Skip to content

Keep every workflow_run step on the commit that passed the one before - #72

Merged
adelrodriguez merged 2 commits into
mainfrom
ci/pin-tested-sha
Oct 5, 2026
Merged

adelrodriguez merged 2 commits into
mainfrom
ci/pin-tested-sha

Conversation

@adelrodriguez

Copy link
Copy Markdown
Owner

On main, test, build and release each start from the previous workflow through workflow_run. In a workflow_run run, actions/checkout defaults to github.sha, which is the latest commit on main, not the commit the previous workflow checked. If main moves between steps, or an older run is re-run, build can verify a different commit than test did, and release can publish a commit that never passed both.

  • Each workflow_run job checks out github.event.workflow_run.head_sha.
  • Each one runs only while that SHA is still github.sha, the tip of main. A run that passes this check has the tested commit as its own head_sha, so that SHA carries through to the next step. A stale chain ends as skipped, not success, so the next step does not start, and the newer commit releases through its own chain.

Pull request runs are unchanged: the added expressions are empty on pull_request.

Pullfrog raised this on faultier#89 and sakuga#21. This PR applies the same fix here.

🤖 Generated with Claude Code

A workflow_run event checks out the latest main commit, not the commit
the upstream workflow tested. Check out workflow_run.head_sha in test,
build and release, and run only while it is still the tip of main. A
stale chain is then skipped, and the newer commit releases through its
own chain.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes Reviewed commit selection and job conditions in the test, build, and release workflows.

  • Pinned checkout: Each workflow_run job checks out the source run's head_sha.
  • Stale run checks: Each job requires a successful source run whose SHA matches the receiving run's github.sha. Existing Actions API records confirm that workflows with all jobs skipped have conclusion skipped, so they do not pass the next success condition.
  • Pull request behavior: The test and build jobs retain their pull request path. An empty checkout ref retains the default pull request checkout.

The five existing PR checks passed. I checked the GitHub event contracts and Actions API records. I did not start a new main workflow chain.

Pullfrog  | View workflow run | Using gpt-6.1-sol | 𝕏

Workflow concurrency applies before job conditions, so a stale or failed
upstream event could cancel or replace the run for the current commit
and then skip its own jobs. Give those events a group of their own.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes Reviewed the concurrency changes in 2aa504f, since the prior review at cee9099.

  • Isolated skipped runs: Changed test, build, and release to use a separate github.run_id group for stale or unsuccessful workflow_run events.
  • Preserved active-run controls: Kept successful current-SHA events and pull request checks in their previous ref-based groups. Retained cancellation in test and build, and serialization without cancellation in release.

All three changed workflows passed local actionlint validation. All five PR checks passed. I checked the expressions against GitHub's documented concurrency rules; I did not start a new main workflow chain.

Pullfrog  | View workflow run | Using gpt-6.1-sol | 𝕏

@adelrodriguez
adelrodriguez merged commit c69f9bd into main Oct 5, 2026
6 checks passed
@adelrodriguez
adelrodriguez deleted the ci/pin-tested-sha branch October 5, 2026 17:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant