Files
ever-gauzy/.github/workflows/snyk-analysis.yml
T
Ruslan KonviserandClaude Opus 5.5 40826df61b ci: unpack the lint cache off the RAM disk; PRs into develop start no workflow
Static Checks / lint (x64-4 lane): every cache hit since the job moved to
this lane ran out of space. The 2.47 GB archive plus the tree it unpacks to
does not fit the 16Gi RAM-backed workspace, so each hit fell back to a
1.5-4 h cold install (16 of 16 runs cold since #10303). The Restore step
now moves the archive onto the disk-backed package-cache volume (the
parent of YARN_CACHE_FOLDER) before extracting, so only the tree lives in
RAM. Where YARN_CACHE_FOLDER is unset, or the move fails, it extracts in
place exactly as before. Two report-only df lines (after the restore and
at the top of Summarize) record workspace headroom and can never fail a
step.

Triggers: apply the owner decision of 2026-09-21 (already on draft #10254,
same text) directly to develop. A pull request INTO develop no longer
starts static-checks, typos (cspell), snyk-analysis (trigger removed,
restore lines kept in a comment), or build, secrets-analysis and the
external-uptime-monitor self-test (branches-ignore: develop, so PRs into
stage/master still run them). Every push trigger is unchanged, so all of
them still run when code lands on develop. develop has no required status
checks, so no PR is blocked by the missing runs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-27 15:11:58 +02:00

51 lines
1.7 KiB
YAML

name: 'Snyk'
on:
push:
branches:
- develop
# Off by owner decision (2026-09-21): a pull request INTO develop no longer starts a run: the cost
# belonged to every commit on the branch being merged, and the run belongs to the merge. The push
# trigger above runs the whole workflow when code lands on develop. To restore the PR trigger,
# replace this comment with:
# pull_request:
# branches:
# - develop
concurrency:
group: ${{ github.ref }}-${{ github.workflow }}
cancel-in-progress: true
# Least-privilege scope for the automatic GITHUB_TOKEN.
# `security-events: write` is required by codeql-action/upload-sarif; `actions: read`
# lets it resolve the run it is attaching results to on pull_request events.
permissions:
contents: read
security-events: write
actions: read
jobs:
analyze:
name: Analyze
# Never run jobs for a pull request from a fork (owner decision 2026-09-16); branch PRs and pushes still run.
if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }}
runs-on: ${{ vars.RUNNER_LINUX_X64_4 || 'ubuntu-latest' }}
timeout-minutes: 300
steps:
- name: Checkout repository
uses: actions/checkout@v5
- name: Run Snyk to check for vulnerabilities
uses: snyk/actions/node@master
continue-on-error: true # To make sure that SARIF upload gets called
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
with:
args: --sarif-file-output=snyk.sarif
- name: Upload result to GitHub Code Scanning
uses: github/codeql-action/upload-sarif@v2
with:
sarif_file: snyk.sarif