Repository navigation
Harden and speed up the GitHub Actions workflows - #22
Merged
Merged
Conversation
Encrypt the configuration cache that setup-gradle saves with the GRADLE_ENCRYPTION_KEY secret, which the reusable build-and-verify workflow declares and its callers pass by name, and use the enhanced cache provider in the release's publish job as well. Add an "All checks passed" job to CI that needs every other job and fails unless all of them succeeded, so branch protection can require a single status check. A new "Lint workflows" job runs actionlint and zizmor on the workflows. Builds of main are no longer cancelled by a newer push, since only they save the caches every other build restores. The release workflow is read-only by default and grants contents: write only to the jobs that create the release and push the README update. Checkouts no longer persist credentials unless they push, the README push reads the default branch from the environment instead of expanding it into the script, every release job has a timeout, and the four native bundle downloads are one pattern download that fails if a bundle is missing. Dependabot now updates the GitHub Actions, the Gradle version catalog and wrapper, and the native collector's crates weekly, in grouped pull requests labelled for the Maintenance section of the release notes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
setup-gradlestep (anddependency-submission) getscache-encryption-key: ${{ secrets.GRADLE_ENCRYPTION_KEY }}, so the enhanced cache provider can save and restore the configuration cache. The reusablebuild-and-verify.ymldeclares the secret andci.yml/release.ymlpass it by name (notsecrets: inherit). The release'spublishjob now uses the enhanced provider too.All checks passedjob inci.ymlneeds every other job, always runs, and fails unless all of them succeeded, so branch protection can require this one check.Lint workflowsjob runs actionlint (with shellcheck) and zizmor..github/actionlint.yamldeclares theubuntu-26.04runner labels..github/zizmor.ymlrequires SHA pins for every action except GitHub's ownactions/*.mainalways finish, because only they save the caches.release.ymlis read-only by default, and onlygithub-releaseandupdate-readmegetcontents: write.pull-requests: writeinci.ymlmoves to the job that needs it. Checkouts setpersist-credentials: falseexcept where the job pushes.maintenancelabel.dtolnay/rust-toolchainis excluded because its pin must match thecargo +<version>formatting check.Before merging
GRADLE_ENCRYPTION_KEYrepository secret, for example withopenssl rand -base64 16 | gh secret set GRADLE_ENCRYPTION_KEY. Without it, the configuration cache is not saved.All checks passed, the release'supdate-readmejob can no longer push tomaindirectly. It will need a bypass for GitHub Actions, or it will have to open a pull request instead.Verification
actionlint1.7.12 andzizmor1.30.1 (with online audits) pass locally with no findings.