Repository navigation
ci: scan every pushed range - #90
Conversation
CI runs get their own concurrency group outside pull requests, and Release queues pending pushes instead of replacing them, so every pushed range reaches the scan while releases and deploys stay serialized. The README badge follows Release, which runs on every push to main.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It alters release/deploy pipeline concurrency semantics relying on a recently introduced platform feature (queue: max), which has real operational impact and warrants human verification.
Review effort: Balanced
Findings: None
What changed in this PR
This PR adjusts the CI/CD concurrency model so that every pushed range to main reaches CI's scan step, rather than having an in-flight Release run cancel the pending run of the push before it. It leverages GitHub Actions' queue: max concurrency setting (which allows up to 100 pending runs in a group instead of the default behavior of replacing the pending run) on the Release workflow, while giving non-PR CI runs their own per-run concurrency group so queued runs are never replaced. Releases and deploys still execute one at a time.
Changes:
- Add
queue: maxtorelease.ymlconcurrency so pending main pushes queue (up to 100) instead of being superseded, with an explanatory comment. - Change
ci.ymlconcurrency group to key non-pull_requestevents bygithub.run_id(unique per run) while PR events keepgithub.ref+cancel-in-progress. - Add
.github/actionlint.yamlto suppress the "unexpected keyqueue" warning from Actionlint 1.7.12, and repoint the README status badge from CI to Release (since Release runs on every main push).
| File | Description |
|---|---|
.github/workflows/release.yml |
Adds queue: max (with cancel-in-progress: false) so every pending main push is queued rather than replaced. |
.github/workflows/ci.yml |
Makes non-PR runs use a per-run (run_id) concurrency group so queued runs are never cancelled; PR runs keep ref-based cancellation. |
.github/actionlint.yaml |
New config that ignores the queue concurrency-key warning only for release.yml, scoped and justified by Actionlint version. |
README.md |
Status badge now tracks release.yml on main instead of ci.yml. |
I verified the key correctness concern: queue: max is a valid concurrency key (added to GitHub Actions around May 2026) and is only incompatible with cancel-in-progress: true — here it is paired with cancel-in-progress: false, which is valid. The .github/actionlint.yaml file parses as valid YAML and matches Actionlint's paths/ignore schema, with the ignore scoped to release.yml and specific enough not to mask unrelated errors. The ci.yml group expression resolves to unique per-run groups for workflow_call/workflow_dispatch and ref-based groups for pull requests, consistent with the stated intent. I found no defects to flag.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
A push to
mainno longer cancels the pending Release run of the push before it, so every pushed range reaches CI's scan. Releases and deploys still run one at a time.roku-release-<ref>, unchanged.github/actionlint.yamlignores only thequeuekey inrelease.yml, which Actionlint 1.7.12 predates.main. CI runs onmainonly on dispatch, so its badge last moved in August.ci:commit releases and deploys nothing.Written by an agent (Claude Code, Claude Opus 5.5)