From cee9099b5a2dc39c2717f454f0cd4252aacbc6f3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Adel=20Rodr=C3=ADguez?= Date: Mon, 5 Oct 2026 12:16:30 -0400 Subject: [PATCH 1/2] Keep every workflow_run step on the commit that passed the one before A workflow_run event checks out the latest main commit, not the commit the upstream workflow tested. Check out workflow_run.head_sha in test, build and release, and run only while it is still the tip of main. A stale chain is then skipped, and the newer commit releases through its own chain. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/build.yml | 5 ++++- .github/workflows/release.yml | 5 ++++- .github/workflows/test.yml | 5 ++++- 3 files changed, 12 insertions(+), 3 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 2f8a406..2c22057 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -22,11 +22,14 @@ jobs: timeout-minutes: 10 if: >- github.event_name == 'pull_request' || - github.event.workflow_run.conclusion == 'success' + (github.event.workflow_run.conclusion == 'success' && + github.event.workflow_run.head_sha == github.sha) steps: - name: Checkout code uses: actions/checkout@v7 + with: + ref: ${{ github.event.workflow_run.head_sha }} - name: Setup pnpm uses: pnpm/action-setup@v6 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index c00fb59..98126e7 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -18,11 +18,14 @@ jobs: release: runs-on: ubuntu-latest timeout-minutes: 15 - if: ${{ github.event.workflow_run.conclusion == 'success' }} + if: >- + github.event.workflow_run.conclusion == 'success' && + github.event.workflow_run.head_sha == github.sha steps: - name: Checkout code uses: actions/checkout@v7 with: + ref: ${{ github.event.workflow_run.head_sha }} fetch-depth: 0 # Setup Node.js to enable trusted publishing with OIDC authentication. diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index aee813b..aee1ef3 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -23,7 +23,8 @@ jobs: timeout-minutes: 10 if: >- github.event_name == 'pull_request' || - github.event.workflow_run.conclusion == 'success' + (github.event.workflow_run.conclusion == 'success' && + github.event.workflow_run.head_sha == github.sha) strategy: fail-fast: false matrix: @@ -36,6 +37,8 @@ jobs: steps: - name: Checkout code uses: actions/checkout@v7 + with: + ref: ${{ github.event.workflow_run.head_sha }} - name: Setup pnpm uses: pnpm/action-setup@v6 From 2aa504f793ecd2d15f884f0bc7b5158a064bdc07 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Adel=20Rodr=C3=ADguez?= Date: Mon, 5 Oct 2026 12:32:43 -0400 Subject: [PATCH 2/2] Keep skipped workflow_run events out of the shared concurrency group Workflow concurrency applies before job conditions, so a stale or failed upstream event could cancel or replace the run for the current commit and then skip its own jobs. Give those events a group of their own. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/build.yml | 4 +++- .github/workflows/release.yml | 4 +++- .github/workflows/test.yml | 4 +++- 3 files changed, 9 insertions(+), 3 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 2c22057..f6f9008 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -12,8 +12,10 @@ on: permissions: contents: read +# Only runs that will do work share the group, so a skipped stale +# workflow_run cannot cancel or replace the run for the current commit. concurrency: - group: ${{ github.workflow }}-${{ github.ref }} + group: ${{ github.workflow }}-${{ (github.event_name != 'workflow_run' || (github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.head_sha == github.sha)) && github.ref || github.run_id }} cancel-in-progress: true jobs: diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 98126e7..6d72bc9 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -12,7 +12,9 @@ permissions: pull-requests: write id-token: write # Required for OIDC -concurrency: ${{ github.workflow }}-${{ github.ref }} +# Only runs that will do work share the group, so a skipped stale +# workflow_run cannot cancel or replace the run for the current commit. +concurrency: ${{ github.workflow }}-${{ (github.event_name != 'workflow_run' || (github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.head_sha == github.sha)) && github.ref || github.run_id }} jobs: release: diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index aee1ef3..9da9787 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -12,8 +12,10 @@ on: permissions: contents: read +# Only runs that will do work share the group, so a skipped stale +# workflow_run cannot cancel or replace the run for the current commit. concurrency: - group: ${{ github.workflow }}-${{ github.ref }} + group: ${{ github.workflow }}-${{ (github.event_name != 'workflow_run' || (github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.head_sha == github.sha)) && github.ref || github.run_id }} cancel-in-progress: true jobs: