed from the base of the PR and between 2f003bc and 741ad85.

📒 Files selected for processing (3)
  • .changeset/dogfood-snapi.md
  • .github/workflows/api-changes.yml
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml Outdated
@pkg-pr-new

pkg-pr-newBot commented May 22, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8621

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8621

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8621

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8621

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8621

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8621

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8621

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8621

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8621

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8621

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8621

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8621

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8621

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8621

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8621

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8621

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8621

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8621

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8621

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8621

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8621

commit: a182d1c

Publish the API baseline to a GHA cache on push to main and the release
branches, keyed by commit sha. PR runs restore from that cache with a
prefix-match fallback, and only rebuild the baseline via worktree on a
full miss.
Add @clerk/ui to the watched package set with a tsc-based
build:declarations task matching @clerk/shared's pattern.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 124-127: The fallback fetch uses a moving ref
(origin/${GITHUB_BASE_REF}) which can drift; change the git fetch invocation(s)
that currently use GITHUB_BASE_REF to fetch the immutable PR base SHA
(github.event.pull_request.base.sha) instead so the fallback baseline matches
the PR base commit; update both occurrences of the fetch command in the workflow
to use the PR base SHA when populating refs/remotes/origin/${GITHUB_BASE_REF}.
- Around line 57-61: Update the workflow steps that use actions to pin their
versions to specific commit SHAs and disable persisted credentials: replace both
uses of actions/checkout@v4 (the "Checkout Repo" steps) with the corresponding
actions/checkout@<commit-sha> and add persist-credentials: false under their
with blocks; likewise replace actions/cache/save@v4 and actions/cache/restore@v4
with their pinned commit SHAs (actions/cache/save@<commit-sha>,
actions/cache/restore@<commit-sha>). Ensure you only change the version
specifiers and add the persist-credentials: false key to the checkout steps
while keeping existing keys like filter and show-progress intact.
- Around line 112-120: The baseline cache restore step (id baseline-cache using
actions/cache/restore@v4) must gate rebuilds on an exact cache hit, not partial
matches: change the rebuild condition to check
steps.baseline-cache.outputs.cache-hit != 'true' so any non-exact hit (including
partial matches) triggers the rebuild; when rebuilding, ensure the checkout used
to create the baseline worktree checks out the immutable PR base SHA (use ref:
${{ github.event.pull_request.base.sha }} or GITHUB event value) instead of
GITHUB_BASE_REF; set persist-credentials: false on both actions/checkout steps
to avoid leaking tokens; and pin external actions (actions/cache,
actions/checkout, etc.) to specific commit SHAs instead of floating `@v4` tags.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: c19b2a18-6732-4ac4-a1ee-d17aff1504ca

📥 Commits

Reviewing files that changed from the base of the PR and between dd6e886 and 7b226d2.

📒 Files selected for processing (4)
  • .github/workflows/api-changes.yml
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json
✅ Files skipped from review due to trivial changes (3)
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml Outdated
snapi's baseline worktree checks out the PR's base branch but uses
HEAD's snapi config. When a watched package's build:declarations task
is added in the same PR that starts watching it, the baseline tree
doesn't yet have the task and the fallback build fails. Copy ui's
package.json and tsconfig.declarations.json from HEAD into the
worktree before installing, matching the existing pattern for
snapi.config.json.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 138-139: The workflow currently copies the entire
packages/ui/package.json into .worktrees/snapi-baseline/packages/ui/package.json
which imports PR-head manifest changes; instead update only the
scripts.build:declarations entry in the baseline package.json. In the
.github/workflows/api-changes.yml replace the two cp commands that reference
packages/ui/package.json and .worktrees/snapi-baseline/packages/ui/package.json
with a command that reads packages/ui/package.json, extracts the
"build:declarations" script, and patches
.worktrees/snapi-baseline/packages/ui/package.json to set
.scripts["build:declarations"] to that value (preserving all other fields).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: cc276cc0-8fbe-4284-9389-6221b9dcb1cb

📥 Commits

Reviewing files that changed from the base of the PR and between 7b226d2 and b54cb52.

📒 Files selected for processing (1)
  • .github/workflows/api-changes.yml

Comment thread.github/workflows/api-changes.yml Outdated
pnpm 10 mishandles `pnpm --dir <path> <non-builtin> ...`, treating the
path as the command to execute and erroring with
ERR_PNPM_RECURSIVE_EXEC_FIRST_FAIL. Switching the worktree-fallback
install/build/snapshot steps to GHA's `working-directory:` avoids the
flag entirely.
clerk/snapi is private, so pnpm dlx --package "github:clerk/snapi#..."
fails on Actions runners with no SSH key. Switch to the public
pkg.pr.new tarball URL pinned to the latest snapi PR build.
Also pin the worktree-fallback baseline to the immutable
pull_request.base.sha instead of origin/<base-branch>; if the base
branch advances during the run, this prevents drift between the
cached baseline lookup key and what the worktree actually checks out.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@alexcarpenter@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); ci(repo): dogfood snapi api checks by jacekradko · Pull Request #8621 · clerk/javascript · GitHub
Skip to content

ci(repo): dogfood snapi api checks - #8621

Merged
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi
May 27, 2026
Merged

ci(repo): dogfood snapi api checks#8621
jacekradko merged 18 commits into
mainfrom
jacek/dogfood-snapi

Conversation

@jacekradko

@jacekradkojacekradko commented May 21, 2026

Copy link
Copy Markdown
Contributor

Stands up snapi API-change detection for backend, clerk-js, nextjs, react, shared, and ui. On push to main and the release branches a publish-baseline job writes the snapshot to a sha-keyed GHA cache; PR runs restore from it, falling back to rebuilding from a worktree at pull_request.base.sha on a full miss. Snapi itself is pulled from pkg.pr.new because clerk/snapi is private.

continue-on-error: true on the job keeps the workflow non-blocking while we shake it out.

Here is an example PR with breaking changes in clerk/snapi: clerk/break-check#21

Here is a sample of a breaking-change report:

Screenshot 2026-05-23 at 11 09 41 AMScreenshot 2026-05-23 at 11 09 52 AMScreenshot 2026-05-23 at 11 10 02 AMScreenshot 2026-05-23 at 11 10 14 AM

@changeset-bot

changeset-botBot commented May 21, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: a182d1c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented May 21, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentMay 27, 2026 3:44pm

Request Review

@coderabbitai

coderabbitaiBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR adds SNAPI-based API change detection: a new snapi.config.json lists four packages to scan and snapshot settings; a GitHub Actions workflow (api-changes.yml) now runs on push and pull_request for main and release branches, adds a publish-baseline job for push that builds declarations and caches baseline snapshots, and reworks the check-api job for PRs to restore or build baseline snapshots, run snapi detect (failing on breaking changes), and upload api-changes-report.md. The UI package gains a declarations-only tsconfig and a build:declarations script. A changeset entry was updated.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'ci(repo): dogfood snapi api checks' clearly and concisely describes the main change—setting up the snapi API-checks workflow for testing purposes in the repository.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Description check✅ PassedThe pull request description clearly explains the purpose of the changes: setting up snapi API-change detection for multiple packages with a GitHub Actions workflow that uses caching and fallback mechanisms.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Line 67: The workflow generates current snapshots to ".api-snapshots-current"
but snapi.config.json uses snapshotDir ".api-snapshots", so update the pnpm dlx
snapi snapshot invocation or the snapi.detect invocation to use the same
directory: either change the snapshot command (the run line that calls "pnpm dlx
--package \"$SNAPI_PACKAGE\" snapi snapshot --output .api-snapshots-current") to
output to ".api-snapshots" or pass the explicit --current flag/--output value to
the "snapi detect" step so it points at ".api-snapshots-current", ensuring the
snapshot generation and detection commands reference the same directory.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 9f43cc8f-f375-42fc-a605-7463dfc82b40

📥 Commits

Reviewing files that changed from the base of the PR and between 2f003bc and 741ad85.

📒 Files selected for processing (3)
  • .changeset/dogfood-snapi.md
  • .github/workflows/api-changes.yml
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml Outdated
@pkg-pr-new

pkg-pr-newBot commented May 22, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8621

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8621

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8621

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8621

@clerk/dev-cli

npm i https://pkg.pr.new/@clerk/dev-cli@8621

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8621

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8621

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8621

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8621

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8621

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8621

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8621

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8621

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8621

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8621

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8621

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8621

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8621

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8621

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8621

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8621

commit: a182d1c

Publish the API baseline to a GHA cache on push to main and the release
branches, keyed by commit sha. PR runs restore from that cache with a
prefix-match fallback, and only rebuild the baseline via worktree on a
full miss.
Add @clerk/ui to the watched package set with a tsc-based
build:declarations task matching @clerk/shared's pattern.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 124-127: The fallback fetch uses a moving ref
(origin/${GITHUB_BASE_REF}) which can drift; change the git fetch invocation(s)
that currently use GITHUB_BASE_REF to fetch the immutable PR base SHA
(github.event.pull_request.base.sha) instead so the fallback baseline matches
the PR base commit; update both occurrences of the fetch command in the workflow
to use the PR base SHA when populating refs/remotes/origin/${GITHUB_BASE_REF}.
- Around line 57-61: Update the workflow steps that use actions to pin their
versions to specific commit SHAs and disable persisted credentials: replace both
uses of actions/checkout@v4 (the "Checkout Repo" steps) with the corresponding
actions/checkout@<commit-sha> and add persist-credentials: false under their
with blocks; likewise replace actions/cache/save@v4 and actions/cache/restore@v4
with their pinned commit SHAs (actions/cache/save@<commit-sha>,
actions/cache/restore@<commit-sha>). Ensure you only change the version
specifiers and add the persist-credentials: false key to the checkout steps
while keeping existing keys like filter and show-progress intact.
- Around line 112-120: The baseline cache restore step (id baseline-cache using
actions/cache/restore@v4) must gate rebuilds on an exact cache hit, not partial
matches: change the rebuild condition to check
steps.baseline-cache.outputs.cache-hit != 'true' so any non-exact hit (including
partial matches) triggers the rebuild; when rebuilding, ensure the checkout used
to create the baseline worktree checks out the immutable PR base SHA (use ref:
${{ github.event.pull_request.base.sha }} or GITHUB event value) instead of
GITHUB_BASE_REF; set persist-credentials: false on both actions/checkout steps
to avoid leaking tokens; and pin external actions (actions/cache,
actions/checkout, etc.) to specific commit SHAs instead of floating `@v4` tags.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: c19b2a18-6732-4ac4-a1ee-d17aff1504ca

📥 Commits

Reviewing files that changed from the base of the PR and between dd6e886 and 7b226d2.

📒 Files selected for processing (4)
  • .github/workflows/api-changes.yml
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json
✅ Files skipped from review due to trivial changes (3)
  • packages/ui/package.json
  • packages/ui/tsconfig.declarations.json
  • snapi.config.json

Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml
Comment thread.github/workflows/api-changes.yml Outdated
snapi's baseline worktree checks out the PR's base branch but uses
HEAD's snapi config. When a watched package's build:declarations task
is added in the same PR that starts watching it, the baseline tree
doesn't yet have the task and the fallback build fails. Copy ui's
package.json and tsconfig.declarations.json from HEAD into the
worktree before installing, matching the existing pattern for
snapi.config.json.

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/api-changes.yml:
- Around line 138-139: The workflow currently copies the entire
packages/ui/package.json into .worktrees/snapi-baseline/packages/ui/package.json
which imports PR-head manifest changes; instead update only the
scripts.build:declarations entry in the baseline package.json. In the
.github/workflows/api-changes.yml replace the two cp commands that reference
packages/ui/package.json and .worktrees/snapi-baseline/packages/ui/package.json
with a command that reads packages/ui/package.json, extracts the
"build:declarations" script, and patches
.worktrees/snapi-baseline/packages/ui/package.json to set
.scripts["build:declarations"] to that value (preserving all other fields).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: cc276cc0-8fbe-4284-9389-6221b9dcb1cb

📥 Commits

Reviewing files that changed from the base of the PR and between 7b226d2 and b54cb52.

📒 Files selected for processing (1)
  • .github/workflows/api-changes.yml

Comment thread.github/workflows/api-changes.yml Outdated
pnpm 10 mishandles `pnpm --dir <path> <non-builtin> ...`, treating the
path as the command to execute and erroring with
ERR_PNPM_RECURSIVE_EXEC_FIRST_FAIL. Switching the worktree-fallback
install/build/snapshot steps to GHA's `working-directory:` avoids the
flag entirely.
clerk/snapi is private, so pnpm dlx --package "github:clerk/snapi#..."
fails on Actions runners with no SSH key. Switch to the public
pkg.pr.new tarball URL pinned to the latest snapi PR build.
Also pin the worktree-fallback baseline to the immutable
pull_request.base.sha instead of origin/<base-branch>; if the base
branch advances during the run, this prevents drift between the
cached baseline lookup key and what the worktree actually checks out.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@jacekradko@alexcarpenter@wobsoriano