ci: add Dependabot and trim caches and artifacts - #304
Merged
Merged
Conversation
Add weekly Dependabot version updates for the GitHub Actions, including the composite actions, and for Maven, grouped into one PR per ecosystem. The FFmpeg submodule and the WebRTC branch stay manual. Share one Maven cache per OS instead of one per platform, and keep the project's own artifacts, which mvn deploy installs, out of it. The eight caches of 100-150 MB each were rewritten on every pom change. Keep the natives uploaded for test-natives for one day instead of the default 90, and verify the SHA-512 of the Maven that test-natives downloads.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #302. It targets that PR's branch and should be retargeted to
mainafter #302 merges.Changes
.github/dependabot.ymladds weekly version updates for GitHub Actions, including the composite actions under.github/actions, and for Maven, one grouped PR per ecosystem. The FFmpeg submodule and the WebRTC branch stay manual, because each bump needs follow-up by hand (FFmpeg library names and configure options, the Chromium Clang pin). Security updates are configured separately and aren't affected.runner.os, which makes 3 caches. The project's own artifacts, whichmvn deployinstalls into~/.m2, are left out of the cache.build.ymluploads fortest-nativesare kept for 1 day instead of the default 90. Only that same run reads them.test-nativeschecks the SHA-512 of the Maven it downloads against the checksum Apache publishes.Testing
dependabot.yml.The Build workflow's
pull_requesttrigger only covers PRs intomain, so this PR gets CI once it's retargeted.