chore(ci): cancel superseded runs, skip DAST on docs-only PRs, TIA shadow evidence - #8379
Merged
Merged
Conversation
…t TIA shadow evidence Runner-cost pass grounded in the #8084 review of the current pipeline: - dast-smoke.yml: add concurrency cancel-in-progress (25-min advisory builds were stacking on force-push storms) and paths-ignore for docs/**+**/*.md — a docs-only PR cannot change DAST behavior but was paying the 6-11min CLI-bundle build. - semgrep.yml: add concurrency cancel-in-progress. No paths filter on purpose: p/secrets must keep scanning docs-only diffs (credentials leak in .md too). - quality.yml (TIA step): persist the per-PR impacted-test selection to a tia-selection artifact + GITHUB_STEP_SUMMARY line. This is the shadow-evidence phase: TIA false negatives become measurable against fast-unit's full-suite verdict across releases BEFORE any gate authority moves off ordinary PRs. Refs #8084
HouMinXi
pushed a commit
to HouMinXi/OmniRoute
that referenced
this pull request
Aug 2, 2026
…t TIA shadow evidence (diegosouzapw#8379) Runner-cost pass grounded in the diegosouzapw#8084 review of the current pipeline: - dast-smoke.yml: add concurrency cancel-in-progress (25-min advisory builds were stacking on force-push storms) and paths-ignore for docs/**+**/*.md — a docs-only PR cannot change DAST behavior but was paying the 6-11min CLI-bundle build. - semgrep.yml: add concurrency cancel-in-progress. No paths filter on purpose: p/secrets must keep scanning docs-only diffs (credentials leak in .md too). - quality.yml (TIA step): persist the per-PR impacted-test selection to a tia-selection artifact + GITHUB_STEP_SUMMARY line. This is the shadow-evidence phase: TIA false negatives become measurable against fast-unit's full-suite verdict across releases BEFORE any gate authority moves off ordinary PRs. Refs diegosouzapw#8084
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…t TIA shadow evidence (diegosouzapw#8379) Runner-cost pass grounded in the diegosouzapw#8084 review of the current pipeline: - dast-smoke.yml: add concurrency cancel-in-progress (25-min advisory builds were stacking on force-push storms) and paths-ignore for docs/**+**/*.md — a docs-only PR cannot change DAST behavior but was paying the 6-11min CLI-bundle build. - semgrep.yml: add concurrency cancel-in-progress. No paths filter on purpose: p/secrets must keep scanning docs-only diffs (credentials leak in .md too). - quality.yml (TIA step): persist the per-PR impacted-test selection to a tia-selection artifact + GITHUB_STEP_SUMMARY line. This is the shadow-evidence phase: TIA false negatives become measurable against fast-unit's full-suite verdict across releases BEFORE any gate authority moves off ordinary PRs. Refs diegosouzapw#8084
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
First immediate slice of the CI-cost direction discussed in #8084 (@nguyenha935's pipeline review): stop paying for runs that cannot change the outcome, and start collecting the evidence that lets TIA actually replace cost later.
Changes
dast-smoke.yml—concurrency+cancel-in-progress(superseded 25-minute advisory builds were stacking on force-push storms, holding 2-3 runners each), andpaths-ignorefordocs/**+**/*.md: a docs-only PR cannot change DAST behavior but was paying the 6-11min CLI-bundle build on every push (observed on the docs-only docs: sync env-var contract (chaos panel, notion TLS, grok auth path) + repair glued VNC line #8362).semgrep.yml—concurrency+cancel-in-progressonly. Deliberately no paths filter:p/secretsmust keep scanning docs-only diffs, credentials leak in.mdfiles too.quality.yml(TIA step) — persist the per-PR impacted-test selection as atia-selectionartifact (30-day retention) + aGITHUB_STEP_SUMMARYline (empty/__RUN_ALL__/N files). This is the shadow-evidence phase from feat(backend): PR preview artifacts with packaged-runtime validation and build-once promotion #8084: TIA false negatives become measurable againstfast-unit's full-suite verdict on the same run, across releases, BEFORE any gate authority moves off ordinary PRs. No gate semantics change in this PR.Validation
js-yamlload) andquality.ymlkeeps its 7 jobs intact.continue-on-error).Not in this PR (tracked in the rail / #8084)
npm ciper code PR today) — 3.8.51.ci.ymlvsquality.ymlpolicy unification — 3.8.52.Refs #8084