ci: SHA-pin actions, drop net9 from benchmarks, build timeout - #768
Merged
Merged
Conversation
Co-authored-by: Tyler Kron <tylerkron@gmail.com>
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can describe a rule in plain language on the Rules page and Qodo drafts it for you |
PR Summary by QodoPin CI actions, simplify benchmark SDKs, and bound build gate
AI Description
Diagram
High-Level Assessment
Files changed (2)
|
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Author
|
/agentic_review |
|
Code review by qodo was updated up to the latest commit 60002a8 |
Contributor
Author
|
Qodo-clean, CI green — ready for review |
This was referenced Sep 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What was wrong
release.ymlalready SHA-pinsactions/checkout,actions/setup-dotnet, andNuGet/login.ci.ymlandbenchmarks.ymlstill used floating tags (@v7/@v6). If an upstream tag were compromised or moved, what CI and the on-demand benchmark job run would change with no change in this repo.benchmarks.ymlalso installed9.0.xeven though the benchmark host targetsnet10.0only. The requiredbuildaggregator job (if: always(), no checkout) had no timeout, so it fell back to GitHub's 360-minute default.How it was fixed
ci.ymlandbenchmarks.ymlthe same wayrelease.ymldoes: a full 40-character commit SHA plus a trailing# vX.Y.Zcomment. Dependabot'sgithub-actionsupdater (.github/dependabot.yml, weekly) keeps both the SHA and the comment current.actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1(v7.0.1)actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68(v6.0.0)actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9(v6.1.0)actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a(v7.0.1)benchmarks.yml: install10.0.xonly. A short comment at that step says9.0.xhas to come back if a benchmark class adds[SimpleJob(RuntimeMoniker.Net90)], which the benchmarks README suggests for measuring on .NET 9.ci.ymlbuildjob:timeout-minutes: 5. The job only echoes the matrix result and takes a few seconds.Verification
gh api repos/<owner>/<repo>/git/ref/tags/<tag>. All four are lightweight tags that point directly at the commit, and each SHA is also where the floating major tag (v7/v6) points today. So the pins change nothing about what runs now.Daqifi.Core.Benchmarks.csprojisnet10.0only. There is noglobal.json, and no benchmark uses a net9RuntimeMoniker. I dispatched the Benchmarks workflow on this branch with only10.0.xinstalled (*ChannelScaling*, short job). The run built with SDK 10.0.401, executed 3 benchmarks on .NET 10.0.12, and uploaded the report artifact.actionlintreports nothing forci.ymlorbenchmarks.yml.Out of scope:
release.yml(pinned in #747). Overlap: #774 and #781 (ci.yml) and #791 (benchmarks.yml) edit different lines. Test-merging all three on top of this branch produces no conflicts.🤖 Generated with Claude Code