ci: add checks-passed gate job and speed up CI - #387
Conversation
Merge the `tests` and `pre-commit` workflows into a single `checks` workflow and add a final `checks-passed` job that depends on every other job. It runs with `if: always()` and fails unless each dependency succeeded or was skipped, so it can be the single required status check in the main branch ruleset. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Add a `setup-rust-node` composite action for the private-dependency git auth, pinned Rust toolchain, Node, and pnpm setup that was copied into every Rust job. - Cache Rust dependencies with Swatinem/rust-cache. The test jobs share one cache key since they build the same dependency graph; only main saves caches so PR runs don't evict each other. - Cancel in-progress `checks` runs when a PR gets a new push; runs on main always complete. - Set `timeout-minutes` on every job instead of GitHub's 6h default. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5aeb7b2516
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "Codex (@codex) review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "Codex (@codex) address that feedback".
All git dependencies are public, so the BT_GITHUB_TOKEN insteadOf rewrite is unnecessary for building. Fork PRs now build without restoring the Rust cache so untrusted code never reads what main saved. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The setup-rust-node action now uses jdx/mise-action so CI installs the same tool versions as local dev (.tool-versions / mise.toml) instead of hardcoding them in workflow YAML. Matrix jobs override Node through MISE_NODE_VERSION. The pre-commit job now uses the repo's Node version instead of Node 24. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The runner's rustup installs the minimal profile, so the mise-installed toolchain lacks rustfmt and clippy. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Latest downloadable build artifacts for this PR commit
Available artifact names
|
AI Summary
Adds a single
checks-passedjob that can be marked as the only required status check in themainruleset, modeled on the one in braintrust-sdk-python. Also makes CI faster and cheaper to run.Gate job
tests.ymlandpre-commit.ymlinto onechecksworkflow (checks.yml). A job'sneedscan only list jobs in the same workflow, so they have to live together.checks-passedneeds every other job and runs withif: always(). It fails unless each of them succeeded or was skipped, and prints each job's result.if: always()is deliberate. With!cancelled(), a cancelled run would mark the gate as skipped, and GitHub counts a skipped required check as passing.CI speedups
Swatinem/rust-cache. The core-tests, eval-tests-go, eval-tests-node and eval-tests-python jobs share one cache key (tests) because they build the same dependency graph. The key still separates OSes.pre-commithas its own cache because clippy builds different outputs. Onlymainsaves caches; PRs restore frommain's, which keeps us under the 10 GB repo cache limit. PRs from forks skip the cache entirely, so untrusted code never reads whatmainsaved. That means this PR won't show the speedup itself; it shows up after merge.concurrency. Runs onmainalways complete.timeout-minutes: 60on every job. The previous limit was GitHub's 6h default..github/actions/setup-rust-nodecomposite action replaces the Rust, Node and pnpm setup that was copied into 5 jobs. Each job keeps its ownpnpm installcommand unchanged.jdx/mise-action, so Rust, Node, pnpm, bun and uv are installed at the versions in.tool-versions/mise.toml, the same place local dev reads them. Nothing is hardcoded in workflow YAML anymore. Theeval-tests-nodematrix overrides Node throughMISE_NODE_VERSION.pre-commitnow runs on the repo's Node 22.15.0 instead of Node 24.setup-bunandsetup-uvare replaced by mise; both were alreadylatestin.tool-versions. Python and Deno still use their own setup actions because they aren't in the mise config. The runner's rustup uses the minimal profile, sopre-commitaddsrustfmtandclippythrough the action'srust-componentsinput.BT_GITHUB_TOKENgit-auth step fromchecks. Every git dependency (braintrust-sdk-rust,braintrust-coding-agent-plugins,lingua,ankrgyl/serde-json) is public, andcargo fetch --lockedsucceeds with no credentials.release.ymlandrelease-canary.ymlstill have their copies of this step, which are left for a separate change.After merge
checks-passedas a required status check in themainruleset.checks.yml, also add it tochecks-passed.needs.Test plan
actionlintpasses on all workflows, including input validation for the new composite action.needsJSON: all success/skipped exits 0;failure/cancelledexits 1 and names the failed jobs.checks-passed.needscovers every other job in the workflow.cargo fetch --lockedwith an emptyCARGO_HOME, no git config and no GitHub tokens fetches all git dependencies.checks-passedreported failure rather than skipped.miseresolves Rust 1.97.1 (with rustfmt and clippy), Node 22.15.0 and pnpm 10.28.2, and exportsRUSTUP_TOOLCHAIN=1.97.1;MISE_NODE_VERSION=20resolves Node 20.x.checks-passedreports success. Theeval-tests-nodematrix jobs install the requested Node major (e.g. 24.21.0 fornode 24).mainwith and without the cache.🤖 Generated with Claude Code
Co-authored by StarfolkAI (@starfolkai)[bot]