ci: pin the actions by version tag and cap the test timeout at 10m

This commit is contained in:
2026-09-22 21:45:25 +02:00
parent eb6ac1ab9d
commit 010a7b2a1e
4 changed files with 14 additions and 14 deletions
+2 -2
View File
@@ -22,9 +22,9 @@ jobs:
runs-on: fedora runs-on: fedora
timeout-minutes: 10 timeout-minutes: 10
steps: steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: actions/checkout@v7
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6 - uses: actions/setup-go@v6
with: with:
go-version-file: go.mod go-version-file: go.mod
cache: true cache: true
+3 -3
View File
@@ -22,9 +22,9 @@ jobs:
runs-on: fedora runs-on: fedora
timeout-minutes: 45 timeout-minutes: 45
steps: steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: actions/checkout@v7
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6 - uses: actions/setup-go@v6
with: with:
go-version-file: go.mod go-version-file: go.mod
cache: true cache: true
@@ -34,4 +34,4 @@ jobs:
run: dnf install -y gcc run: dnf install -y gcc
- name: Race - name: Race
run: go test -race -count=1 -timeout 30m ./... run: go test -race -count=1 -timeout 10m ./...
+6 -6
View File
@@ -4,8 +4,8 @@
# carries the CHANGELOG section as its body and nothing else. The gates still run first, # carries the CHANGELOG section as its body and nothing else. The gates still run first,
# in their own job and once, minus the race detector: race never runs on a push path or a # in their own job and once, minus the race detector: race never runs on a push path or a
# tag, and the local gate raced this tree before the tag was cut. The write permission # tag, and the local gate raced this tree before the tag was cut. The write permission
# sits on the release job alone, and the version contract these steps implement is in the # sits on the release job alone, and the version the binary reports is the one the
# `release` skill. # toolchain records from the tag, with nothing injected.
# #
# Every step is one command, so the step that fails is the gate that failed, and no shell # Every step is one command, so the step that fails is the gate that failed, and no shell
# option has to be trusted for the run to stop. The scripted steps are Perl, not shell and # option has to be trusted for the run to stop. The scripted steps are Perl, not shell and
@@ -31,9 +31,9 @@ jobs:
runs-on: fedora runs-on: fedora
timeout-minutes: 10 timeout-minutes: 10
steps: steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: actions/checkout@v7
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6 - uses: actions/setup-go@v6
with: with:
# The module is the source of truth for the version, so it cannot drift. # The module is the source of truth for the version, so it cannot drift.
go-version-file: go.mod go-version-file: go.mod
@@ -77,7 +77,7 @@ jobs:
- name: Tests - name: Tests
# Keep the pattern equal to `packages` in the project's justfile. # Keep the pattern equal to `packages` in the project's justfile.
run: go test -count=1 -timeout 30m -coverprofile=coverage.out ./... run: go test -count=1 -timeout 10m -coverprofile=coverage.out ./...
- name: Coverage floor - name: Coverage floor
run: | run: |
@@ -103,7 +103,7 @@ jobs:
contents: read contents: read
releases: write releases: write
steps: steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: actions/checkout@v7
- name: Install Perl - name: Install Perl
# The runner images are minimal and Perl is not guaranteed. The install is a # The runner images are minimal and Perl is not guaranteed. The install is a
+3 -3
View File
@@ -44,9 +44,9 @@ jobs:
runs-on: fedora runs-on: fedora
timeout-minutes: 10 timeout-minutes: 10
steps: steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: actions/checkout@v7
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6 - uses: actions/setup-go@v6
with: with:
# The module is the source of truth for the version, so it cannot drift. # The module is the source of truth for the version, so it cannot drift.
go-version-file: go.mod go-version-file: go.mod
@@ -80,7 +80,7 @@ jobs:
- name: Tests - name: Tests
# Scope the pattern to the packages that hold the logic when a thin cmd/ drags the # Scope the pattern to the packages that hold the logic when a thin cmd/ drags the
# total under the floor, and keep it equal to `packages` in the project's justfile. # total under the floor, and keep it equal to `packages` in the project's justfile.
run: go test -count=1 -timeout 30m -coverprofile=coverage.out ./... run: go test -count=1 -timeout 10m -coverprofile=coverage.out ./...
- name: Coverage floor - name: Coverage floor
run: | run: |