Skip to content

ci: add per-PR perf-regression detection (#144) - #221

Merged
Chris-Wolfgang merged 4 commits into
vNextfrom
ci/perf-regression
Jul 24, 2026
Merged

ci: add per-PR perf-regression detection (#144)#221
Chris-Wolfgang merged 4 commits into
vNextfrom
ci/perf-regression

Conversation

@Chris-Wolfgang

Copy link
Copy Markdown
Owner

Adds perf-regression.yaml — runs the BenchmarkDotNet suite on the PR and compares it against the gh-pages dev/bench baseline (published by benchmarks.yaml) via github-action-benchmark, commenting on regressions beyond the alert threshold.

Design (fleet-canonical, from D20-Dice)

  • Forward-looking per-PR signal — the [Maintenance] testing: Per-PR perf regression detection (BDN delta vs base branch) #144 ask. Compares against the gh-pages baseline (which already exists from benchmarks.yaml) rather than a base...HEAD double-run: simpler and proven.
  • Path-filtered to src/** + benchmarks/** (AC).
  • Report-only (fail-on-alert: false, auto-push: false) — BDN on shared runners is noisy; flip fail-on-alert with a noise-tuned threshold to gate. comment-on-alert replaces its own comment each push.
  • Single-TFM (net10.0); benchmarks project builds clean locally. Refreshed canonical action pins.

AC follow-up (not blocking)

  • Promote to a gate + perf-impact-acknowledged label override once CI noise floor is characterized.

Closes #144 when the vNext cycle merges to main.

🤖 Generated with Claude Code

Adds perf-regression.yaml: runs the BenchmarkDotNet suite on the PR and
compares against the gh-pages dev/bench baseline via github-action-benchmark,
commenting on regressions. Path-filtered to src/** and benchmarks/**;
report-only (fail-on-alert:false, auto-push:false) given shared-runner noise.
Ported from D20-Dice; canonical refreshed pins.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings July 22, 2026 00:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

The actions-audit (#143) was failing every open PR on findings that aren't
actionable:

- actionlint tripped on info-level shellcheck nits (SC2012 'use find not ls',
  SC2035 'use ./*glob*') in the canonical pr.yaml. Set SHELLCHECK_OPTS to
  --severity=warning so it gates on warning+ (real issues), not style nits.
- zizmor flagged error[dangerous-triggers] on pr.yaml's pull_request_target.
  That is the intentional *gated* pattern (runs from trusted main, checks out PR
  refs, re-fetches config from main). Added a documented dangerous-triggers
  ignore for pr.yaml to .zizmor.yml and wired --config .zizmor.yml into the
  zizmor step (it is not auto-discovered).
- Enabling the config also activates the existing unpinned-uses:hash-pin policy,
  which then flagged pr.yaml's three remaining tag-pinned actions
  (checkout@v7, setup-dotnet@v5, upload-sarif@v4). SHA-pinned them to the repo
  canonical commits (also fixing a real SHA-pin-convention gap).

Verified locally: zizmor --config at high severity reports no findings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Chris-Wolfgang and others added 2 commits July 22, 2026 20:38
Addresses the zizmor 'mismatched version comment' finding on #234: the pin
e0647621 is a real codeql-action commit (v4.37.2) but not the one the v4 tag
points to, so the hash-pin comment-match check flags it. Re-pin every
codeql-action reference (init / analyze / upload-sarif across pr, codeql,
actions-audit, scorecard, semgrep) to e4fba868 — the actual commit v4 resolves
to (verified via the GitHub tags API) — so each # v4 comment now matches.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants