Skip to content

release.yml: cache fetch-deps downloads across runs - #432

Merged
m4ttheweric merged 2 commits into
mainfrom
ci-deps-cache
Sep 25, 2026
Merged

m4ttheweric merged 2 commits into
mainfrom
ci-deps-cache

Conversation

@m4ttheweric

Copy link
Copy Markdown
Collaborator

The v2.11.0 tag run failed in scripts/fetch-deps.sh on a gitlab.com 503 for glab, before anything was built. CI runners start with an empty download cache, so every release depends on every upstream host being up at that moment.

What changed

Cache (.github/workflows/release.yml, around "Fetch bundled dependencies")

  • actions/cache/restore loads ~/Library/Caches/mattstack-deps (fetch-deps' own default path), keyed on the rt-tray/deps.lock hash, with a prefix fallback.
  • actions/cache/save runs straight after the fetch, so a run that fails later still keeps its downloads.
  • A prune step first drops cached files whose sha deps.lock no longer pins, so prefix restores don't pile up old versions.

Safety

  • fetch-deps already re-hashes every cached file against deps.lock and fails on a mismatch, so a bad cache entry stops the run instead of shipping.
  • A tag run can only restore caches saved on main. The rehearsal dispatch on main saves the cache that the tag run then restores.

Verification

  • actionlint reports nothing on the new steps (its findings are all in older steps).
  • A dry run of the prune logic against this Mac's cache keeps the 19 cached current pins and drops 22 superseded files.
  • The first real test is the next release rehearsal on main: expect a cache miss and save, then a hit on the tag run.

🤖 Generated with Claude Code

https://claude.ai/code/session_017A8MG18FT27cFsiEWiKGHD

An upstream outage (gitlab.com 503s on glab) failed the v2.11.0 tag run
before the build. Downloads now restore from actions/cache keyed on
deps.lock, save straight after the fetch, and drop files deps.lock no
longer pins. fetch-deps still re-hashes every cached file.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017A8MG18FT27cFsiEWiKGHD
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 28 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 84 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 34d0cc65-d0d1-49ca-9ee0-dc73842e6bfe

📥 Commits

Reviewing files that changed from the base of the PR and between b983acc and 5634aa2.

📒 Files selected for processing (1)
  • .github/workflows/release.yml

Comment @coderabbitai help to get the list of available commands.

…ommand

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017A8MG18FT27cFsiEWiKGHD
@m4ttheweric

m4ttheweric commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator Author

Review of record (Opus; CodeRabbit rate limited). No blockers and nothing should-fix.

Checked and correct

  • A main dispatch saves into the default-branch scope and a tag run restores it. PRs and forks can't write it, since release.yml has no pull_request trigger.
  • A cache hit never skips verification: fetch() re-hashes every file, and every bundled row requires a 64-hex sha256.
  • The cache-hit != 'true' gating is right for both a miss and a partial hit.
  • The prune's cut -d- -f1 matches the real <sha>-<name> naming.
  • ~ and $HOME resolve to the same directory on macos-15.
  • No new secret exposure.

Nits

  • Applied in 5634aa2: the comment dropped its incident history and now names gh cache delete as the fix if a cached entry ever goes bad. A bad entry would fail every run on that key until it's cleared.
  • Not applied: pruning .part files. A .part can't reach a save, because fetch-deps renames it on success and deletes it on failure, and a failed fetch stops the job before save.

@m4ttheweric
m4ttheweric merged commit c9fe81c into main Sep 25, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant