Repository navigation
ci: scan every pushed range - #206
Conversation
Push and dispatch runs get their own concurrency group, so a third push no longer replaces the pending second run before its range is scanned. Verify and compatibility check out one commit; nothing they run reads history.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Changes to CI concurrency and release-adjacent checkout behavior carry operational risk and warrant final human review even though the logic verified as correct.
Review effort: Balanced
Findings: None
What changed in this PR
This PR adjusts the CI workflow so that pushes to main are never superseded/cancelled by a later push, ensuring every pushed commit range reaches the push-time secret/workflow scan. It changes the concurrency keying and removes the full-history checkout from the verify and compatibility jobs, relying on the shared scan action to deepen its own checkout only when needed.
Changes:
- Concurrency now keys pull requests by
github.ref(cancellable) and pushes/dispatches bygithub.run_id(unique group, never superseded), withcancel-in-progresslimited to pull requests. - Removed
fetch-depth: 0from theverifyandcompatibilitycheckouts so they fetch a single commit; thescanaction deepens to the pushed range (or unshallows) itself. - Added an explanatory comment documenting the concurrency strategy.
| File | Description |
|---|---|
.github/workflows/ci.yml |
Re-keys concurrency so pushes get a per-run group that is never cancelled, and drops full-history checkouts from verify/compatibility, leaving range deepening to the scan action. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
🎉 This PR is included in version 13.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Summary
A push to
mainno longer cancels the pending run of the push before it, so every pushed range reaches the scan.release-<repo>-mainverifyandcompatibilitynow check out one commit. Nothing they run reads history, and the scan deepens its own checkout to the pushed range. The release job keeps full history.Verification
vp run verifyNotes
ci:commit publishes nothing.Written by an agent (Claude Code, Claude Opus 5.5)