Repository navigation
ci: scan every main push and use shallow verify checkouts - #94
Conversation
Push and dispatch runs get their own concurrency group, so a third push no longer cancels a pending run whose range was never scanned. Pull request runs still cancel superseded ones. Verify jobs keep the default checkout depth; the scan deepens its own clone and the release workflow keeps full history.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It alters CI concurrency grouping whose correctness depends on the release pipeline's serialization behavior, and publishing mistakes are irreversible, so a human should confirm before approval.
Review effort: Balanced
Findings: None
What changed in this PR
This PR adjusts the CI workflow so that every push to main completes its own run, ensuring the secret/workflow scan audits each pushed commit range, and so the verify job uses a shallow checkout instead of fetching full history.
Previously, push/dispatch runs shared a single ${{ github.workflow }}-${{ github.ref }} concurrency group; because queued runs are superseded, a rapid third push could cancel a pending second run and leave that commit range unscanned. The new expression keeps ref-based grouping (and cancellation) only for pull requests and switches push/dispatch to the unique github.run_id, so each push runs independently and is fully scanned. Removing fetch-depth: 0 is safe because the shared scan action deepens its own clone to the pushed range (or unshallows on dispatch), vp run verify needs no git history, and the separate reusable release workflow keeps its own fetch-depth: 0 plus a release-<repo>-main concurrency group that serializes releases.
Changes:
- Group push/dispatch CI runs by
github.run_id(unique per run) while keeping PR runs grouped by ref, so every pushed range is scanned rather than superseded. - Drop
fetch-depth: 0from theverifyjob checkout, relying on a default shallow clone.
| File | Description |
|---|---|
.github/workflows/ci.yml |
Event-aware concurrency group so main pushes aren't cancelled, and a shallow checkout for the verify job. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Summary
Every
mainpush now finishes its CI run, so the secret and workflow scan covers each pushed range, and verification checks out one commit instead of full history.CI-refs/heads/maingroup; a third push cancels the pending second run, whose range is never scannedverifycheckoutRisks
release-<repo>-maingroup, which keeps full history for semantic-release. That group holds one pending release, so if three pushes land within one release and the older verify finishes last, semantic-release skips the stale commit and the newer commits publish on the next push.Verification
actionlint1.7.12 andzizmor1.29.0 report nothing on this branch locally, and the firstmainrun after merge audits the change.verifyand the release job onmain; aci:commit publishes nothing.Follow-Ups
None.
Written by an agent (Claude Code, Claude Opus 5.5)