Repository navigation
ci: scan every main push and use shallow verify checkouts - #97
Conversation
Push and dispatch runs get their own concurrency group, so a third push no longer cancels a pending run whose range was never scanned. Pull request runs still cancel superseded ones. Verify jobs keep the default checkout depth; the scan deepens its own clone and the release workflow keeps full history.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The concurrency behavior change leaves docs/DISTRIBUTION.md describing the old "main runs queue" mechanism, which the repo's contract-change guidance requires updating.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
This PR tunes the CI GitHub Actions workflow so that every main push run completes rather than cancelling queued runs, which guarantees the secret/workflow scan covers each pushed commit range. It also drops fetch-depth: 0 from the verify checkout, relying on the shared scan action to deepen the clone only when needed. This fits the repo's delivery model where each main merge must be verified, scanned, and potentially published.
Changes:
- Concurrency group now uses
github.refonly for pull requests andgithub.run_idotherwise, so push/dispatch runs get a unique group and never cancel each other (PR cancel-in-progress behavior is unchanged). - Removes
fetch-depth: 0from theverifyjob checkout, letting the scan action self-deepen/unshallow to the pushed range (or full history on dispatch).
| File | Description |
|---|---|
.github/workflows/ci.yml |
Per-run concurrency group for push/dispatch and a shallow default checkout for verify, keeping every pushed range scanned. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Summary
Every
mainpush now finishes its CI run, so the secret and workflow scan covers each pushed range, and verification checks out one commit instead of full history.CI-refs/heads/maingroup; a third push cancels the pending second run, whose range is never scannedverifycheckoutVerification
The scan passes through on pull requests;
actionlint1.7.12 andzizmor1.29.0 report nothing on this branch locally, and the firstmainrun after merge audits the change.Notes
release-<repo>-maingroup, which keeps full history for semantic-release. That group holds one pending release, so if three pushes land within one release and the older verify finishes last, semantic-release skips the stale commit and the newer commits publish on the next push.verifyand the release job onmain; aci:commit publishes nothing.Written by an agent (Claude Code, Claude Opus 5.5)