mirror of
https://github.com/ever-co/ever-gauzy.git
synced 2026-10-02 01:54:50 +08:00
Static Checks / lint (x64-4 lane): every cache hit since the job moved to this lane ran out of space. The 2.47 GB archive plus the tree it unpacks to does not fit the 16Gi RAM-backed workspace, so each hit fell back to a 1.5-4 h cold install (16 of 16 runs cold since #10303). The Restore step now moves the archive onto the disk-backed package-cache volume (the parent of YARN_CACHE_FOLDER) before extracting, so only the tree lives in RAM. Where YARN_CACHE_FOLDER is unset, or the move fails, it extracts in place exactly as before. Two report-only df lines (after the restore and at the top of Summarize) record workspace headroom and can never fail a step. Triggers: apply the owner decision of 2026-09-21 (already on draft #10254, same text) directly to develop. A pull request INTO develop no longer starts static-checks, typos (cspell), snyk-analysis (trigger removed, restore lines kept in a comment), or build, secrets-analysis and the external-uptime-monitor self-test (branches-ignore: develop, so PRs into stage/master still run them). Every push trigger is unchanged, so all of them still run when code lands on develop. develop has no required status checks, so no PR is blocked by the missing runs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
51 lines
1.7 KiB
YAML
51 lines
1.7 KiB
YAML
name: 'Snyk'
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- develop
|
|
# Off by owner decision (2026-09-21): a pull request INTO develop no longer starts a run: the cost
|
|
# belonged to every commit on the branch being merged, and the run belongs to the merge. The push
|
|
# trigger above runs the whole workflow when code lands on develop. To restore the PR trigger,
|
|
# replace this comment with:
|
|
# pull_request:
|
|
# branches:
|
|
# - develop
|
|
|
|
concurrency:
|
|
group: ${{ github.ref }}-${{ github.workflow }}
|
|
cancel-in-progress: true
|
|
|
|
# Least-privilege scope for the automatic GITHUB_TOKEN.
|
|
# `security-events: write` is required by codeql-action/upload-sarif; `actions: read`
|
|
# lets it resolve the run it is attaching results to on pull_request events.
|
|
permissions:
|
|
contents: read
|
|
security-events: write
|
|
actions: read
|
|
|
|
jobs:
|
|
analyze:
|
|
name: Analyze
|
|
# Never run jobs for a pull request from a fork (owner decision 2026-09-16); branch PRs and pushes still run.
|
|
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
|
|
runs-on: ${{ vars.RUNNER_LINUX_X64_4 || 'ubuntu-latest' }}
|
|
timeout-minutes: 300
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v5
|
|
|
|
- name: Run Snyk to check for vulnerabilities
|
|
uses: snyk/actions/node@master
|
|
continue-on-error: true # To make sure that SARIF upload gets called
|
|
env:
|
|
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
|
|
with:
|
|
args: --sarif-file-output=snyk.sarif
|
|
|
|
- name: Upload result to GitHub Code Scanning
|
|
uses: github/codeql-action/upload-sarif@v2
|
|
with:
|
|
sarif_file: snyk.sarif
|