diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c712c71b8a..a29b82baba 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -7,13 +7,23 @@ on: - main - dev +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + jobs: verify: runs-on: ubuntu-latest + timeout-minutes: 15 steps: - name: Checkout code uses: actions/checkout@v4 + with: + persist-credentials: false - name: Setup Node.js uses: actions/setup-node@v4 diff --git a/.github/workflows/lab-reject-pr-to-main.yml b/.github/workflows/lab-reject-pr-to-main.yml index 1d0d74f260..91f5d06751 100644 --- a/.github/workflows/lab-reject-pr-to-main.yml +++ b/.github/workflows/lab-reject-pr-to-main.yml @@ -5,9 +5,16 @@ on: pull_request: branches: [main] +permissions: {} + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + jobs: reject: runs-on: ubuntu-latest + timeout-minutes: 2 steps: - name: Explain run: | diff --git a/.github/workflows/lab-sync-upstream-main.yml b/.github/workflows/lab-sync-upstream-main.yml index 184e047382..15f99e5228 100644 --- a/.github/workflows/lab-sync-upstream-main.yml +++ b/.github/workflows/lab-sync-upstream-main.yml @@ -5,13 +5,12 @@ name: lab — sync main from upstream on: schedule: - cron: "17 6 * * *" - push: - branches: [main] workflow_dispatch: concurrency: group: lab-sync-upstream-main - cancel-in-progress: true + # A newer request must not interrupt an in-flight branch update. + cancel-in-progress: false permissions: contents: read @@ -19,6 +18,7 @@ permissions: jobs: sync: runs-on: ubuntu-latest + timeout-minutes: 5 steps: - name: Check out main over SSH uses: actions/checkout@v4 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 89102e637b..fa9710e59e 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -5,9 +5,13 @@ on: tags: - 'v*' +permissions: + contents: read + jobs: build-and-release: runs-on: ubuntu-latest + timeout-minutes: 15 permissions: contents: write @@ -16,6 +20,7 @@ jobs: - name: Checkout code uses: actions/checkout@v4 with: + persist-credentials: false fetch-depth: 0 fetch-tags: true @@ -58,7 +63,7 @@ jobs: git log --pretty=format:"- %h %s" "${range}" >> release-notes.md - name: Create Release - uses: softprops/action-gh-release@v1 + uses: softprops/action-gh-release@v2 with: files: dist/management.html body_path: release-notes.md diff --git a/LAB.md b/LAB.md index 6d58951b2c..d69e033a77 100644 --- a/LAB.md +++ b/LAB.md @@ -36,7 +36,8 @@ GitHub enforces that: - `.github/workflows/lab-reject-pr-to-main.yml` fails any PR that targets `main`. - `.github/workflows/lab-sync-upstream-main.yml` resets `main` to - `upstream/main` daily, on push, and via workflow_dispatch. + `upstream/main` daily and via workflow_dispatch. A push from the sync + deploy key does not schedule another redundant sync. PR #1 was merged into `main` by accident and then undone. The ruleset is there so that cannot stick again.