Skip to content

ci: scan every pushed range - #206

Merged
altaywtf merged 1 commit into
mainfrom
ci/scan-every-push
Oct 5, 2026
Merged

altaywtf merged 1 commit into
mainfrom
ci/scan-every-push

Conversation

@altaywtf

@altaywtf altaywtf commented Oct 5, 2026

Copy link
Copy Markdown
Member

Summary

A push to main no longer cancels the pending run of the push before it, so every pushed range reaches the scan.

Event Concurrency group Superseded run
pull request per PR cancelled
push, dispatch per run finishes
release (shared npm workflow) release-<repo>-main waits, unchanged

verify and compatibility now check out one commit. Nothing they run reads history, and the scan deepens its own checkout to the pushed range. The release job keeps full history.

Verification

  • vp run verify
  • Actionlint 1.7.12 and Zizmor 1.29.0 are clean.

Notes

  • A ci: commit publishes nothing.

Written by an agent (Claude Code, Claude Opus 5.5)

Push and dispatch runs get their own concurrency group, so a third push no longer replaces the pending second run before its range is scanned. Verify and compatibility check out one commit; nothing they run reads history.
Copilot AI balanced review requested due to automatic review settings October 5, 2026 07:16
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Changes to CI concurrency and release-adjacent checkout behavior carry operational risk and warrant final human review even though the logic verified as correct.

Review effort: Balanced
Findings: None

What changed in this PR

This PR adjusts the CI workflow so that pushes to main are never superseded/cancelled by a later push, ensuring every pushed commit range reaches the push-time secret/workflow scan. It changes the concurrency keying and removes the full-history checkout from the verify and compatibility jobs, relying on the shared scan action to deepen its own checkout only when needed.

Changes:

  • Concurrency now keys pull requests by github.ref (cancellable) and pushes/dispatches by github.run_id (unique group, never superseded), with cancel-in-progress limited to pull requests.
  • Removed fetch-depth: 0 from the verify and compatibility checkouts so they fetch a single commit; the scan action deepens to the pushed range (or unshallows) itself.
  • Added an explanatory comment documenting the concurrency strategy.
File Description
.github/​workflows/​ci.yml Re-keys concurrency so pushes get a per-run group that is never cancelled, and drops full-history checkouts from verify/compatibility, leaving range deepening to the scan action.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@altaywtf
altaywtf merged commit e563a2d into main Oct 5, 2026
9 checks passed
@altaywtf
altaywtf deleted the ci/scan-every-push branch October 5, 2026 07:28
@putio-ci

putio-ci Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 13.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@putio-ci putio-ci Bot added the released label Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants