Skip to content

feat(sdk-events): add @dotcms/events for pageviews, content events and experiments #3268

feat(sdk-events): add @dotcms/events for pageviews, content events and experiments

feat(sdk-events): add @dotcms/events for pageviews, content events and experiments #3268

name: Claude AI SDK Breaking Change Check
on:
pull_request:
types: [opened, synchronize]
# Reviewing a commit that has already been superseded helps nobody, and the run
# holds a runner slot the rest of the pipeline is queueing for.
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
jobs:
# Security gate: Check if user is dotCMS organization member
#
# REQUIREMENTS FOR CLAUDE ACCESS:
# 1. Must be a member of the dotCMS organization
# 2. Membership must be set to PUBLIC visibility
#
# TROUBLESHOOTING: If blocked, visit https://github.com/orgs/dotCMS/people
# and ensure your membership is public (click "Make public" if needed)
security-check:
runs-on: ubuntu-latest
permissions:
contents: read # Allow repository checkout
# Note: Organization membership checking uses fine-grained token
# so no additional GITHUB_TOKEN permissions needed for that API
outputs:
authorized: ${{ steps.membership-check.outputs.is_member }}
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Check organization membership
id: membership-check
uses: ./.github/actions/security/org-membership-check
with:
username: ${{ github.event.pull_request.user.login || github.actor }}
- name: Log security decision
run: |
if [ "${{ steps.membership-check.outputs.is_member }}" = "true" ]; then
echo "✅ Access granted: User is a dotCMS organization member"
else
echo "❌ Access denied: User failed dotCMS organization membership check"
echo ""
echo "📋 TROUBLESHOOTING: If you are a dotCMS team member:"
echo " 1. Visit https://github.com/orgs/dotCMS/people"
echo " 2. Ensure your membership is set to 'Public'"
echo " 3. If you're not listed, contact an organization owner"
echo ""
echo "::warning::Unauthorized user attempted to trigger Claude workflow: ${{ github.event.pull_request.user.login || github.actor }}"
fi
# SDK breaking-change analysis — runs on every PR push. Single label design: the AI only
# ever ADDS "SDK Breaking Change" when it detects a break; it never removes it. Removing
# the label (because a human disagrees with the AI's call, or because a later push fixed
# the issue) is always a manual human action — no separate "Human: ..." label needed, and
# no preflight step to clear/protect anything: a human's removal simply stands until the
# AI sees reason to re-add it on some future push.
claude-sdk-breaking-change-check:
needs: security-check
# Cancel in-progress check when a new push arrives — always analyze latest state
concurrency:
group: claude-sdk-breaking-${{ github.event.pull_request.number }}
cancel-in-progress: true
if: needs.security-check.outputs.authorized == 'true'
permissions:
contents: write
id-token: write
pull-requests: write
issues: write
uses: dotCMS/ai-workflows/.github/workflows/claude-orchestrator.yml@v3
with:
model_id: ${{ vars.BEDROCK_MODEL_ID }}
bedrock_role_arn: ${{ vars.BEDROCK_ROLE_ARN }}
trigger_mode: automatic
prompt: |
You are a dotCMS SDK-compatibility analyst. Determine whether the changes in this PR
break compatibility for `@dotcms/*` SDK consumers (`@dotcms/client`, `@dotcms/react`,
`@dotcms/angular`, `@dotcms/uve`) — i.e. whether an SDK version built against the
server contract *before* this change would misbehave against the server *after* this
change.
STEP 1 — Read the SDK breaking-change categories reference:
cat docs/core/SDK_BREAKING_CHANGE_CATEGORIES.md
STEP 2 — Get the full PR diff:
git diff ${{ github.event.pull_request.base.sha }}...${{ github.event.pull_request.head.sha }}
STEP 3 — Analyze the diff against EVERY category in the reference document.
Focus on: GraphQL schema surface reachable via the page API's graphql.page /
graphql.content extension (new required fields/args, removed/renamed types or
fields), REST response shape changes to /api/v1/page/*, /api/v1/content, and
/api/v1/nav, changes to the UVE/editor postMessage protocol (message names or
payload shapes in DotCMSUVEAction / __DOTCMS_UVE_EVENT__), and changes to the
SdkVersionWebInterceptor / X-DotCMS-Version / X-DotCMS-Min-SDK headers or the
compareVersions() comparison contract in sdk-compatibility.ts. Ignore pure admin-UI
(dotcms-ui) changes, test-only changes, or documentation changes unless they touch
one of the above surfaces.
STEP 4 — If the changes break SDK compatibility, post this comment on the PR
using: gh pr comment ${{ github.event.pull_request.number }} --body "..."
Format:
SDK Breaking Change Detected!!!
- Category: <category ID and name, e.g. "G-1 — Removing or Renaming a Reachable GraphQL Type/Field">
- Why it breaks compatibility: <specific explanation tied to the actual code changed>
- Code that makes it breaking: <file path(s) and the specific lines or block>
- Safer alternative (if possible): <the safer alternative from the reference, adapted to this change>
If multiple categories match, repeat the block for each one.
Then add the label (only if it isn't already on the PR):
gh pr edit ${{ github.event.pull_request.number }} --add-label "SDK Breaking Change"
If the changes do NOT break SDK compatibility, do nothing — no comment, no label, and
do NOT remove an existing "SDK Breaking Change" label even if you disagree with it.
Removing that label is a human-only decision.
Be specific: quote actual file names and code lines, not generic descriptions.
claude_args: '--allowedTools "Bash(git diff*),Bash(git log*),Bash(cat docs/core/SDK_BREAKING_CHANGE_CATEGORIES.md),Bash(gh pr comment*),Bash(gh pr edit*)"'
timeout_minutes: 15
runner: ubuntu-latest
enable_mention_detection: false