deps(ci): bump the actions group with 2 updates - #6
Merged
Merged
Conversation
Bumps the actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action). Updates `github/codeql-action/init` from 24c7eb380a2dc368f2d129e4c65e51d172983a1e to 5595ccaf912efad79be6eef63a5619ff05969be3 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@24c7eb3...5595cca) Updates `github/codeql-action/analyze` from 24c7eb380a2dc368f2d129e4c65e51d172983a1e to 5595ccaf912efad79be6eef63a5619ff05969be3 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@24c7eb3...5595cca) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 5595ccaf912efad79be6eef63a5619ff05969be3 dependency-type: direct:production dependency-group: actions - dependency-name: github/codeql-action/analyze dependency-version: 5595ccaf912efad79be6eef63a5619ff05969be3 dependency-type: direct:production dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
dependabot
Bot
deleted the
dependabot/github_actions/actions-0842fdd703
branch
August 12, 2026 22:27
sameersegal
pushed a commit
that referenced
this pull request
Aug 13, 2026
`vitest-pool-workers` loses a race on startup and the run then hangs forever rather than failing: an environment is torn down while module resolution is still in flight, workerd raises EnvironmentTeardownError: [vitest-worker]: Closing rpc while "resolve" was pending as an uncaught exception, and vitest never prints a summary and never exits. The job had no timeout, so each occurrence burned GitHub's six-hour default before reporting anything, and `deploy` — which needs `check` — never ran. That is what happened to the CodeQL bump in #6 and then to main itself. The failure scales with the number of test files, not with anything in them: one file is clean 6/6 in ten seconds, an 11-file shard wedges, and the full 44-file suite fails between half and three quarters of attempts. Upgrading the pool to 0.21.2, serialising with `--no-file-parallelism`, sharding into quarters and clearing leaked state between runs were all measured and none of them move it. Every wedge landed during collection, before a test had run, which is also why no test is at fault. So this bounds the damage rather than claiming a cure. `timeout` reports a wedge as 124 and only 124 is retried; a genuine test failure exits non-zero some other way and still fails the build on the first attempt, so a red test cannot hide in here. Between attempts the orphaned workerd processes are reaped — `timeout` kills vitest but not the children it spawned, and they were measured surviving and accumulating. Five attempts rather than three because at the observed rate three would still leave about a 30% chance of a spurious red. The job timeout is the backstop for anything the retry does not anticipate. The real fix belongs upstream. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011ZPuc3Cq4bo5wXBejhn6E1
sameersegal
pushed a commit
that referenced
this pull request
Aug 13, 2026
`vitest-pool-workers` loses a race on startup and the run then hangs forever rather than failing: an environment is torn down while module resolution is still in flight, workerd raises EnvironmentTeardownError: [vitest-worker]: Closing rpc while "resolve" was pending as an uncaught exception, and vitest never prints a summary and never exits. The job had no timeout, so each occurrence burned GitHub's six-hour default before reporting anything, and `deploy` — which needs `check` — never ran. That is what happened to the CodeQL bump in #6 and then to main itself. The failure scales with the number of test files, not with anything in them: one file is clean 6/6 in ten seconds, an 11-file shard wedges, and the full 44-file suite fails between half and three quarters of attempts. Upgrading the pool to 0.21.2, serialising with `--no-file-parallelism`, sharding into quarters and clearing leaked state between runs were all measured and none of them move it. Every wedge landed during collection, before a test had run, which is also why no test is at fault. So this bounds the damage rather than claiming a cure. `timeout` reports a wedge as 124 and only 124 is retried; a genuine test failure exits non-zero some other way and still fails the build on the first attempt, so a red test cannot hide in here. Between attempts the orphaned workerd processes are reaped — `timeout` kills vitest but not the children it spawned, and they were measured surviving and accumulating. Five attempts rather than three because at the observed rate three would still leave about a 30% chance of a spurious red. The job timeout is the backstop for anything the retry does not anticipate. The real fix belongs upstream. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011ZPuc3Cq4bo5wXBejhn6E1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the actions group with 2 updates: github/codeql-action/init and github/codeql-action/analyze.
Updates
github/codeql-action/initfrom 24c7eb380a2dc368f2d129e4c65e51d172983a1e to 5595ccaf912efad79be6eef63a5619ff05969be3Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
Updates
github/codeql-action/analyzefrom 24c7eb380a2dc368f2d129e4c65e51d172983a1e to 5595ccaf912efad79be6eef63a5619ff05969be3Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions