Repository navigation
chore(OmniRoute): add concurrency blocks to 6 remaining workflows #8
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,5 +1,9 @@ | ||
| name: Lock released branch | ||
|
|
||
| concurrency: | ||
| group: ${{ github.workflow }}-${{ github.ref }} | ||
| cancel-in-progress: true | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Security workflow can be cancelled mid-execution by dispatchMedium Severity This security-critical workflow locks release branches to prevent post-release commits. With Reviewed by Cursor Bugbot for commit d20ed5e. Configure here. |
||
|
|
||
| # Two responsibilities (defense in depth — Hard Rule #18 enforcement): | ||
| # | ||
| # 1. `on: release: published` — when a GitHub Release publishes tag v3.X.Y, | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,4 +1,7 @@ | ||
| name: Publish to npm | ||
| concurrency: | ||
| group: ${{ github.workflow }}-${{ github.ref }} | ||
| cancel-in-progress: true | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Reusable workflow concurrency causes deadlock when called via workflow_callHigh Severity
Additional Locations (1)Reviewed by Cursor Bugbot for commit d20ed5e. Configure here. |
||
|
|
||
| on: | ||
| # 'released' (not 'published') so editing/re-publishing old releases does NOT | ||
|
|
@@ -39,8 +42,8 @@ | |
|
|
||
| permissions: | ||
| contents: read | ||
| id-token: write | ||
|
Check warning on line 45 in .github/workflows/npm-publish.yml
|
||
| packages: write | ||
|
Check warning on line 46 in .github/workflows/npm-publish.yml
|
||
|
|
||
| env: | ||
| NPM_PUBLISH_NODE_VERSION: "24" | ||
|
|
||


There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Concurrency group cancels all Claude runs across PRs
High Severity
For
issue_commentandpull_request_review_commentevents,github.refis always the default branch (e.g.,refs/heads/main), not the PR branch. This means every Claude Code invocation shares the same concurrency group (Claude Code-refs/heads/main). Withcancel-in-progress: true, any new comment on any issue or PR — even one that doesn't mention@claude— triggers the workflow, joins the shared group, and cancels the in-progress run before the job-levelifcondition filtering for@claudeis evaluated. This effectively makes Claude unable to complete any task if comments arrive on other issues/PRs.Reviewed by Cursor Bugbot for commit d20ed5e. Configure here.