Skip to content

ci: add Dependabot and trim caches and artifacts - #304

Merged
devopvoid merged 1 commit into
ci/pipeline-hardeningfrom
ci/pipeline-cleanup
Sep 29, 2026
Merged

devopvoid merged 1 commit into
ci/pipeline-hardeningfrom
ci/pipeline-cleanup

Conversation

@devopvoid

Copy link
Copy Markdown
Owner

Stacked on #302. It targets that PR's branch and should be retargeted to main after #302 merges.

Changes

  • Dependabot. .github/dependabot.yml adds weekly version updates for GitHub Actions, including the composite actions under .github/actions, and for Maven, one grouped PR per ecosystem. The FFmpeg submodule and the WebRTC branch stay manual, because each bump needs follow-up by hand (FFmpeg library names and configure options, the Chromium Clang pin). Security updates are configured separately and aren't affected.
  • One Maven cache per OS. There were 8 caches, one per platform, of 100–150 MB each, rewritten on every pom change. Dependencies don't differ between platforms of the same OS, so the key is now runner.os, which makes 3 caches. The project's own artifacts, which mvn deploy installs into ~/.m2, are left out of the cache.
  • Shorter artifact retention. The natives that build.yml uploads for test-natives are kept for 1 day instead of the default 90. Only that same run reads them.
  • Verified Maven download. test-natives checks the SHA-512 of the Maven it downloads against the checksum Apache publishes.

Testing

  • The workflows pass actionlint 1.7.12.
  • All YAML parses, including dependabot.yml.
  • I ran the checksum line locally against the real Maven 3.9.9 download: it passes, and a bad or empty hash fails with exit 1.

The Build workflow's pull_request trigger only covers PRs into main, so this PR gets CI once it's retargeted.

Add weekly Dependabot version updates for the GitHub Actions, including
the composite actions, and for Maven, grouped into one PR per ecosystem.
The FFmpeg submodule and the WebRTC branch stay manual.

Share one Maven cache per OS instead of one per platform, and keep the
project's own artifacts, which mvn deploy installs, out of it. The eight
caches of 100-150 MB each were rewritten on every pom change.

Keep the natives uploaded for test-natives for one day instead of the
default 90, and verify the SHA-512 of the Maven that test-natives
downloads.
@devopvoid
devopvoid added this pull request to stack #305 September 28, 2026 21:49
@devopvoid
devopvoid merged commit c36f4e5 into main Sep 29, 2026
17 checks passed
@devopvoid
devopvoid deleted the ci/pipeline-cleanup branch September 29, 2026 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant