Repository navigation
CI: Cut lint run time by caching dependencies and skipping the build - #3692
Merged
Merged
Conversation
The lint job spent about 2 minutes on setup for 21 seconds of actual linting. It installed svn via apt, ran a full composer install, linked node_modules from scratch, and ran a webpack build whose output nothing lints. Split linting into two parallel jobs (PHP, and JS/CSS) that share a composite action for the composer side. vendor/ is cached on composer.lock, so svn and composer install only run on a miss. node_modules is cached on yarn.lock and .nvmrc, so yarn install is a no-op on a hit. The build step is dropped, and a concurrency group cancels superseded runs on the same ref. Co-Authored-By: Claude Mythos 5.1 <noreply@anthropic.com>
…e hits Each lint workflow now only runs when files it checks (or its tooling) change, so PHP-only PRs skip the Node job entirely and vice versa. On an exact node_modules cache hit, yarn install is skipped outright: yarn 1 re-fetched and re-linked everything (82s) even with node_modules restored. The composer setup action no longer copies the repo-tools configs, since only the front-end job needs them. phpcs scans on 4 processes, matching the runner core count. Trunk runs are no longer cancelled by a newer push, so they always populate the caches that PR runs read from. Co-Authored-By: Claude Mythos 5.1 <noreply@anthropic.com>
All actions now reference the commit SHA of their latest release, with the version as a trailing comment, so a moved tag cannot change what runs. A Dependabot config keeps the pins current. Every checkout sets persist-credentials: false; the two workflows that push use the token the push action is given, not the one checkout would leave in .git. The assign-issue action stays on v2.0.0, pinned: v3 renames its inputs, adds a per-user assignment cap that cannot be disabled, and turns days_until_unassign 0 into 14, so moving to it is a behavior decision. The review-instructions job is gated at the job level, so a runner no longer starts for every issue comment. phpcs.xml.dist passes the I18n text domains as element nodes, the syntax PHPCS 4 requires. Co-Authored-By: Claude Mythos 5.1 <noreply@anthropic.com>
Dependabot scans the composite action's directory too, since "/" only covers workflows. apt-get update runs before the svn install on a cache miss, so a stale package index cannot fail the install. The PHP job calls composer directly instead of going through yarn. The concurrency comment says what GitHub actually does with a queued trunk run. Co-Authored-By: Claude Mythos 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The Lint job took ~2m09s, of which only 21s was linting (see this run). The rest was setup it didn't need:
wordpress-meta/*dev packages that phpcs excludes. The Ubuntu mirror served the 2.3 MB package at 25–43 kB/s, so this step ranged from 27s to 97s across runs.How
Follows the patterns in WordPress/wordpress.org, wporg-main-2022 and wporg-mu-plugins.
linters.yml:lint-php.ymlruns only when PHP,phpcs.xml.distor composer files change;lint-frontend.ymlruns only when JS/SCSS/CSS, package manifests, lint configs,yarn.lock,.nvmrcorcomposer.lockchange (the ESLint/Stylelint configs come fromwporg-repo-tools). A PHP-only PR never spins up Node, and a docs-only PR runs nothing..github/actions/setup-composerrestoresvendor/from a cache keyed oncomposer.lock. svn install,composer installand the git reset only run on a cache miss.composer.lockhas changed twice since 2024, so misses are rare.node_modulescache (root + three workspaces) keyed onyarn.lock+.nvmrc. On an exact hityarn installis skipped entirely. Yarn 1 does not trust a restored tree: with node_modules fully restored it still re-fetched and re-linked everything (82s), so skipping is the only way to benefit from the cache. Norestore-keys, since a stale node_modules is only safe on an exact match.<arg name="parallel" value="4" />inphpcs.xml.dist, matching the runner's core count. 10.7s → 5s. The I18ntext_domainlist is passed as<element>nodes, which removes the PHPCS 3.3 deprecation notice and is the syntax PHPCS 4 requires.yarn buildand the no-opyarn setup:toolsfrom the PHP side.timeout-minuteslowered to 10.Action pinning and hardening (all workflows)
uses:across.github/workflowsand.github/actionsis pinned to the commit SHA of its latest release, with the version as a trailing comment: checkout v7.0.1, setup-node v7.0.0, cache v6.1.0, github-script v9.0.0, setup-php 2.37.2, actions-js/push v1.6, create-or-update-comment v5.0.0. The inputs these workflows use are unchanged across those bumps.takanome-dev/assign-issue-actionis SHA-pinned but stays on v2.0.0. v3 renames every input, adds a per-user cap of 3 open assignments that cannot be disabled (0and empty both fall back to 3), turnsdays_until_unassign: 0into 14, and enables auto-suggestion replies, newcomer welcome text, reminders and block-after-unassign by default. Moving to it is a behavior decision for the team, not a mechanical upgrade..github/dependabot.ymlkeeps the pins current with one grouped weekly PR.persist-credentials: false. The lint jobs are read-only;build.ymlandi18n.ymlpush through the token they handactions-js/push, not the one checkout would leave in.git/config.review-instructions.ymlis gated at the job level, so a runner no longer starts for every issue comment.Measured on this PR
First run after a
composer.lockoryarn.lockchange is a cache miss and takes 1–2.5 minutes depending on apt mirror speed. That happens once per lockfile change on trunk; PR branches read trunk's caches.🤖 Generated with Claude Code