Skip to content

Harden and speed up the GitHub Actions workflows - #22

Merged
lhotari merged 1 commit into
mainfrom
improve-github-actions
Sep 24, 2026
Merged

lhotari merged 1 commit into
mainfrom
improve-github-actions

Conversation

@lhotari

@lhotari lhotari commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Gradle configuration cache: every setup-gradle step (and dependency-submission) gets cache-encryption-key: ${{ secrets.GRADLE_ENCRYPTION_KEY }}, so the enhanced cache provider can save and restore the configuration cache. The reusable build-and-verify.yml declares the secret and ci.yml/release.yml pass it by name (not secrets: inherit). The release's publish job now uses the enhanced provider too.
  • Required status check: a new All checks passed job in ci.yml needs every other job, always runs, and fails unless all of them succeeded, so branch protection can require this one check.
  • Workflow linting: a new Lint workflows job runs actionlint (with shellcheck) and zizmor. .github/actionlint.yaml declares the ubuntu-26.04 runner labels. .github/zizmor.yml requires SHA pins for every action except GitHub's own actions/*.
  • Concurrency: only pull request builds are cancelled by a newer push. Builds of main always finish, because only they save the caches.
  • Least privilege: release.yml is read-only by default, and only github-release and update-readme get contents: write. pull-requests: write in ci.yml moves to the job that needs it. Checkouts set persist-credentials: false except where the job pushes.
  • Fixes from the linters: the README push reads the default branch from an environment variable instead of expanding it into the script (template injection), and the DuckDB step no longer triggers shellcheck SC2155.
  • Release jobs: every job now has a timeout. The four native bundle downloads are one pattern download plus a step that moves each bundle into place and fails if one is missing.
  • Dependabot: weekly grouped updates for GitHub Actions, the Gradle version catalog and wrapper, and the native collector's crates, with separate security-update groups and a cooldown before new releases are proposed. Pull requests carry the maintenance label. dtolnay/rust-toolchain is excluded because its pin must match the cargo +<version> formatting check.

Before merging

  • Create the GRADLE_ENCRYPTION_KEY repository secret, for example with openssl rand -base64 16 | gh secret set GRADLE_ENCRYPTION_KEY. Without it, the configuration cache is not saved.
  • If branch protection later requires All checks passed, the release's update-readme job can no longer push to main directly. It will need a bypass for GitHub Actions, or it will have to open a pull request instead.

Verification

  • actionlint 1.7.12 and zizmor 1.30.1 (with online audits) pass locally with no findings.

Encrypt the configuration cache that setup-gradle saves with the
GRADLE_ENCRYPTION_KEY secret, which the reusable build-and-verify
workflow declares and its callers pass by name, and use the enhanced
cache provider in the release's publish job as well.

Add an "All checks passed" job to CI that needs every other job and
fails unless all of them succeeded, so branch protection can require a
single status check. A new "Lint workflows" job runs actionlint and
zizmor on the workflows.

Builds of main are no longer cancelled by a newer push, since only they
save the caches every other build restores. The release workflow is
read-only by default and grants contents: write only to the jobs that
create the release and push the README update. Checkouts no longer
persist credentials unless they push, the README push reads the default
branch from the environment instead of expanding it into the script,
every release job has a timeout, and the four native bundle downloads
are one pattern download that fails if a bundle is missing.

Dependabot now updates the GitHub Actions, the Gradle version catalog
and wrapper, and the native collector's crates weekly, in grouped pull
requests labelled for the Maintenance section of the release notes.
@lhotari lhotari added the maintenance Build, CI, dependency and other maintenance changes label Sep 24, 2026
@lhotari
lhotari merged commit 8928a8f into main Sep 24, 2026
7 checks passed
@lhotari
lhotari deleted the improve-github-actions branch September 24, 2026 13:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance Build, CI, dependency and other maintenance changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant