From 3fff0768f29c3462d97ee6fbdc468d5053bce128 Mon Sep 17 00:00:00 2001 From: Alex Andres Date: Mon, 28 Sep 2026 23:43:23 +0200 Subject: [PATCH] ci: add Dependabot and trim caches and artifacts Add weekly Dependabot version updates for the GitHub Actions, including the composite actions, and for Maven, grouped into one PR per ecosystem. The FFmpeg submodule and the WebRTC branch stay manual. Share one Maven cache per OS instead of one per platform, and keep the project's own artifacts, which mvn deploy installs, out of it. The eight caches of 100-150 MB each were rewritten on every pom change. Keep the natives uploaded for test-natives for one day instead of the default 90, and verify the SHA-512 of the Maven that test-natives downloads. --- .github/actions/build-macos-x86_64/action.yml | 11 ++++-- .github/actions/build/action.yml | 11 ++++-- .../actions/release-macos-x86_64/action.yml | 11 ++++-- .github/actions/release/action.yml | 11 ++++-- .github/actions/test-natives/action.yml | 4 ++- .github/dependabot.yml | 34 +++++++++++++++++++ .github/workflows/build.yml | 4 +++ 7 files changed, 73 insertions(+), 13 deletions(-) create mode 100644 .github/dependabot.yml diff --git a/.github/actions/build-macos-x86_64/action.yml b/.github/actions/build-macos-x86_64/action.yml index 3315021d..6ee6d9e7 100644 --- a/.github/actions/build-macos-x86_64/action.yml +++ b/.github/actions/build-macos-x86_64/action.yml @@ -51,12 +51,17 @@ runs: key: ffmpeg-${{ env.FFMPEG_VERSION }}-${{ inputs.platform-name }}-${{ hashFiles('webrtc-java-media/src/main/cpp/dependencies/ffmpeg/CMakeLists.txt') }}-${{ hashFiles('webrtc-java-media/pom.xml') }} restore-keys: ffmpeg-${{ env.FFMPEG_VERSION }}-${{ inputs.platform-name }}-${{ hashFiles('webrtc-java-media/src/main/cpp/dependencies/ffmpeg/CMakeLists.txt') }}- + # One cache per OS: the dependencies do not differ between the platforms of + # an OS. The project's own artifacts, which mvn deploy installs, change with + # every build and stay out of it. - name: Set up Maven cache uses: actions/cache@v6 with: - path: ~/.m2/repository - key: maven-${{ inputs.platform-name }}-${{ hashFiles('**/pom.xml') }} - restore-keys: maven-${{ inputs.platform-name }}- + path: | + ~/.m2/repository + !~/.m2/repository/dev/onvoid/webrtc + key: maven-${{ runner.os }}-${{ hashFiles('**/pom.xml') }} + restore-keys: maven-${{ runner.os }}- # The runner is Apple Silicon. The build runs natively and cross compiles # for Intel; only the tests need an Intel JVM, to load what was built, and diff --git a/.github/actions/build/action.yml b/.github/actions/build/action.yml index 7baeb547..6c5463e5 100644 --- a/.github/actions/build/action.yml +++ b/.github/actions/build/action.yml @@ -51,12 +51,17 @@ runs: key: ffmpeg-${{ env.FFMPEG_VERSION }}-${{ inputs.platform-name }}-${{ hashFiles('webrtc-java-media/src/main/cpp/dependencies/ffmpeg/CMakeLists.txt') }}-${{ hashFiles('webrtc-java-media/pom.xml') }} restore-keys: ffmpeg-${{ env.FFMPEG_VERSION }}-${{ inputs.platform-name }}-${{ hashFiles('webrtc-java-media/src/main/cpp/dependencies/ffmpeg/CMakeLists.txt') }}- + # One cache per OS: the dependencies do not differ between the platforms of + # an OS. The project's own artifacts, which mvn deploy installs, change with + # every build and stay out of it. - name: Set up Maven cache uses: actions/cache@v6 with: - path: ~/.m2/repository - key: maven-${{ inputs.platform-name }}-${{ hashFiles('**/pom.xml') }} - restore-keys: maven-${{ inputs.platform-name }}- + path: | + ~/.m2/repository + !~/.m2/repository/dev/onvoid/webrtc + key: maven-${{ runner.os }}-${{ hashFiles('**/pom.xml') }} + restore-keys: maven-${{ runner.os }}- - name: Set up JDK ${{ inputs.java-version }} uses: actions/setup-java@v5 diff --git a/.github/actions/release-macos-x86_64/action.yml b/.github/actions/release-macos-x86_64/action.yml index c0ac1510..42656994 100644 --- a/.github/actions/release-macos-x86_64/action.yml +++ b/.github/actions/release-macos-x86_64/action.yml @@ -43,12 +43,17 @@ runs: key: ffmpeg-${{ env.FFMPEG_VERSION }}-${{ inputs.platform-name }}-${{ hashFiles('webrtc-java-media/src/main/cpp/dependencies/ffmpeg/CMakeLists.txt') }}-${{ hashFiles('webrtc-java-media/pom.xml') }} restore-keys: ffmpeg-${{ env.FFMPEG_VERSION }}-${{ inputs.platform-name }}-${{ hashFiles('webrtc-java-media/src/main/cpp/dependencies/ffmpeg/CMakeLists.txt') }}- + # One cache per OS: the dependencies do not differ between the platforms of + # an OS. The project's own artifacts, which mvn deploy installs, change with + # every build and stay out of it. - name: Set up Maven cache uses: actions/cache@v6 with: - path: ~/.m2/repository - key: maven-${{ inputs.platform-name }}-${{ hashFiles('**/pom.xml') }} - restore-keys: maven-${{ inputs.platform-name }}- + path: | + ~/.m2/repository + !~/.m2/repository/dev/onvoid/webrtc + key: maven-${{ runner.os }}-${{ hashFiles('**/pom.xml') }} + restore-keys: maven-${{ runner.os }}- # The runner is Apple Silicon. The build runs natively and cross compiles # for Intel; only the tests need an Intel JVM, to load what was built, and diff --git a/.github/actions/release/action.yml b/.github/actions/release/action.yml index 27c73883..45bba012 100644 --- a/.github/actions/release/action.yml +++ b/.github/actions/release/action.yml @@ -42,12 +42,17 @@ runs: key: ffmpeg-${{ env.FFMPEG_VERSION }}-${{ inputs.platform-name }}-${{ hashFiles('webrtc-java-media/src/main/cpp/dependencies/ffmpeg/CMakeLists.txt') }}-${{ hashFiles('webrtc-java-media/pom.xml') }} restore-keys: ffmpeg-${{ env.FFMPEG_VERSION }}-${{ inputs.platform-name }}-${{ hashFiles('webrtc-java-media/src/main/cpp/dependencies/ffmpeg/CMakeLists.txt') }}- + # One cache per OS: the dependencies do not differ between the platforms of + # an OS. The project's own artifacts, which mvn deploy installs, change with + # every build and stay out of it. - name: Set up Maven cache uses: actions/cache@v6 with: - path: ~/.m2/repository - key: maven-${{ inputs.platform-name }}-${{ hashFiles('**/pom.xml') }} - restore-keys: maven-${{ inputs.platform-name }}- + path: | + ~/.m2/repository + !~/.m2/repository/dev/onvoid/webrtc + key: maven-${{ runner.os }}-${{ hashFiles('**/pom.xml') }} + restore-keys: maven-${{ runner.os }}- - name: Set up JDK ${{ inputs.java-version }} uses: actions/setup-java@v5 diff --git a/.github/actions/test-natives/action.yml b/.github/actions/test-natives/action.yml index 26c1d035..490fd10c 100644 --- a/.github/actions/test-natives/action.yml +++ b/.github/actions/test-natives/action.yml @@ -67,7 +67,9 @@ runs: - name: Ensure Maven run: | if ! command -v mvn >/dev/null 2>&1; then - curl -sSLo maven.zip https://archive.apache.org/dist/maven/maven-3/3.9.9/binaries/apache-maven-3.9.9-bin.zip + url=https://archive.apache.org/dist/maven/maven-3/3.9.9/binaries/apache-maven-3.9.9-bin.zip + curl -sSfLo maven.zip "$url" + echo "$(curl -sSfL "$url.sha512" | cut -d' ' -f1) maven.zip" | sha512sum -c - unzip -q maven.zip -d "$RUNNER_TEMP/maven" echo "$RUNNER_TEMP/maven/apache-maven-3.9.9/bin" >> "$GITHUB_PATH" fi diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 00000000..7ca013f9 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,34 @@ +version: 2 + +# Weekly version updates, one grouped PR per ecosystem. Security updates are +# enabled separately in the repository settings and are not affected by this. +# +# The FFmpeg submodule and the WebRTC branch are left out on purpose: each bump +# needs manual follow-up (FFmpeg's library file names and configure options, +# the Chromium Clang pin in prepare-linux), so they are updated by hand. +updates: + - package-ecosystem: github-actions + # Also covers the composite actions under .github/actions. + directories: + - "/" + - "/.github/actions/*" + schedule: + interval: weekly + groups: + github-actions: + patterns: ["*"] + commit-message: + prefix: ci + + - package-ecosystem: maven + directory: "/" + schedule: + interval: weekly + groups: + maven-plugins: + patterns: ["org.apache.maven.plugins:*", "*-maven-plugin"] + maven-dependencies: + patterns: ["*"] + commit-message: + prefix: build + include: scope diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index e630046d..e2f38542 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -81,6 +81,8 @@ jobs: webrtc-jni/target/webrtc-java-*.jar webrtc-java-media/target/webrtc-java-media-*.jar if-no-files-found: error + # Only test-natives of this same run reads them. + retention-days: 1 build-linux: strategy: @@ -124,6 +126,8 @@ jobs: webrtc-jni/target/webrtc-java-*.jar webrtc-java-media/target/webrtc-java-media-*.jar if-no-files-found: error + # Only test-natives of this same run reads them. + retention-days: 1 build-macos: strategy: