Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 16 additions & 13 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,30 +1,33 @@
name: CI

# Build + test + lint, on pull requests and on every push to master. Runs on
# GitHub-hosted runners so that untrusted fork PRs cannot execute arbitrary
# code on a maintainer-owned self-hosted machine. Tag-cut release builds live
# in `release.yml` (also hosted); reproducible-build verification lives in
# `nix.yml`.
# Build + test + lint, on pull requests and on every push to master or a
# release branch. Runs on GitHub-hosted runners so that untrusted fork PRs
# cannot execute arbitrary code on a maintainer-owned self-hosted machine.
# Tag-cut release builds live in `release.yml` (also hosted); reproducible-build
# verification lives in `nix.yml`.
#
# `Tests` and `Lint` run on master pushes as well as PRs, and deliberately so.
# A PR is tested as head-merged-into-base at event time, which is not the tree
# the merge actually produces; and a merge that outruns its own checks — or
# bypasses them — leaves nothing else to notice. Master went two days with a
# tree that did not compile because the only master-push job was `seed-cache`,
# and it was found by an unrelated PR rather than by CI. These two jobs are
# the detection net for that.
# `Tests` and `Lint` run on master and release-branch pushes as well as PRs,
# and deliberately so. A PR is tested as head-merged-into-base at event time,
# which is not the tree the merge actually produces; and a merge that outruns
# its own checks — or bypasses them — leaves nothing else to notice. Master
# went two days with a tree that did not compile because the only master-push
# job was `seed-cache`, and it was found by an unrelated PR rather than by CI.
# These two jobs are the detection net for that. Patch releases are tagged
# from a `release/*` branch, so the fixes merged there get the same net.

on:
push:
branches:
- master
- 'release/**'
pull_request:
types: [opened, synchronize, reopened]

# Cancel superseded runs on the same PR. Avoids burning hosted-runner
# minutes on stale commits when a contributor pushes rapid fixups.
#
# Cancellation is scoped to pull requests. Master pushes share one ref, so a
# Cancellation is scoped to pull requests. Master pushes share one ref (as do
# a release branch's), so a
# blanket `cancel-in-progress` made each merge cancel the post-merge
# verification of the merge before it — and merges routinely land minutes
# apart. The `seed-cache` job that runs on master is the only thing that
Expand Down
Loading