Skip to content

ci: scan every main push and use shallow verify checkouts - #97

Merged
altaywtf merged 2 commits into
mainfrom
ci/scan-every-push
Oct 5, 2026
Merged

altaywtf merged 2 commits into
mainfrom
ci/scan-every-push

Conversation

@altaywtf

@altaywtf altaywtf commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Summary

Every main push now finishes its CI run, so the secret and workflow scan covers each pushed range, and verification checks out one commit instead of full history.

Before After
Push and dispatch runs one CI-refs/heads/main group; a third push cancels the pending second run, whose range is never scanned one group per run; every pushed range is scanned
Pull request runs superseded runs cancelled unchanged
verify checkout full history default depth

Verification

The scan passes through on pull requests; actionlint 1.7.12 and zizmor 1.29.0 report nothing on this branch locally, and the first main run after merge audits the change.

Notes

  • Releases stay serialized by the shared release workflow's own release-<repo>-main group, which keeps full history for semantic-release. That group holds one pending release, so if three pushes land within one release and the older verify finishes last, semantic-release skips the stale commit and the newer commits publish on the next push.
  • The scan deepens its own clone to the pushed range, or to full history on dispatch.
  • Merging runs verify and the release job on main; a ci: commit publishes nothing.

Written by an agent (Claude Code, Claude Opus 5.5)

Push and dispatch runs get their own concurrency group, so a third push no longer cancels a pending run whose range was never scanned. Pull request runs still cancel superseded ones. Verify jobs keep the default checkout depth; the scan deepens its own clone and the release workflow keeps full history.
Copilot AI balanced review requested due to automatic review settings October 5, 2026 07:12
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The concurrency behavior change leaves docs/DISTRIBUTION.md describing the old "main runs queue" mechanism, which the repo's contract-change guidance requires updating.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

This PR tunes the CI GitHub Actions workflow so that every main push run completes rather than cancelling queued runs, which guarantees the secret/workflow scan covers each pushed commit range. It also drops fetch-depth: 0 from the verify checkout, relying on the shared scan action to deepen the clone only when needed. This fits the repo's delivery model where each main merge must be verified, scanned, and potentially published.

Changes:

  • Concurrency group now uses github.ref only for pull requests and github.run_id otherwise, so push/dispatch runs get a unique group and never cancel each other (PR cancel-in-progress behavior is unchanged).
  • Removes fetch-depth: 0 from the verify job checkout, letting the scan action self-deepen/unshallow to the pushed range (or full history on dispatch).
File Description
.github/​workflows/​ci.yml Per-run concurrency group for push/dispatch and a shallow default checkout for verify, keeping every pushed range scanned.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/ci.yml
@altaywtf
altaywtf merged commit 2dd96f7 into main Oct 5, 2026
2 checks passed
@altaywtf
altaywtf deleted the ci/scan-every-push branch October 5, 2026 07:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants