From 3bc7bc50d157b2810264dcfb059ab9fc29e86ab8 Mon Sep 17 00:00:00 2001 From: Matthew Goodwin Date: Thu, 24 Sep 2026 19:07:22 -0500 Subject: [PATCH 1/2] release.yml: cache fetch-deps downloads across runs An upstream outage (gitlab.com 503s on glab) failed the v2.11.0 tag run before the build. Downloads now restore from actions/cache keyed on deps.lock, save straight after the fetch, and drop files deps.lock no longer pins. fetch-deps still re-hashes every cached file. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_017A8MG18FT27cFsiEWiKGHD --- .github/workflows/release.yml | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 903bd2946..9ca8beb55 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -143,6 +143,19 @@ jobs: run: bun scripts/bench-startup.ts continue-on-error: true + # An upstream outage (gitlab.com 503s on glab) failed a v2.11.0 tag run + # before the build, so downloads are cached across runs. fetch-deps + # re-hashes every cached file against deps.lock, so a bad entry fails + # the run rather than shipping. A tag run restores what the rehearsal + # dispatch on main saved. + - name: Restore dependency downloads + id: deps-cache + uses: actions/cache/restore@v4 + with: + path: ~/Library/Caches/mattstack-deps + key: mattstack-deps-${{ runner.os }}-${{ hashFiles('rt-tray/deps.lock') }} + restore-keys: mattstack-deps-${{ runner.os }}- + - name: Fetch bundled dependencies # GH_TOKEN: console and chat are private repos, so their release # assets refuse bare curl; fetch-deps falls back to gh, which needs @@ -151,6 +164,25 @@ jobs: GH_TOKEN: ${{ secrets.MATTSTACK_RELEASE_TOKEN }} run: scripts/fetch-deps.sh arm64 + # Saved straight after the fetch, so a run that fails later (notarize, + # clean room) still keeps its downloads. Files deps.lock no longer pins + # are dropped first, or a restore-keys hit would carry them forever. + - name: Prune dependency downloads + if: steps.deps-cache.outputs.cache-hit != 'true' + run: | + keep="$(jq -r '.tools[].sha256' rt-tray/deps.lock)" + for f in "$HOME"/Library/Caches/mattstack-deps/*; do + [ -e "$f" ] || continue + grep -qxF "$(basename "$f" | cut -d- -f1)" <<<"$keep" || rm -f "$f" + done + + - name: Save dependency downloads + uses: actions/cache/save@v4 + if: steps.deps-cache.outputs.cache-hit != 'true' + with: + path: ~/Library/Caches/mattstack-deps + key: mattstack-deps-${{ runner.os }}-${{ hashFiles('rt-tray/deps.lock') }} + # bunx vsce package runs a Node CLI under Bun's Node-compat shim, which # this repo has already hit drift on (bunx --bun wrangler silently # no-ops); pin the runtime instead of trusting the runner image's From 5634aa29fc9606d14ef544772efc7e69a046c9cf Mon Sep 17 00:00:00 2001 From: Matthew Goodwin Date: Thu, 24 Sep 2026 20:14:24 -0500 Subject: [PATCH 2/2] release.yml: deps cache comment states constraints, names the clear command Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_017A8MG18FT27cFsiEWiKGHD --- .github/workflows/release.yml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 9ca8beb55..da47311ec 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -143,11 +143,11 @@ jobs: run: bun scripts/bench-startup.ts continue-on-error: true - # An upstream outage (gitlab.com 503s on glab) failed a v2.11.0 tag run - # before the build, so downloads are cached across runs. fetch-deps - # re-hashes every cached file against deps.lock, so a bad entry fails - # the run rather than shipping. A tag run restores what the rehearsal - # dispatch on main saved. + # fetch-deps re-hashes every cached file against deps.lock, so a bad + # entry fails the run rather than shipping; it also fails every later + # run on the same key, so clear it with + # `gh cache delete mattstack-deps-macOS-`. A tag run can only + # restore what the rehearsal dispatch on main saved. - name: Restore dependency downloads id: deps-cache uses: actions/cache/restore@v4