Scope CI by visibility: private repositories run on pull requests and dispatch only - #2
Merged
Merged
Conversation
Admiral decision 0025: CI tests run on pull requests only, plus workflow_dispatch; never on a push (main included) and never on a schedule. Drops the push block (branches, tags, paths-ignore) and the schedule block from templates/CI.yml, the same change as JuliaSMLM/GaussMLE c8d4a77, whose copy now differs from this one only in its with: lines. The README's trigger description follows. No file in this repository records the template's hash. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Decision 0025 covers every test workflow, so the self-test also drops its push trigger and gains workflow_dispatch. The pre job ran only on a schedule, which decision 0025 rules out for test workflows and the caller template no longer has, so it is removed rather than kept as dead code; the registered input now adds only the downgrade job. The schedule clause in JULIA_CACHE_SAVE goes with it (a scheduled run is on the default branch anyway). The README follows, and its timeout now reads 60 minutes, as the jobs have been since PR 1. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e note The self-test's pull_request trigger takes the template's types, so a draft marked ready for review gets a real run; without ready_for_review its only run is the draft one, whose skipped jobs count as success. The README notes that only a manual workflow_dispatch run on main seeds a Julia cache. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…chedule Keith revised decision 0025: Actions minutes are free on public repositories, so they keep push and scheduled CI and the warm cache; private repositories test on pull requests and by hand only. This replaces the trigger removal of the earlier commits on this branch: - templates/CI.yml is back to main's version, byte for byte, so no package copy has to change. - julia-ci.yml skips every job on a push or scheduled event in a private repository. Push, pull request and dispatch events carry github.event.repository.private; a scheduled event carries no repository, so a visibility job looks it up via the API, on scheduled runs only. - A private repository tests Julia 1 only (its floor is in the local record); downgrade and pre run in public repositories only. Public repositories keep the min/1 matrix. - The cache rule is unchanged: the default branch saves, including a public repository's push to main; the schedule clause stays because a scheduled event carries no default_branch. - The self-test keeps push and gains the template's pull_request types and workflow_dispatch. - README: the private-repository rule, how a private cache is seeded, and the 60-minute timeout. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Review of PR 2: the job conditions now list what may run (pull_request, workflow_dispatch, a public repository's event, or a scheduled run the visibility job found public) instead of what to skip, so an event a private caller adds later cannot run paid jobs. The downgrade job's gate is the public test alone, which makes its old push clause and private check redundant. A private repository has no push runs, so every one of its runs now saves the Julia cache; the Runic job gains actions: write for the old-cache deletion that follows a save off the default branch, and loses delete-old-caches: false. The README says how each kind is seeded and that GitHub drops a cache unused for 7 days. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR implements admiral decision 0025 as Keith revised it. Actions minutes are free on public repositories, so they keep push and scheduled CI and the warm cache. Private repositories test on pull requests and by hand (
workflow_dispatch) only.The merge is a squash. The earlier commits on this branch removed the caller's triggers outright; 7942c1c and a5fabb7 replace them, so the net diff against main is what is described here.
Change
templates/CI.yml: unchanged. It is byte-identical to main, so no package copy has to change. GaussMLE's copy, from its commit c8d4a77, differs and needs reverting to match.julia-ci.yml, which events may run: the job conditions list what may run instead of what to skip. A job may run on:pull_request(not a draft);workflow_dispatch;github.event.repository.private;visibilityjob found public.A scheduled event carries no repository object, so the
visibilityjob looks the repository up withgh api, on scheduled runs only. An event a private caller adds later, such asmerge_group,releaseorrepository_dispatch, therefore runs nothing. No condition testsprivate == false, becausenull == falseis true.julia-ci.yml, per-job rules:1only; its floor is in the local record.downgradeandprerun in public repositories only. Downgrade's gate is the public test alone.min/1matrix and run on every event, as before.Caches:
JULIA_CACHE_SAVEgains|| github.event.repository.private.actions: writeand dropsdelete-old-caches: 'false'. After a save off the default branch, julia-actions/cache deletes the caches that save replaces, and that needs the permission.Superseded pull-request runs: the template's concurrency (
cancel-in-progressonpull_request) already cancels them. It is unchanged.selftest.yml: keepspush(this repository is public). It gains the template'spull_requesttypes, so a draft marked ready gets a real run. It also gainsworkflow_dispatch.README.md: states the private-repository rule, how each kind of repository's cache is seeded, and that GitHub drops a cache unused for 7 days. It also corrects the timeout to 60 minutes.Test
The Self-test is green on a5fabb7 for both
push(run 36450435050) andpull_request(run 36450441599).Core - Julia minandCore - Julia 1, QA,Core - lowest compatand Runic ran and passed.Visibilityandprewere skipped.diag/visibility, with the self-test. The branch and its caches are now deleted.github.event.repository.privateset totrueCore - Julia 1, QA and Runic only; downgrade and pre skipped; all three saved a cache (run 36450449804)'schedule'read as'workflow_dispatch'Visibilityfound the repository public; every job ran, including downgrade andpre(run 36450737114)Visibilityran; every other job skipped (run 36451009448)Notes for review
Core - Julia mincheck would wait on it forever. No lab repository is known to require it.v2. The change is backward-compatible for callers: nothing that passed can turn red, and no input changed. The release is the merge plus movingv2.🤖 Generated with Claude Code