Skip to content

chore(ci): cancel superseded runs, skip DAST on docs-only PRs, TIA shadow evidence - #8379

Merged
diegosouzapw merged 1 commit into
release/v3.8.49from
chore/ci-runner-savings
Jul 24, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.49from
chore/ci-runner-savings

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Summary

First immediate slice of the CI-cost direction discussed in #8084 (@nguyenha935's pipeline review): stop paying for runs that cannot change the outcome, and start collecting the evidence that lets TIA actually replace cost later.

Changes

  1. dast-smoke.yml — concurrency + cancel-in-progress (superseded 25-minute advisory builds were stacking on force-push storms, holding 2-3 runners each), and paths-ignore for docs/** + **/*.md: a docs-only PR cannot change DAST behavior but was paying the 6-11min CLI-bundle build on every push (observed on the docs-only docs: sync env-var contract (chaos panel, notion TLS, grok auth path) + repair glued VNC line #8362).
  2. semgrep.yml — concurrency + cancel-in-progress only. Deliberately no paths filter: p/secrets must keep scanning docs-only diffs, credentials leak in .md files too.
  3. quality.yml (TIA step) — persist the per-PR impacted-test selection as a tia-selection artifact (30-day retention) + a GITHUB_STEP_SUMMARY line (empty / __RUN_ALL__ / N files). This is the shadow-evidence phase from feat(backend): PR preview artifacts with packaged-runtime validation and build-once promotion #8084: TIA false negatives become measurable against fast-unit's full-suite verdict on the same run, across releases, BEFORE any gate authority moves off ordinary PRs. No gate semantics change in this PR.

Validation

  • All three files parse (js-yaml load) and quality.yml keeps its 7 jobs intact.
  • No required-status impact: the release-branch ruleset has no required status checks, and both touched standalone workflows are advisory (continue-on-error).
  • Advisory-only + docs-path semantics: zero change to any blocking gate.

Not in this PR (tracked in the rail / #8084)

  • Lane consolidation (9× npm ci per code PR today) — 3.8.51.
  • ci.yml vs quality.yml policy unification — 3.8.52.
  • Full-suite authority move to merge queue (needs the shadow evidence this PR starts collecting) — 3.8.54.
  • CodeQL default-setup language trim (c-cpp/python analyze on a TS repo) — repo settings, operator-only.

Refs #8084

…t TIA shadow evidence

Runner-cost pass grounded in the #8084 review of the current pipeline:

- dast-smoke.yml: add concurrency cancel-in-progress (25-min advisory builds were
  stacking on force-push storms) and paths-ignore for docs/**+**/*.md — a docs-only
  PR cannot change DAST behavior but was paying the 6-11min CLI-bundle build.
- semgrep.yml: add concurrency cancel-in-progress. No paths filter on purpose:
  p/secrets must keep scanning docs-only diffs (credentials leak in .md too).
- quality.yml (TIA step): persist the per-PR impacted-test selection to a
  tia-selection artifact + GITHUB_STEP_SUMMARY line. This is the shadow-evidence
  phase: TIA false negatives become measurable against fast-unit's full-suite
  verdict across releases BEFORE any gate authority moves off ordinary PRs.

Refs #8084
@diegosouzapw
diegosouzapw merged commit 7c3b987 into release/v3.8.49 Jul 24, 2026
10 checks passed
@diegosouzapw
diegosouzapw deleted the chore/ci-runner-savings branch July 24, 2026 13:03
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
…t TIA shadow evidence (diegosouzapw#8379)

Runner-cost pass grounded in the diegosouzapw#8084 review of the current pipeline:

- dast-smoke.yml: add concurrency cancel-in-progress (25-min advisory builds were
  stacking on force-push storms) and paths-ignore for docs/**+**/*.md — a docs-only
  PR cannot change DAST behavior but was paying the 6-11min CLI-bundle build.
- semgrep.yml: add concurrency cancel-in-progress. No paths filter on purpose:
  p/secrets must keep scanning docs-only diffs (credentials leak in .md too).
- quality.yml (TIA step): persist the per-PR impacted-test selection to a
  tia-selection artifact + GITHUB_STEP_SUMMARY line. This is the shadow-evidence
  phase: TIA false negatives become measurable against fast-unit's full-suite
  verdict across releases BEFORE any gate authority moves off ordinary PRs.

Refs diegosouzapw#8084
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…t TIA shadow evidence (diegosouzapw#8379)

Runner-cost pass grounded in the diegosouzapw#8084 review of the current pipeline:

- dast-smoke.yml: add concurrency cancel-in-progress (25-min advisory builds were
  stacking on force-push storms) and paths-ignore for docs/**+**/*.md — a docs-only
  PR cannot change DAST behavior but was paying the 6-11min CLI-bundle build.
- semgrep.yml: add concurrency cancel-in-progress. No paths filter on purpose:
  p/secrets must keep scanning docs-only diffs (credentials leak in .md too).
- quality.yml (TIA step): persist the per-PR impacted-test selection to a
  tia-selection artifact + GITHUB_STEP_SUMMARY line. This is the shadow-evidence
  phase: TIA false negatives become measurable against fast-unit's full-suite
  verdict across releases BEFORE any gate authority moves off ordinary PRs.

Refs diegosouzapw#8084
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant