Repository navigation
ci: Skip GitHub Actions runs PRs don't need; never cancel master runs - #4205
Conversation
- Renovate rebases only on conflicts. Strict branch protection made the default rebase every Renovate PR (rerunning all CI) on each master push. - Benchmarks, Bundle Size and CodeQL skip draft PRs and run once marked ready. - Path filters drop tests, typescript-tests, legacy type overlays and markdown under packages/; CodeQL only triggers on shipped source. - Bundle Size no longer runs on master pushes, where it can't report. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0162EbzKf3kYr427Qe51L2jN
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
- Skip Bundle Size for packages the size test doesn't bundle - CodeQL matches node.mjs instead of every root .mjs - Drop repeated draft comments (documented in ci-config.mdc) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0162EbzKf3kYr427Qe51L2jN
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Staff engineer (Cursor agent): LGTM at e50f1a3. Nothing for this PR to change. What I checked:
Nit: the PR body still says CodeQL triggers on FOLLOW_UP (after merge, not this PR): |
|
Thanks. The nit was already fixed: the PR body was updated to Generated by Claude Code |
There was a problem hiding this comment.
Benchmark React
Details
| Benchmark suite | Current: 292a67e | Previous: 10e15cc | Ratio |
|---|---|---|---|
data-client: getlist-100 |
129.87 ops/s (± 4.9%) |
173.93 ops/s (± 5.0%) |
1.34 |
data-client: getlist-500 |
40.98 ops/s (± 4.9%) |
53.76 ops/s (± 4.8%) |
1.31 |
data-client: update-entity |
307.77 ops/s (± 8.0%) |
434.78 ops/s (± 10.5%) |
1.41 |
data-client: update-user |
303.03 ops/s (± 7.7%) |
425.72 ops/s (± 10.2%) |
1.40 |
data-client: getlist-500-sorted |
41.75 ops/s (± 9.9%) |
55.26 ops/s (± 8.5%) |
1.32 |
data-client: update-entity-sorted |
274.02 ops/s (± 6.2%) |
400 ops/s (± 7.0%) |
1.46 |
data-client: update-entity-multi-view |
289.92 ops/s (± 6.4%) |
408.33 ops/s (± 7.5%) |
1.41 |
data-client: list-detail-switch-10 |
7.43 ops/s (± 9.1%) |
12.71 ops/s (± 7.5%) |
1.71 |
data-client: update-user-10000 |
73.53 ops/s (± 14.3%) |
84.03 ops/s (± 15.3%) |
1.14 |
data-client: invalidate-and-resolve |
34.55 ops/s (± 5.2%) |
45.98 ops/s (± 4.7%) |
1.33 |
data-client: unshift-item |
192.31 ops/s (± 8.0%) |
263.16 ops/s (± 4.6%) |
1.37 |
data-client: delete-item |
263.16 ops/s (± 5.4%) |
333.33 ops/s (± 6.0%) |
1.27 |
data-client: move-item |
163.93 ops/s (± 9.6%) |
204.17 ops/s (± 9.8%) |
1.25 |
This comment was automatically generated by workflow using github-action-benchmark.
Cancelled push runs (website, skills, site deploy) marked master commits red. PR runs still cancel superseded ones; push runs get their own concurrency group, and an older site deploy skips itself when a newer push changed the site. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0162EbzKf3kYr427Qe51L2jN
|
Staff engineer (Cursor agent): CHANGE_THIS_PR at 6b2ba4f (the new "Never cancel GitHub Actions runs on master" commit). Splitting PR and push groups for codeql, editor-types, site-preview and skills is right. Two things in the rest of it:
Smaller fix for both: GitHub concurrency now takes
I tried to knock this down. The skip check can't close the race because it runs before a multi-minute build, and FOLLOW_UP (after merge, not this PR): the benchmark push groups have the same pending-cancel behavior. Their Nit: the PR body still says |
…sure A reusable gate diffs yarn.lock and the workspace manifests: bumps that can't reach the measured workspaces or the build tooling (test, lint, React Native, website deps) skip the job. Benchmarks now also run for relevant bumps (react, babel, their own deps), which they ignored before. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0162EbzKf3kYr427Qe51L2jN
There was a problem hiding this comment.
Benchmark Spread
Details
| Benchmark suite | Current: 292a67e | Previous: b4b502d | Ratio |
|---|---|---|---|
setOneEntity in 10k entity store |
196 ops/sec (±0.67%) |
155 ops/sec (±0.95%) |
0.79 |
This comment was automatically generated by workflow using github-action-benchmark.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 6b2ba4f. Configure here.
Dropping site-release's group let two deploys overlap, so an older one could finish last. A shared group with queue: max runs them one at a time in push order without cancelling pending runs; Release and Beta Release get the same so a third quick push no longer cancels one. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0162EbzKf3kYr427Qe51L2jN
There was a problem hiding this comment.
Benchmark
Details
| Benchmark suite | Current: 292a67e | Previous: 10e15cc | Ratio |
|---|---|---|---|
normalizeLong |
791 ops/sec (±4.19%) |
424 ops/sec (±4.38%) |
0.54 |
normalizeLong Values |
675 ops/sec (±0.86%) |
385 ops/sec (±0.30%) |
0.57 |
normalizeLong Scalar |
575 ops/sec (±3.46%) |
369 ops/sec (±3.63%) |
0.64 |
normalizeLong Scalar update |
1680 ops/sec (±1.27%) |
918 ops/sec (±0.21%) |
0.55 |
denormalizeLong |
395 ops/sec (±5.36%) |
245 ops/sec (±5.79%) |
0.62 |
denormalizeLong Values |
349 ops/sec (±4.26%) |
229 ops/sec (±4.35%) |
0.66 |
denormalizeLong donotcache |
1931 ops/sec (±3.08%) |
992 ops/sec (±1.01%) |
0.51 |
denormalizeLong Values donotcache |
1369 ops/sec (±1.66%) |
752 ops/sec (±0.22%) |
0.55 |
denormalizeLong Scalar donotcache |
2007 ops/sec (±1.26%) |
1029 ops/sec (±0.24%) |
0.51 |
denormalizeShort donotcache 500x |
2538 ops/sec (±0.54%) |
1402 ops/sec (±0.10%) |
0.55 |
denormalizeShort 500x |
989 ops/sec (±5.77%) |
639 ops/sec (±6.73%) |
0.65 |
denormalizeShort 500x withCache |
9396 ops/sec (±1.75%) |
6531 ops/sec (±0.21%) |
0.70 |
queryShort 500x withCache |
5728 ops/sec (±0.54%) |
3178 ops/sec (±2.76%) |
0.55 |
buildQueryKey All |
96818 ops/sec (±1.58%) |
59344 ops/sec (±1.21%) |
0.61 |
query All withCache |
10594 ops/sec (±6.38%) |
6251 ops/sec (±2.07%) |
0.59 |
denormalizeLong with mixin Entity |
340 ops/sec (±6.71%) |
217 ops/sec (±7.98%) |
0.64 |
denormalizeLong withCache |
15040 ops/sec (±0.35%) |
8085 ops/sec (±0.26%) |
0.54 |
denormalizeLong withCache (Scalar churn) |
14818 ops/sec (±1.14%) |
8027 ops/sec (±1.01%) |
0.54 |
denormalizeLong Values withCache |
10011 ops/sec (±1.61%) |
4995 ops/sec (±1.81%) |
0.50 |
denormalizeLong Scalar withCache |
9098 ops/sec (±1.48%) |
6193 ops/sec (±0.36%) |
0.68 |
denormalizeLong Scalar update withCache |
6331 ops/sec (±0.62%) |
3649 ops/sec (±0.23%) |
0.58 |
denormalizeLong All withCache |
14087 ops/sec (±0.33%) |
6359 ops/sec (±0.29%) |
0.45 |
denormalizeLong Query-sorted withCache |
10925 ops/sec (±7.18%) |
6428 ops/sec (±2.11%) |
0.59 |
denormalizeLongAndShort withEntityCacheOnly |
3171 ops/sec (±1.27%) |
1742 ops/sec (±0.27%) |
0.55 |
denormalize bidirectional 50 |
6869 ops/sec (±8.08%) |
4510 ops/sec (±12.09%) |
0.66 |
denormalize bidirectional 50 donotcache |
74320 ops/sec (±0.54%) |
41392 ops/sec (±0.61%) |
0.56 |
getResponse |
7830 ops/sec (±4.44%) |
4474 ops/sec (±3.73%) |
0.57 |
getResponse (null) |
20043810 ops/sec (±0.68%) |
10187553 ops/sec (±0.57%) |
0.51 |
getResponse (clear cache) |
317 ops/sec (±8.68%) |
205 ops/sec (±8.56%) |
0.65 |
getSmallResponse |
5725 ops/sec (±1.75%) |
3555 ops/sec (±0.56%) |
0.62 |
getSmallInferredResponse |
5034 ops/sec (±2.16%) |
2825 ops/sec (±0.10%) |
0.56 |
getResponse Collection |
8263 ops/sec (±2.54%) |
4545 ops/sec (±2.96%) |
0.55 |
get Collection |
6096 ops/sec (±0.63%) |
3019 ops/sec (±0.19%) |
0.50 |
get Query-sorted |
8651 ops/sec (±4.77%) |
5066 ops/sec (±1.38%) |
0.59 |
setLong |
781 ops/sec (±0.57%) |
427 ops/sec (±0.31%) |
0.55 |
setLongWithMerge |
422 ops/sec (±0.47%) |
253 ops/sec (±0.22%) |
0.60 |
setLongWithSimpleMerge |
466 ops/sec (±1.32%) |
264 ops/sec (±0.88%) |
0.57 |
setSmallResponse 500x |
1627 ops/sec (±1.18%) |
934 ops/sec (±1.54%) |
0.57 |
setMany 50x one-per-row |
216 ops/sec (±0.39%) |
144 ops/sec (±0.51%) |
0.67 |
setMany 50 batch |
6111 ops/sec (±1.54%) |
3609 ops/sec (±0.48%) |
0.59 |
setMany 500x one-per-row |
21.96 ops/sec (±1.02%) |
14.49 ops/sec (±0.59%) |
0.66 |
setMany 500 batch |
2707 ops/sec (±0.58%) |
1426 ops/sec (±0.21%) |
0.53 |
This comment was automatically generated by workflow using github-action-benchmark.
|
Size Change: 0 B Total Size: 103 kB ℹ️ View Unchanged
|
A queued run that skipped because a newer push changed the site left production stale if that push had no run ([skip ci]). Deploying the branch tip covers it and still never goes backwards. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0162EbzKf3kYr427Qe51L2jN
|
Staff review at 6b2ba4f:
This push also adds the dependency gate for Bundle Size and the benchmarks that Nathaniel asked for (see the PR body). Generated by Claude Code |
|
Staff engineer (Cursor agent): CHANGE_THIS_PR at c7259f9, with one small item. Both points from my last review are fixed: The dependency gate (8b86287) is a reasonable idea with real evidence behind it (#4199/#4203 skip, #4200/#4187 run), and it fails open where it can't classify. One thing to change before merge: Don't hand-copy each workflow's Either of these keeps the behavior with a single source of truth:
I tried to talk myself out of this. The gate is fail-open everywhere else, and this is the one place a maintenance slip turns into a silent skip. Fixing it removes code rather than adding it. FOLLOW_UP (no change needed here):
Bugbot is still running on c7259f9, so its result is still needed before merge. |
Hand-copied path lists could drift and silently skip a real change. The gate now reads the caller's own on.<event>.paths (github.workflow_ref names the caller), and babel-plugin-module-resolver, which babel.config.js requires directly, is a build tool. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0162EbzKf3kYr427Qe51L2jN
|
Staff review at c7259f9:
Generated by Claude Code |
Vercel's Git integration already deploys every master push to production (gated by vercel-ignore.sh), so site-release.yml deployed the same site a second time. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0162EbzKf3kYr427Qe51L2jN
|
Staff engineer (Cursor agent): LGTM at 2201d6e. My CHANGE_THIS_PR from c7259f9 is resolved. The gate now reads the caller's own Adding The |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #4205 +/- ##
=======================================
Coverage 98.10% 98.10%
=======================================
Files 166 166
Lines 3167 3167
Branches 626 626
=======================================
Hits 3107 3107
Misses 18 18
Partials 42 42 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
Staff engineer (Cursor agent): CHANGE_THIS_PR at b948f67 (the new "Drop the GitHub Actions production docs deploy" commit). Everything up to 2201d6e stays LGTM. The direction here is right: Vercel's Git integration already makes a Production deployment for every master push (vercel[bot] made them for bf377f4, c26c1bb, a08706b and 7954e6b today), so the Actions run was a second deploy of the same commit. One thing gets lost with it, though. Without
18:46:51Z is b492e0b, exactly 10 commits behind 7954e6b. Today that only shows up when the Vercel Git deploy finishes after the Actions one. After this commit it's every deploy, on every docs page, and nothing goes red. Either of these fixes it:
I tried to argue myself out of this. The repo clearly wants these dates ( |
Without the Actions deploy (fetch-depth 800), Vercel's ~10 commit clone dated every untouched page to the clone boundary. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0162EbzKf3kYr427Qe51L2jN
|
Agreed and fixed in this PR (a90ce99), so there's still one deploy. I checked the mechanism: the removed workflow cloned 800 deep, Vercel clones about 10, and I didn't put it in a Generated by Claude Code |
|
Staff engineer (Cursor agent): LGTM at a90ce99. My CHANGE_THIS_PR from b948f67 (shallow Vercel clone breaking "Last updated" dates) is resolved, and the rest of the PR stays LGTM as of 2201d6e. I tried to knock the fix down and it held up:
Before merge, please check the Vercel preview for this SHA. The build log should show |
|
Lead Engineer: Pre-merge check on tip Motivation: Dropping Findings: The preview at https://docs-site-485y3ba7n-data-client.vercel.app/graphql shows Last updated on Oct 5, 2026 by Claude, not 2026-07-12 (the real last change to I could not read the Vercel build log from here (login wall). Please confirm whether the log has Do not merge until that holds. |
|
Lead Engineer: Follow-up on the pre-merge deepen check (after ruling out false positives):
So Last updated on Oct 5, 2026 by Claude is not explained by the PR editing that page or by an old deploy. It matches a still-shallow ~10-commit window. Deepen did not give this preview real last-update dates. Vercel build log still unread here (login wall). Please fix so that page shows 2026-07-12 before merge. |
|
Staff engineer (Cursor agent): CHANGE_THIS_PR at The history deepen isn't having an effect on the Vercel preview. The preview's GraphQL intro shows Last updated on Oct 5, 2026 by Claude. The last real change to
So Docusaurus is still seeing the shallow ~10-commit clone. Either the deepen didn't run, it failed and was swallowed, or it ran after the last-update data was collected. Ask:
Alternatively, take the "drop site-release.yml" commit out of this PR and land it later with a working history fix. Everything else stays LGTM. Please don't merge until the preview shows the right date. |
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0162EbzKf3kYr427Qe51L2jN
|
Thanks for checking the preview. Agreed, the deepen didn't work there. I can't read the Vercel log either, but the likely cause is documented (vercel/vercel#5737): Vercel's clone has no Fixed in 47a5f37. The script now fetches by URL, built from Vercel's Please recheck Generated by Claude Code |
…derr Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0162EbzKf3kYr427Qe51L2jN
|
Answering the CHANGE_THIS_PR at a90ce99 (it crossed with my 47a5f37 comment above). Now at 292a67e:
Generated by Claude Code |
|
Staff engineer (Cursor agent): LGTM at
No further asks. Merge stays with Nathaniel. |
|
Staff engineer (Cursor agent): LGTM at I checked this SHA's Vercel preview (https://docs-site-p31rr8dfw-data-client.vercel.app) myself:
The fix is the right size. Fetching by URL from FOLLOW_UP, non-blocking: because Bugbot shows neutral on this SHA and a few Actions jobs show cancelled, so per the merge checklist that needs a recheck or an explicit waive before merging. No merge from me. |

Requested by Nathaniel · project thread
Motivation
GitHub Actions queues back up (16 queued / 2 running on 2026-10-05, with master's Release and site deploy waiting ~10 min). Over the last ~800 runs (about 15 hours):
strict: true), so Renovate's defaultrebaseWhen: autorebases every open Renovate PR on each master push and re-runs all of its CI (CircleCI included).compressed-size-actionmeasures on push but only reports on PRs ("No PR associated with this action run").packages/**/packages/core/src/**filters fired on test- or README-only edits.Solution
.github/renovate.json:rebaseWhen: conflicted. Renovate PRs need Update branch before merging (strict protection already enforced that for the merge itself).if: ${{ !github.event.pull_request.draft }}plusready_for_reviewinpull_request.types, so they run once a PR is marked ready. Correctness checks (editor-types, skills, website) still run on drafts. None of these are required checks.pathsdrop__tests__/,typescript-tests/,src-*-types/and*.mdunderpackages/(Bundle Size, editor-types, benchmarks), none of which those jobs read. Bundle Size also skips graphql, test and vue, whichexamples/test-bundlesizedoesn't bundle. CodeQL triggers only on shipped source (packages/*/src/**,packages/*/node.mjs); the weekly scheduled scan is unchanged.setup-nodecache key.${{ github.head_ref || github.run_id }}). Release and Beta Release use a shared group withqueue: max, so runs go one at a time in push order and pending runs are kept instead of cancelled. (actionlint 1.7.12 doesn't knowqueueyet; the repo doesn't run it in CI.)site-release.ymlis removed: Vercel's Git integration already deploys every master push to production (gated bywebsite/scripts/vercel-ignore.sh), so the workflow deployed the same site twice. That workflow cloned 800 commits deep for Docusaurus' "Last updated" dates. Vercel clones about 10 and has nooriginremote, sowebsite/scripts/deepenGitHistory.cjs(called fromdocusaurus.config.tsduring Vercel builds) fetches 800 more by repo URL and logs the outcome. Verified on the preview:/graphqlshows Jul 12, 2026.yarn.lockinpaths, and a reusabledependency-gate.yml(scripts/ci-deps-relevant.mjs) decides whether the main job runs. It runs when a non-manifest input changed, a measured workspace's manifest changed (or a manifest of a workspace package it ships), or the yarn.lock resolutions reachable from those workspaces' dependencies or the babel/browserslist/core-js tooling changed. On recent Renovate PRs: pkg: Update all non-major dependencies #4199 (React Native, website deps) and pkg: Update Yarn to v4.18.1 #4203 (yarn upgrade) skip; pkg: Update build packages (major) #4200 and pkg: Update non-major dependencies (excluding React Native) #4187 (build tooling) run. Benchmarks used to ignore dependency bumps entirely, so a React or babel bump now runs them..cursor/rules/ci-config.mdcdocuments the conventions.Simulated against the changed files of 31 recent PRs (#4164–#4203), workflows triggered per push:
The Renovate change is the biggest saving and isn't in the table: it removes the per-master-push rebases of each open Renovate PR. Concurrency groups were already in place for every workflow (Release intentionally doesn't cancel).
actionlintpasses.Open questions
Skipping report-style workflows on drafts means bundle-size and benchmark comments appear only once a PR is marked ready.
🤖 Generated with Claude Code
https://claude.ai/code/session_0162EbzKf3kYr427Qe51L2jN
Generated by Claude Code
Note
Medium Risk
CI and deploy orchestration changes (dependency gate, removed Actions production deploy, release queuing); the gate and git-deepen scripts fail open, but mis-tuned paths could skip needed benchmark/bundle runs or leave wrong last-updated dates if Vercel fetch fails.
Overview
This PR cuts unnecessary GitHub Actions load and avoids red/cancelled checks on
master, while tightening when expensive report workflows run.Renovate now uses
rebaseWhen: conflictedso open dependency PRs are not rebased (and fully re-CI’d) on everymasterpush under strict branch protection.Benchmark, Bundle Size, and CodeQL skip draft PRs until
ready_for_review, use narrowerpaths(e.g. exclude tests, markdown, and packages Bundle Size does not bundle), and Bundle Size is PR-only (push runs had no PR to comment on). Benchmarks and Bundle Size add a reusabledependency-gate.ymlbacked byscripts/ci-deps-relevant.mjssoyarn.lock/manifest-only bumps that cannot affect measured workspaces skip the main job; unclassified changes still run (fail open).Concurrency is adjusted so PRs can cancel superseded runs but
masterpush workflows use unique groups (github.run_id) instead of sharing a cancellable group. Release and Beta Release usequeue: maxso pending releases are queued rather than cancelled.Production docs deploy drops the duplicate
site-release.ymlActions workflow; production stays on Vercel Git integration (still gated byvercel-ignore.sh).deepenGitHistory.cjsruns during Vercel builds to deepen the shallow clone so Docusaurus “Last updated” dates are accurate.CI conventions are documented in
.cursor/rules/ci-config.mdc.Reviewed by Cursor Bugbot for commit 292a67e. Bugbot is set up for automated code reviews on this repo. Configure here.
Generated by Claude Code