Skip to content

ci: add checks-passed gate job and speed up CI - #387

Merged
Abhijeet Prasad (AbhiPrasad) merged 6 commits into
mainfrom
ci/checks-passed-gate
Sep 28, 2026
Merged

Abhijeet Prasad (AbhiPrasad) merged 6 commits into
mainfrom
ci/checks-passed-gate

Conversation

@AbhiPrasad

@AbhiPrasad Abhijeet Prasad (AbhiPrasad) commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

AI Summary

Adds a single checks-passed job that can be marked as the only required status check in the main ruleset, modeled on the one in braintrust-sdk-python. Also makes CI faster and cheaper to run.

Gate job

  • Merges tests.yml and pre-commit.yml into one checks workflow (checks.yml). A job's needs can only list jobs in the same workflow, so they have to live together.
  • checks-passed needs every other job and runs with if: always(). It fails unless each of them succeeded or was skipped, and prints each job's result.
  • Individual job names are unchanged. The ruleset currently requires no status checks, so the rename breaks nothing.
  • if: always() is deliberate. With !cancelled(), a cancelled run would mark the gate as skipped, and GitHub counts a skipped required check as passing.

CI speedups

  • Rust build caching with Swatinem/rust-cache. The core-tests, eval-tests-go, eval-tests-node and eval-tests-python jobs share one cache key (tests) because they build the same dependency graph. The key still separates OSes. pre-commit has its own cache because clippy builds different outputs. Only main saves caches; PRs restore from main's, which keeps us under the 10 GB repo cache limit. PRs from forks skip the cache entirely, so untrusted code never reads what main saved. That means this PR won't show the speedup itself; it shows up after merge.
  • Cancel superseded PR runs through concurrency. Runs on main always complete.
  • timeout-minutes: 60 on every job. The previous limit was GitHub's 6h default.
  • .github/actions/setup-rust-node composite action replaces the Rust, Node and pnpm setup that was copied into 5 jobs. Each job keeps its own pnpm install command unchanged.
  • Tool versions come from mise. The setup action uses jdx/mise-action, so Rust, Node, pnpm, bun and uv are installed at the versions in .tool-versions / mise.toml, the same place local dev reads them. Nothing is hardcoded in workflow YAML anymore. The eval-tests-node matrix overrides Node through MISE_NODE_VERSION. pre-commit now runs on the repo's Node 22.15.0 instead of Node 24. setup-bun and setup-uv are replaced by mise; both were already latest in .tool-versions. Python and Deno still use their own setup actions because they aren't in the mise config. The runner's rustup uses the minimal profile, so pre-commit adds rustfmt and clippy through the action's rust-components input.
  • Removes the BT_GITHUB_TOKEN git-auth step from checks. Every git dependency (braintrust-sdk-rust, braintrust-coding-agent-plugins, lingua, ankrgyl/serde-json) is public, and cargo fetch --locked succeeds with no credentials. release.yml and release-canary.yml still have their copies of this step, which are left for a separate change.

After merge

  • Add checks-passed as a required status check in the main ruleset.
  • When adding a new job to checks.yml, also add it to checks-passed.needs.

Test plan

  • actionlint passes on all workflows, including input validation for the new composite action.
  • prettier pre-commit hook passes.
  • Ran the gate script locally against sample needs JSON: all success/skipped exits 0; failure/cancelled exits 1 and names the failed jobs.
  • Checked that checks-passed.needs covers every other job in the workflow.
  • cargo fetch --locked with an empty CARGO_HOME, no git config and no GitHub tokens fetches all git dependencies.
  • Pushing a new commit cancelled the previous PR run, and its checks-passed reported failure rather than skipped.
  • Locally, mise resolves Rust 1.97.1 (with rustfmt and clippy), Node 22.15.0 and pnpm 10.28.2, and exports RUSTUP_TOOLCHAIN=1.97.1; MISE_NODE_VERSION=20 resolves Node 20.x.
  • This PR's own run (36450056512): every job passes with the mise-based setup and checks-passed reports success. The eval-tests-node matrix jobs install the requested Node major (e.g. 24.21.0 for node 24).
  • After merge: compare job durations on main with and without the cache.

🤖 Generated with Claude Code

Co-authored by StarfolkAI (@starfolkai)[bot]

Merge the `tests` and `pre-commit` workflows into a single `checks`
workflow and add a final `checks-passed` job that depends on every other
job. It runs with `if: always()` and fails unless each dependency
succeeded or was skipped, so it can be the single required status check
in the main branch ruleset.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Add a `setup-rust-node` composite action for the private-dependency
  git auth, pinned Rust toolchain, Node, and pnpm setup that was copied
  into every Rust job.
- Cache Rust dependencies with Swatinem/rust-cache. The test jobs share
  one cache key since they build the same dependency graph; only main
  saves caches so PR runs don't evict each other.
- Cancel in-progress `checks` runs when a PR gets a new push; runs on
  main always complete.
- Set `timeout-minutes` on every job instead of GitHub's 6h default.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T16:21:49.237130Z 23f0b4b New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5aeb7b2516

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "Codex (@codex) review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "Codex (@codex) address that feedback".

Comment thread .github/actions/setup-rust-node/action.yml Outdated
All git dependencies are public, so the BT_GITHUB_TOKEN insteadOf
rewrite is unnecessary for building. Fork PRs now build without
restoring the Rust cache so untrusted code never reads what main saved.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The setup-rust-node action now uses jdx/mise-action so CI installs the
same tool versions as local dev (.tool-versions / mise.toml) instead of
hardcoding them in workflow YAML. Matrix jobs override Node through
MISE_NODE_VERSION. The pre-commit job now uses the repo's Node version
instead of Node 24.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The runner's rustup installs the minimal profile, so the mise-installed
toolchain lacks rustfmt and clippy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

Latest downloadable build artifacts for this PR commit 23f0b4b04e8f:

Available artifact names
  • artifacts-build-global
  • artifacts-build-local-aarch64-pc-windows-msvc
  • artifacts-build-local-x86_64-pc-windows-msvc
  • artifacts-build-local-x86_64-unknown-linux-gnu
  • artifacts-build-local-aarch64-apple-darwin
  • artifacts-build-local-x86_64-apple-darwin
  • artifacts-build-local-aarch64-unknown-linux-gnu
  • artifacts-build-local-x86_64-unknown-linux-musl
  • artifacts-plan-dist-manifest
  • cargo-dist-cache

@AbhiPrasad
Abhijeet Prasad (AbhiPrasad) merged commit 035fb24 into main Sep 28, 2026
29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants