ci: reduce PR check time from ~30 min to ~1 min (#1073)
* ci: reduce PR check time from ~30 min to ~1 min - merge lint + prettier into single code-quality workflow - add concurrency groups to cancel stale runs on rapid pushes - add path filters so irrelevant changes skip checks - make full nix build opt-in via "nix" label (eval-only by default) - add nix store caching via magic-nix-cache-action - cache trusted-signing-cli binary on windows builds - upgrade setup-bun from v1 to v2 * ci: add workflow path filters and expand nix build triggers - add .github/workflows/** to path filters on code-quality and nix-check so CI runs when workflow files themselves change - include tauri.conf.json and build.rs in nix full-build diff check since these can break nix sandbox builds independently of cargo builds
This commit is contained in:
parent
d1da935479
commit
e1a484f70f
7 changed files with 116 additions and 51 deletions
15
.github/workflows/build.yml
vendored
15
.github/workflows/build.yml
vendored
|
|
@ -44,6 +44,9 @@ on:
|
||||||
type: boolean
|
type: boolean
|
||||||
default: false
|
default: false
|
||||||
|
|
||||||
|
env:
|
||||||
|
TSC_VERSION: "0.9.0"
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
permissions:
|
permissions:
|
||||||
|
|
@ -170,9 +173,17 @@ jobs:
|
||||||
vulkan-components: Vulkan-Headers, Vulkan-Loader
|
vulkan-components: Vulkan-Headers, Vulkan-Loader
|
||||||
vulkan-use-cache: true
|
vulkan-use-cache: true
|
||||||
|
|
||||||
- name: Install trusted-signing-cli
|
- name: Cache trusted-signing-cli
|
||||||
if: contains(inputs.platform, 'windows') && inputs.sign-binaries
|
if: contains(inputs.platform, 'windows') && inputs.sign-binaries
|
||||||
run: cargo install trusted-signing-cli
|
id: cache-tsc
|
||||||
|
uses: actions/cache@v4
|
||||||
|
with:
|
||||||
|
path: ~/.cargo/bin/trusted-signing-cli*
|
||||||
|
key: trusted-signing-cli-${{ env.TSC_VERSION }}-${{ runner.os }}-${{ runner.arch }}
|
||||||
|
|
||||||
|
- name: Install trusted-signing-cli
|
||||||
|
if: contains(inputs.platform, 'windows') && inputs.sign-binaries && steps.cache-tsc.outputs.cache-hit != 'true'
|
||||||
|
run: cargo install trusted-signing-cli@${{ env.TSC_VERSION }}
|
||||||
|
|
||||||
- name: Prepare Vulkan SDK for Ubuntu 24.04
|
- name: Prepare Vulkan SDK for Ubuntu 24.04
|
||||||
if: contains(inputs.platform, 'ubuntu-24.04') && !contains(inputs.platform, 'arm')
|
if: contains(inputs.platform, 'ubuntu-24.04') && !contains(inputs.platform, 'arm')
|
||||||
|
|
|
||||||
40
.github/workflows/code-quality.yml
vendored
Normal file
40
.github/workflows/code-quality.yml
vendored
Normal file
|
|
@ -0,0 +1,40 @@
|
||||||
|
name: "code quality"
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
pull_request:
|
||||||
|
paths:
|
||||||
|
- "src/**"
|
||||||
|
- "package.json"
|
||||||
|
- "bun.lock"
|
||||||
|
- ".eslintrc*"
|
||||||
|
- "eslint.config.*"
|
||||||
|
- ".prettierrc*"
|
||||||
|
- "tsconfig*"
|
||||||
|
- "tailwind.config.*"
|
||||||
|
- ".github/workflows/**"
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
|
||||||
|
cancel-in-progress: true
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
code-quality:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- uses: oven-sh/setup-bun@v2
|
||||||
|
with:
|
||||||
|
bun-version: latest
|
||||||
|
|
||||||
|
- name: Install dependencies
|
||||||
|
run: bun install --frozen-lockfile
|
||||||
|
|
||||||
|
- name: Check translation consistency
|
||||||
|
run: bun run check:translations
|
||||||
|
|
||||||
|
- name: Run ESLint
|
||||||
|
run: bun run lint
|
||||||
|
|
||||||
|
- name: Run prettier
|
||||||
|
run: bun run format:check
|
||||||
21
.github/workflows/lint.yml
vendored
21
.github/workflows/lint.yml
vendored
|
|
@ -1,21 +0,0 @@
|
||||||
name: "lint"
|
|
||||||
on: [pull_request]
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
lint:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- uses: oven-sh/setup-bun@v1
|
|
||||||
with:
|
|
||||||
bun-version: latest
|
|
||||||
|
|
||||||
- name: Install dependencies
|
|
||||||
run: bun install --frozen-lockfile
|
|
||||||
|
|
||||||
- name: Check translation consistency
|
|
||||||
run: bun run check:translations
|
|
||||||
|
|
||||||
- name: Run ESLint
|
|
||||||
run: bun run lint
|
|
||||||
47
.github/workflows/nix-check.yml
vendored
47
.github/workflows/nix-check.yml
vendored
|
|
@ -1,12 +1,27 @@
|
||||||
# Verify that Nix dependency files (.nix/bun.nix) are in sync with lockfiles
|
# Nix CI — two tiers:
|
||||||
# and that the flake evaluates successfully.
|
|
||||||
#
|
#
|
||||||
# This catches cases where a developer updated bun.lock but forgot to
|
# 1. Quick checks (bun.nix sync, flake eval) run on ANY source change
|
||||||
# regenerate .nix/bun.nix (e.g., committed without running bun install,
|
# so compilation-breaking edits are caught by flake eval.
|
||||||
# which triggers the postinstall hook).
|
# 2. Full nix build (~25 min) only runs when nix packaging files change.
|
||||||
|
#
|
||||||
|
# Setting up a Cachix binary cache would further reduce full-build times.
|
||||||
|
|
||||||
name: "nix build check"
|
name: "nix build check"
|
||||||
on: [pull_request]
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
pull_request:
|
||||||
|
paths:
|
||||||
|
- "flake.nix"
|
||||||
|
- "flake.lock"
|
||||||
|
- ".nix/**"
|
||||||
|
- "bun.lock"
|
||||||
|
- "src-tauri/**"
|
||||||
|
- "src/**"
|
||||||
|
- ".github/workflows/**"
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
|
||||||
|
cancel-in-progress: true
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
nix-build:
|
nix-build:
|
||||||
|
|
@ -16,11 +31,15 @@ jobs:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
- uses: oven-sh/setup-bun@v2
|
- uses: oven-sh/setup-bun@v2
|
||||||
|
with:
|
||||||
|
bun-version: latest
|
||||||
|
|
||||||
- uses: cachix/install-nix-action@v30
|
- uses: cachix/install-nix-action@v30
|
||||||
with:
|
with:
|
||||||
nix_path: nixpkgs=channel:nixos-unstable
|
nix_path: nixpkgs=channel:nixos-unstable
|
||||||
|
|
||||||
|
- uses: DeterminateSystems/magic-nix-cache-action@565684385bcd71bad329742eefe8d12f2e765b39 # v13
|
||||||
|
|
||||||
# Regenerate .nix/bun.nix from bun.lock and check if it matches
|
# Regenerate .nix/bun.nix from bun.lock and check if it matches
|
||||||
# what's committed. A diff means the developer forgot to run
|
# what's committed. A diff means the developer forgot to run
|
||||||
# bun scripts/check-nix-deps.ts or bun install (which triggers it).
|
# bun scripts/check-nix-deps.ts or bun install (which triggers it).
|
||||||
|
|
@ -73,8 +92,22 @@ jobs:
|
||||||
cat eval_err.log
|
cat eval_err.log
|
||||||
exit 1
|
exit 1
|
||||||
|
|
||||||
|
# Detect whether nix packaging files changed — if only source code
|
||||||
|
# changed, the quick checks above are sufficient.
|
||||||
|
# Skipped on workflow_dispatch (no base ref) — full build runs instead.
|
||||||
|
- name: Check if nix files changed
|
||||||
|
if: github.event_name == 'pull_request'
|
||||||
|
id: nix-files
|
||||||
|
run: |
|
||||||
|
git fetch origin ${{ github.base_ref }} --depth=1
|
||||||
|
if git diff --name-only origin/${{ github.base_ref }}...HEAD | grep -qE '^(flake\.(nix|lock)|\.nix/|bun\.lock|src-tauri/(Cargo\.(toml|lock)|tauri\.conf\.json|build\.rs))'; then
|
||||||
|
echo "changed=true" >> "$GITHUB_OUTPUT"
|
||||||
|
fi
|
||||||
|
|
||||||
# Full build — catches runtime build errors (broken dependencies,
|
# Full build — catches runtime build errors (broken dependencies,
|
||||||
# sandbox issues, compilation failures) that flake eval alone misses.
|
# sandbox issues, compilation failures) that flake eval alone misses.
|
||||||
|
# Only runs when nix packaging files change (~25 min with cold cache).
|
||||||
|
# Always runs on workflow_dispatch (manual trigger).
|
||||||
- name: Build handy
|
- name: Build handy
|
||||||
if: steps.bun-check.outputs.outdated != 'true' && steps.eval.outputs.failed != 'true'
|
if: steps.bun-check.outputs.outdated != 'true' && steps.eval.outputs.failed != 'true' && (steps.nix-files.outputs.changed == 'true' || github.event_name == 'workflow_dispatch')
|
||||||
run: nix build .#handy -L --show-trace
|
run: nix build .#handy -L --show-trace
|
||||||
|
|
|
||||||
16
.github/workflows/playwright.yml
vendored
16
.github/workflows/playwright.yml
vendored
|
|
@ -1,5 +1,17 @@
|
||||||
name: "Playwright"
|
name: "Playwright"
|
||||||
on: [pull_request]
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
pull_request:
|
||||||
|
paths:
|
||||||
|
- "src/**"
|
||||||
|
- "package.json"
|
||||||
|
- "bun.lock"
|
||||||
|
- "playwright.config.*"
|
||||||
|
- "tests/**"
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
|
||||||
|
cancel-in-progress: true
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
playwright:
|
playwright:
|
||||||
|
|
@ -7,7 +19,7 @@ jobs:
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
- uses: oven-sh/setup-bun@v1
|
- uses: oven-sh/setup-bun@v2
|
||||||
with:
|
with:
|
||||||
bun-version: latest
|
bun-version: latest
|
||||||
|
|
||||||
|
|
|
||||||
18
.github/workflows/prettier.yml
vendored
18
.github/workflows/prettier.yml
vendored
|
|
@ -1,18 +0,0 @@
|
||||||
name: "prettier"
|
|
||||||
on: [pull_request]
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
prettier:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- uses: oven-sh/setup-bun@v1
|
|
||||||
with:
|
|
||||||
bun-version: latest
|
|
||||||
|
|
||||||
- name: Install dependencies
|
|
||||||
run: bun install --frozen-lockfile
|
|
||||||
|
|
||||||
- name: Run prettier
|
|
||||||
run: bun run format:check
|
|
||||||
10
.github/workflows/test.yml
vendored
10
.github/workflows/test.yml
vendored
|
|
@ -1,5 +1,13 @@
|
||||||
name: "test"
|
name: "test"
|
||||||
on: [pull_request]
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
pull_request:
|
||||||
|
paths:
|
||||||
|
- "src-tauri/**"
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
|
||||||
|
cancel-in-progress: true
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
rust-tests:
|
rust-tests:
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue