Skip to content

ci: scan every pushed range - #90

Merged
altaywtf merged 1 commit into
mainfrom
ci/scan-every-push
Oct 5, 2026
Merged

altaywtf merged 1 commit into
mainfrom
ci/scan-every-push

Conversation

@altaywtf

@altaywtf altaywtf commented Oct 5, 2026

Copy link
Copy Markdown
Member

A push to main no longer cancels the pending Release run of the push before it, so every pushed range reaches CI's scan. Releases and deploys still run one at a time.

Workflow Group Pending runs Running run
CI, pull request per PR newest replaces older cancelled by a newer push
CI, dispatch or called by Release per run none finishes
Release, push or dispatch roku-release-<ref>, unchanged queued, up to 100 finishes
  • .github/actionlint.yaml ignores only the queue key in release.yml, which Actionlint 1.7.12 predates.
  • The README badge now follows Release, which runs on every push to main. CI runs on main only on dispatch, so its badge last moved in August.
  • A ci: commit releases and deploys nothing.

Written by an agent (Claude Code, Claude Opus 5.5)

CI runs get their own concurrency group outside pull requests, and Release queues pending pushes instead of replacing them, so every pushed range reaches the scan while releases and deploys stay serialized. The README badge follows Release, which runs on every push to main.
Copilot AI balanced review requested due to automatic review settings October 5, 2026 07:18
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It alters release/deploy pipeline concurrency semantics relying on a recently introduced platform feature (queue: max), which has real operational impact and warrants human verification.

Review effort: Balanced
Findings: None

What changed in this PR

This PR adjusts the CI/CD concurrency model so that every pushed range to main reaches CI's scan step, rather than having an in-flight Release run cancel the pending run of the push before it. It leverages GitHub Actions' queue: max concurrency setting (which allows up to 100 pending runs in a group instead of the default behavior of replacing the pending run) on the Release workflow, while giving non-PR CI runs their own per-run concurrency group so queued runs are never replaced. Releases and deploys still execute one at a time.

Changes:

  • Add queue: max to release.yml concurrency so pending main pushes queue (up to 100) instead of being superseded, with an explanatory comment.
  • Change ci.yml concurrency group to key non-pull_request events by github.run_id (unique per run) while PR events keep github.ref + cancel-in-progress.
  • Add .github/actionlint.yaml to suppress the "unexpected key queue" warning from Actionlint 1.7.12, and repoint the README status badge from CI to Release (since Release runs on every main push).
File Description
.github/​workflows/​release.yml Adds queue: max (with cancel-in-progress: false) so every pending main push is queued rather than replaced.
.github/​workflows/​ci.yml Makes non-PR runs use a per-run (run_id) concurrency group so queued runs are never cancelled; PR runs keep ref-based cancellation.
.github/​actionlint.yaml New config that ignores the queue concurrency-key warning only for release.yml, scoped and justified by Actionlint version.
README.md Status badge now tracks release.yml on main instead of ci.yml.

I verified the key correctness concern: queue: max is a valid concurrency key (added to GitHub Actions around May 2026) and is only incompatible with cancel-in-progress: true — here it is paired with cancel-in-progress: false, which is valid. The .github/actionlint.yaml file parses as valid YAML and matches Actionlint's paths/ignore schema, with the ignore scoped to release.yml and specific enough not to mask unrelated errors. The ci.yml group expression resolves to unique per-run groups for workflow_call/workflow_dispatch and ref-based groups for pull requests, consistent with the stated intent. I found no defects to flag.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@altaywtf
altaywtf merged commit 6090814 into main Oct 5, 2026
2 checks passed
@altaywtf
altaywtf deleted the ci/scan-every-push branch October 5, 2026 07:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants