diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3b27c130840..1b41578fa4d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,10 +1,8 @@ name: CI on: - push: - branches: - - main pull_request: + types: [opened, synchronize, reopened, ready_for_review] workflow_dispatch: env: @@ -13,14 +11,11 @@ env: concurrency: group: ci-${{ github.workflow }}-${{ github.ref }} - # Superseded pull request pushes are wasted work, but superseded main pushes - # are not: a cancelled run never reaches its post step, so it never saves a - # Turbo cache. Cancelling them let a burst of merges leave every pull request - # restoring from a main commit well behind HEAD. - cancel-in-progress: ${{ github.ref != 'refs/heads/main' }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} jobs: checks: + if: ${{ github.event_name != 'pull_request' || github.event.pull_request.draft == false }} name: Checks (ubuntu-latest, Node 22.x) runs-on: blacksmith-4vcpu-ubuntu-2404 timeout-minutes: 30 @@ -96,6 +91,7 @@ jobs: # suites are CPU-bound and previously fought each other (and the builds) for # the same 4 vCPUs, which made tests the critical path of every run. tests: + if: ${{ github.event_name != 'pull_request' || github.event.pull_request.draft == false }} name: Tests (${{ matrix.shard }}, ubuntu-latest, Node 22.x) runs-on: blacksmith-4vcpu-ubuntu-2404 timeout-minutes: 30 @@ -149,6 +145,7 @@ jobs: # evicted each other. `smoke:tarball` is itself `"cache": false`, so only its # build dependencies could ever have been reused. package-smoke: + if: ${{ github.event_name != 'pull_request' || github.event.pull_request.draft == false }} name: Package Smoke (${{ matrix.os }}, Node ${{ matrix.node-version }}) runs-on: ${{ matrix.os }} timeout-minutes: 45 @@ -229,3 +226,35 @@ jobs: - name: Smoke bb-app tarball run: pnpm exec turbo run smoke:tarball --filter=bb-app --cache-dir=.turbo/cache --output-logs=new-only + + required: + name: CI required + if: ${{ always() }} + needs: [checks, tests, package-smoke, node-compat-smoke] + runs-on: ubuntu-latest + timeout-minutes: 2 + permissions: {} + steps: + - name: Require the applicable validation jobs + env: + IS_DRAFT: ${{ github.event.pull_request.draft == true }} + EVENT_NAME: ${{ github.event_name }} + CHECKS_RESULT: ${{ needs.checks.result }} + TESTS_RESULT: ${{ needs.tests.result }} + PACKAGE_RESULT: ${{ needs.package-smoke.result }} + COMPAT_RESULT: ${{ needs.node-compat-smoke.result }} + run: | + if [[ "$IS_DRAFT" == "true" ]]; then + echo "::error::Draft PRs do not run paid validation. Mark ready for review to run the complete PR suite." + exit 1 + fi + for result in "$CHECKS_RESULT" "$TESTS_RESULT" "$PACKAGE_RESULT"; do + if [[ "$result" != "success" ]]; then + echo "::error::Required validation did not succeed: $result" + exit 1 + fi + done + if [[ "$EVENT_NAME" != "pull_request" && "$COMPAT_RESULT" != "success" ]]; then + echo "::error::Manually requested compatibility validation did not succeed: $COMPAT_RESULT" + exit 1 + fi diff --git a/.github/workflows/marketplace-v2-live.yml b/.github/workflows/marketplace-v2-live.yml index a27638ad17d..7cd5d580467 100644 --- a/.github/workflows/marketplace-v2-live.yml +++ b/.github/workflows/marketplace-v2-live.yml @@ -1,13 +1,15 @@ name: Marketplace v2 live validation on: - schedule: - - cron: "27 4 * * *" workflow_dispatch: permissions: contents: read +concurrency: + group: marketplace-v2-live-${{ github.ref }} + cancel-in-progress: true + jobs: validate: name: Parse the live v2 marketplace diff --git a/.github/workflows/mobile-e2e.yml b/.github/workflows/mobile-e2e.yml index bb2af6f1070..df7fbf7aab5 100644 --- a/.github/workflows/mobile-e2e.yml +++ b/.github/workflows/mobile-e2e.yml @@ -2,7 +2,7 @@ name: Mobile E2E # iOS simulator end-to-end run for apps/mobile (Maestro flows against the # integration harness backend). Label-gated on pull requests (`mobile-e2e`), -# manual, and nightly — the macOS runner is slow and paid, and the Linux +# and manual — the macOS runner is slow and paid, and the Linux # `checks` / `tests` jobs in ci.yml already typecheck, lint and unit-test # @bb/mobile on every pull request (turbo picks the package up; the # `packages` test shard covers it). @@ -15,16 +15,13 @@ name: Mobile E2E # exposes the e2e-only affordances, exactly like the local Metro setup. on: pull_request: - types: [opened, synchronize, reopened, labeled] + types: [opened, synchronize, reopened, ready_for_review, labeled] workflow_dispatch: inputs: flows: description: Space-separated flow names (default = the CI set; see apps/mobile/e2e/scripts/ci-run-flows.sh) required: false default: "" - schedule: - # Nightly, 09:17 UTC (runs on the default branch). - - cron: "17 9 * * *" permissions: contents: read @@ -55,7 +52,9 @@ jobs: name: iOS simulator flows if: >- github.event_name != 'pull_request' || - contains(github.event.pull_request.labels.*.name, 'mobile-e2e') + (github.event.pull_request.draft == false && + contains(github.event.pull_request.labels.*.name, 'mobile-e2e') && + (github.event.action != 'labeled' || github.event.label.name == 'mobile-e2e')) runs-on: blacksmith-6vcpu-macos-15 timeout-minutes: 90 diff --git a/.github/workflows/publish-bb-app.yml b/.github/workflows/publish-bb-app.yml index dd88485ffa0..c9cc9d24ce3 100644 --- a/.github/workflows/publish-bb-app.yml +++ b/.github/workflows/publish-bb-app.yml @@ -3,9 +3,6 @@ name: Publish bb-app on: - schedule: - - cron: "0 3 * * *" - timezone: "America/Los_Angeles" workflow_dispatch: inputs: npm_tag: diff --git a/.github/workflows/version-lockstep.yml b/.github/workflows/version-lockstep.yml index 410c336554a..b793fa1203e 100644 --- a/.github/workflows/version-lockstep.yml +++ b/.github/workflows/version-lockstep.yml @@ -1,22 +1,27 @@ name: Version Lockstep on: - push: pull_request: workflow_dispatch: permissions: contents: read +concurrency: + group: version-lockstep-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + jobs: check: - name: Check bb-app and desktop versions - runs-on: blacksmith-4vcpu-ubuntu-2404 + name: Version integrity + runs-on: ubuntu-latest timeout-minutes: 5 steps: - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + fetch-depth: 0 - name: Set up Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 @@ -26,22 +31,5 @@ jobs: - name: Check version lockstep run: node .github/workflows/check-version-lockstep.mjs - plugin-sdk: - name: Check plugin SDK version bump - runs-on: blacksmith-4vcpu-ubuntu-2404 - timeout-minutes: 5 - - steps: - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - # The check diffs against the merge base, which a shallow clone lacks. - fetch-depth: 0 - - - name: Set up Node.js - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 - with: - node-version: 22.x - - name: Check plugin SDK version bump run: node .github/workflows/check-plugin-sdk-version.mjs