Skip to content

ci: add a single gate check for main to require - #1511

Merged
ryoppippi merged 1 commit into
mainfrom
ci/add-required-gate
Jul 28, 2026
Merged

ryoppippi merged 1 commit into
mainfrom
ci/add-required-gate

Conversation

@ryoppippi

@ryoppippi ryoppippi commented Jul 28, 2026 •

Copy link
Copy Markdown
Member

Summary

main has no required status checks, so GitHub auto-merge has nothing to wait for. gh pr merge --auto --squash merged #1509 while its CI was still running, and renovate's platformAutomerge (now enabled again by #1508) would merge dependency PRs exactly the same way — instantly, unchecked.

Fixing that needs a check the ruleset can require. Requiring the existing ones directly does not work: everything behind the changes job is skipped on docs-only pull requests, and a skipped check never satisfies a requirement, so those pull requests would be blocked forever on checks that never report.

What Changed

Adds the usual aggregator job to ci.yaml:

  • needs the same jobs action-timeline already waits for, with if: always().
  • Treats skipped as fine; fails only when a job's result is failure or cancelled, via contains(needs.*.result, ...) so it needs no tooling on the runner.
  • Reports the joined results first, so the log shows why it failed.

The check is named ci gate — that single context is what main's ruleset should require.

Follow-up (repo settings, not in this PR)

Once this is on main, a branch ruleset on the default branch requiring ci gate makes both auto-merge and renovate's automerge wait for CI.

That ruleset needs a bypass actor for the GitHub Actions app, because required status checks reject direct pushes too, and update-pricing.yaml (and tagpr) push to main on purpose — a token-created PR gets no CI, which is why they push directly and validate inline.


View with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is enabled.


Summary by cubic

Adds a single CI gate check so auto-merge and Renovate wait for CI on main, without blocking docs-only PRs.

  • New Features

    • Added ci gate job in .github/workflows/ci.yaml.
    • Aggregates results from key jobs with if: always(); skipped is OK.
    • Fails only on failure or cancelled and outputs the joined results.
  • Migration

    • In the default branch ruleset, require the ci gate status check.
    • Add a bypass for the GitHub Actions app to allow intended direct pushes (e.g., update-pricing.yaml, tagpr).

Written for commit 1feaca5. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Added a unified CI status check that consolidates results from the repository’s major validation and publishing checks.
    • The check now clearly reports failures or cancellations while allowing intentionally skipped checks.

main has no required status checks, so GitHub auto-merge has nothing to wait
for: `gh pr merge --auto` merged #1509 while its CI was still running, and
renovate's platformAutomerge would merge dependency PRs the same way.

Requiring the existing checks directly does not work, because everything
behind `changes` is skipped on docs-only pull requests and a skipped check
never satisfies a requirement. This adds the usual aggregator instead: it
needs every job action-timeline already waits for, treats skipped as fine,
and fails only when a job failed or was cancelled. That single "ci gate"
check is what main's ruleset can require.
Copilot AI review requested due to automatic review settings July 28, 2026 01:14

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Jul 28, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 41ff9e96-c159-422a-804f-6cace97187c8

📥 Commits

Reviewing files that changed from the base of the PR and between b184bdc and 1feaca5.

📒 Files selected for processing (1)
  • .github/workflows/ci.yaml

📝 Walkthrough

Walkthrough

Adds a ci-gate workflow job that aggregates major CI job results and fails when any prerequisite job fails or is cancelled.

Changes

CI gate aggregation

Layer / File(s) Summary
Aggregate CI result gate
.github/workflows/ci.yaml
Adds an always-running ci-gate job that reports prerequisite statuses and exits with failure for failed or cancelled jobs while permitting skipped jobs.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers: copilot

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: adding a single required CI gate for main.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/add-required-gate

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
ccusage-guide 1feaca5 Commit Preview URL

Branch Preview URL
Jul 28 2026, 01:15 AM

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes — adds a single ci gate aggregator job so main's branch ruleset can require one check instead of having auto-merge bypass CI entirely.

  • Add ci-gate job to ci.yaml — mirrors the existing action-timeline needs list exactly; runs with if: always() and fails only on failure or cancelled via contains(needs.*.result, ...), correctly letting skipped pass for docs-only PRs and fork PRs where individual jobs don't run.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | View workflow run | Using DeepSeek Pro (free via Pullfrog for OSS) | 𝕏

@pkg-pr-new

pkg-pr-new Bot commented Jul 28, 2026

Copy link
Copy Markdown

Open in StackBlitz

ccusage

npx https://pkg.pr.new/ccusage@1511

@ccusage/ccusage-darwin-arm64

npx https://pkg.pr.new/@ccusage/ccusage-darwin-arm64@1511

@ccusage/ccusage-darwin-x64

npx https://pkg.pr.new/@ccusage/ccusage-darwin-x64@1511

@ccusage/ccusage-linux-arm64

npx https://pkg.pr.new/@ccusage/ccusage-linux-arm64@1511

@ccusage/ccusage-linux-x64

npx https://pkg.pr.new/@ccusage/ccusage-linux-x64@1511

@ccusage/ccusage-win32-x64

npx https://pkg.pr.new/@ccusage/ccusage-win32-x64@1511

commit: 1feaca5

@github-actions

Copy link
Copy Markdown
Contributor

ccusage performance comparison

PR SHA: 1feaca5cc7cf
Base SHA: b184bdce4daf

This compares the Rust PR release binary against the configured base package on the same CI runner.

Package runtime diagnostics

Compares the PR package wrapper, the installed native optional dependency binary, and the workspace release binary on the same large fixture. This identifies whether slow package results come from JavaScript wrapper overhead, the published native binary build, or the Rust core itself.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2597 files)
All rows run --offline --json, measured by hyperfine with 0 warmups and 1 runs. This isolates wrapper overhead from the installed native optional dependency and the workspace release binary built on the runner.

Command Runtime Input Median Throughput Samples
claude --offline --json Package wrapper 1.01 GiB 352.9ms 2.85 GiB/s 1
claude --offline --json Installed native binary 1.01 GiB 374.4ms 2.69 GiB/s 1
codex --offline --json Package wrapper 1.01 GiB 121.3ms 8.30 GiB/s 1
codex --offline --json Installed native binary 1.01 GiB 98.7ms 10.20 GiB/s 1

Committed fixture performance

Committed small fixtures for stable PR-to-PR feedback and explicit Claude/Codex command coverage.

Fixtures: Claude apps/ccusage/test/fixtures/claude (0.00 MiB, 2 files), Codex apps/ccusage/test/fixtures/codex (0.00 MiB, 1 files)
Base runs the published ccusage package from pkg.pr.new, installed before measurement; PR runs the published native ccusage binary from pkg.pr.new, installed before measurement. Both run --offline --json, measured by hyperfine with 2 warmups and 7 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
claude daily --offline --json 0.00 MiB 27.2ms 5.4ms 4.99x 55.00 MiB 12.45 MiB 0.23x 0.06 MiB/s 0.28 MiB/s
claude session --offline --json 0.00 MiB 25.2ms 2.7ms 9.38x 55.00 MiB 12.45 MiB 0.23x 0.06 MiB/s 0.58 MiB/s
codex daily --offline --json 0.00 MiB 27.0ms 2.4ms 11.32x 55.25 MiB 10.44 MiB 0.19x 0.03 MiB/s 0.36 MiB/s
codex session --offline --json 0.00 MiB 27.7ms 2.5ms 11.06x 55.25 MiB 10.44 MiB 0.19x 0.03 MiB/s 0.34 MiB/s

Large real-world-shaped fixture performance

Generated fixtures shaped from aggregate local log statistics: thousands of JSONL files, many small sessions, and a long tail of larger sessions. No real prompts, paths, or outputs are stored in the fixtures.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2597 files)
Base runs the published ccusage package from pkg.pr.new, installed before measurement; PR runs the published native ccusage binary from pkg.pr.new, installed before measurement. Both run --offline --json, measured by hyperfine with 0 warmups and 1 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
claude --offline --json 1.01 GiB 377.8ms 322.9ms 1.17x 952.58 MiB 928.58 MiB 0.97x 2.66 GiB/s 3.12 GiB/s
codex --offline --json 1.01 GiB 125.4ms 97.8ms 1.28x 424.91 MiB 406.63 MiB 0.96x 8.03 GiB/s 10.30 GiB/s

Artifact size

Artifact Base PR Delta Ratio
packed ccusage-*.tgz 18.78 KiB 18.78 KiB -0.00 KiB 1.00x
installed native package binary 4156.78 KiB 4156.78 KiB +0.00 KiB 1.00x

Lower medians and smaller artifacts are better. CI runner noise still applies; use same-run ratios as directional PR feedback, not release guarantees.

@github-actions

Copy link
Copy Markdown
Contributor

ccusage performance comparison

PR SHA: 1feaca5cc7cf
Base SHA: b184bdce4daf

This compares the PR package against the configured base package on the same CI runner.

Package runtime diagnostics

Compares the PR package wrapper, the installed native optional dependency binary, and the workspace release binary on the same large fixture. This identifies whether slow package results come from JavaScript wrapper overhead, the published native binary build, or the Rust core itself.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2597 files)
All rows run --offline --json, measured by hyperfine with 0 warmups and 1 runs. This isolates wrapper overhead from the installed native optional dependency and the workspace release binary built on the runner.

Command Runtime Input Median Throughput Samples
claude --offline --json Package wrapper 1.01 GiB 344.0ms 2.93 GiB/s 1
claude --offline --json Installed native binary 1.01 GiB 311.2ms 3.24 GiB/s 1
codex --offline --json Package wrapper 1.01 GiB 135.1ms 7.45 GiB/s 1
codex --offline --json Installed native binary 1.01 GiB 98.5ms 10.22 GiB/s 1

Committed fixture performance

Committed small fixtures for stable PR-to-PR feedback and explicit Claude/Codex command coverage.

Fixtures: Claude apps/ccusage/test/fixtures/claude (0.00 MiB, 2 files), Codex apps/ccusage/test/fixtures/codex (0.00 MiB, 1 files)
Base runs the published ccusage package from pkg.pr.new, installed before measurement; PR runs the published ccusage package from pkg.pr.new, installed before measurement. Both run --offline --json, measured by hyperfine with 2 warmups and 7 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
claude daily --offline --json 0.00 MiB 26.1ms 27.2ms 0.96x 55.00 MiB 55.00 MiB 1.00x 0.06 MiB/s 0.06 MiB/s
claude session --offline --json 0.00 MiB 23.5ms 25.4ms 0.93x 55.25 MiB 55.00 MiB 1.00x 0.07 MiB/s 0.06 MiB/s
codex daily --offline --json 0.00 MiB 24.8ms 23.5ms 1.06x 55.00 MiB 55.00 MiB 1.00x 0.03 MiB/s 0.04 MiB/s
codex session --offline --json 0.00 MiB 22.7ms 22.7ms 1.00x 55.00 MiB 55.25 MiB 1.00x 0.04 MiB/s 0.04 MiB/s

Large real-world-shaped fixture performance

Generated fixtures shaped from aggregate local log statistics: thousands of JSONL files, many small sessions, and a long tail of larger sessions. No real prompts, paths, or outputs are stored in the fixtures.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2597 files)
Base runs the published ccusage package from pkg.pr.new, installed before measurement; PR runs the published ccusage package from pkg.pr.new, installed before measurement. Both run --offline --json, measured by hyperfine with 0 warmups and 1 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
claude --offline --json 1.01 GiB 365.8ms 343.6ms 1.06x 968.58 MiB 940.57 MiB 0.97x 2.75 GiB/s 2.93 GiB/s
codex --offline --json 1.01 GiB 120.5ms 124.0ms 0.97x 416.65 MiB 394.89 MiB 0.95x 8.36 GiB/s 8.12 GiB/s

Artifact size

Artifact Base PR Delta Ratio
packed ccusage-*.tgz 18.78 KiB 18.78 KiB -0.00 KiB 1.00x
installed native package binary 4156.78 KiB 4156.78 KiB +0.00 KiB 1.00x

Lower medians and smaller artifacts are better. CI runner noise still applies; use same-run ratios as directional PR feedback, not release guarantees.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Re-trigger cubic

@ryoppippi
ryoppippi merged commit d500f5f into main Jul 28, 2026
39 checks passed
@ryoppippi
ryoppippi deleted the ci/add-required-gate branch July 28, 2026 01:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants