diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 2f8a406..f6f9008 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -12,8 +12,10 @@ on: permissions: contents: read +# Only runs that will do work share the group, so a skipped stale +# workflow_run cannot cancel or replace the run for the current commit. concurrency: - group: ${{ github.workflow }}-${{ github.ref }} + group: ${{ github.workflow }}-${{ (github.event_name != 'workflow_run' || (github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.head_sha == github.sha)) && github.ref || github.run_id }} cancel-in-progress: true jobs: @@ -22,11 +24,14 @@ jobs: timeout-minutes: 10 if: >- github.event_name == 'pull_request' || - github.event.workflow_run.conclusion == 'success' + (github.event.workflow_run.conclusion == 'success' && + github.event.workflow_run.head_sha == github.sha) steps: - name: Checkout code uses: actions/checkout@v7 + with: + ref: ${{ github.event.workflow_run.head_sha }} - name: Setup pnpm uses: pnpm/action-setup@v6 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index c00fb59..6d72bc9 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -12,17 +12,22 @@ permissions: pull-requests: write id-token: write # Required for OIDC -concurrency: ${{ github.workflow }}-${{ github.ref }} +# Only runs that will do work share the group, so a skipped stale +# workflow_run cannot cancel or replace the run for the current commit. +concurrency: ${{ github.workflow }}-${{ (github.event_name != 'workflow_run' || (github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.head_sha == github.sha)) && github.ref || github.run_id }} jobs: release: runs-on: ubuntu-latest timeout-minutes: 15 - if: ${{ github.event.workflow_run.conclusion == 'success' }} + if: >- + github.event.workflow_run.conclusion == 'success' && + github.event.workflow_run.head_sha == github.sha steps: - name: Checkout code uses: actions/checkout@v7 with: + ref: ${{ github.event.workflow_run.head_sha }} fetch-depth: 0 # Setup Node.js to enable trusted publishing with OIDC authentication. diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index aee813b..9da9787 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -12,8 +12,10 @@ on: permissions: contents: read +# Only runs that will do work share the group, so a skipped stale +# workflow_run cannot cancel or replace the run for the current commit. concurrency: - group: ${{ github.workflow }}-${{ github.ref }} + group: ${{ github.workflow }}-${{ (github.event_name != 'workflow_run' || (github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.head_sha == github.sha)) && github.ref || github.run_id }} cancel-in-progress: true jobs: @@ -23,7 +25,8 @@ jobs: timeout-minutes: 10 if: >- github.event_name == 'pull_request' || - github.event.workflow_run.conclusion == 'success' + (github.event.workflow_run.conclusion == 'success' && + github.event.workflow_run.head_sha == github.sha) strategy: fail-fast: false matrix: @@ -36,6 +39,8 @@ jobs: steps: - name: Checkout code uses: actions/checkout@v7 + with: + ref: ${{ github.event.workflow_run.head_sha }} - name: Setup pnpm uses: pnpm/action-setup@v6