From 27ea6a023d2a6e0cb0e285dc84fc3ec5c3f0af52 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 9 Oct 2026 13:33:51 +0000 Subject: [PATCH] Path-filter compat runs on push to main Six compatibility workflows (composer, go, npm, pipenv, pnpm, sbt) ran their whole matrix on every push to main: 44 pushes in the last 24h at ~240 Linux + 32 Windows + 37 macOS job-min per push, whatever the commit touched. PDM, Poetry, Bun, vlt and Gradle already filter their push trigger. Give each a push paths filter: its pre-#1198 relevance set (the shared engine code its cells run through, as the PR filter listed before #1206 narrowed it), its current PR paths and the toolchain files. Over the last 24h of main commits that skips 22-53% of push runs per workflow. A nightly schedule (04:17 UTC, like vlt and Gradle) runs every matrix in full, so a main change outside a filter still gets a run within a day. Jobs gated on `event_name != 'pull_request'` (macOS legs) run on the schedule too. Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_018FBYc7n2aJPmvwCfVGUubD --- .github/workflows/composer-compatibility.yml | 55 +++++++++++++++++++- .github/workflows/go-compatibility.yml | 32 +++++++++++- .github/workflows/npm-compatibility.yml | 31 ++++++++++- .github/workflows/pipenv-compatibility.yml | 35 ++++++++++++- .github/workflows/pnpm-compatibility.yml | 29 ++++++++++- .github/workflows/sbt-compatibility.yml | 47 ++++++++++++++++- 6 files changed, 221 insertions(+), 8 deletions(-) diff --git a/.github/workflows/composer-compatibility.yml b/.github/workflows/composer-compatibility.yml index 7d6406d89..62a8d7fec 100644 --- a/.github/workflows/composer-compatibility.yml +++ b/.github/workflows/composer-compatibility.yml @@ -24,7 +24,8 @@ on: types: [opened, synchronize, reopened, ready_for_review] # Only this ecosystem's own files. A change to shared engine code # (vendor/, patch/, vex/, scan/, Cargo.lock, ...) runs the full matrix on - # push to main, or on demand via workflow_dispatch on the PR branch; + # push to main (when it is in the push filter below) or nightly, or on + # demand via workflow_dispatch on the PR branch; # ci.yml's per-ecosystem blocking slice still runs on every PR and in # the merge queue (#1198). paths: @@ -40,6 +41,58 @@ on: - 'crates/socket-patch-cli/tests/e2e_vex_lockfile/composer.rs' push: branches: [main] + # The ecosystem's pre-#1198 relevance set (the shared engine code its + # cells run through), its PR paths and the toolchain files. A main + # push outside this set waits for the nightly run below. + paths: + - '.github/workflows/composer-compatibility.yml' + - 'tests/docker/Dockerfile.composer' + - 'tests/docker/Dockerfile.base' + - 'Cargo.lock' + - 'Cargo.toml' + - 'crates/*/Cargo.toml' + - 'crates/socket-patch-core/src/vendor/**' + - 'crates/socket-patch-core/src/patch/**' + - 'crates/socket-patch-core/src/formats/composer/**' + - 'crates/socket-patch-core/src/formats/registry.rs' + - 'crates/socket-patch-core/src/hosted/**' + - 'crates/socket-patch-core/src/ledgers.rs' + - 'crates/socket-patch-core/src/policy/**' + - 'crates/socket-patch-core/src/rollout.rs' + - 'crates/socket-patch-core/src/rollout/**' + - 'crates/socket-patch-core/src/manifest/**' + - 'crates/socket-patch-core/tests/fixtures/redirect/composer/**' + - 'crates/socket-patch-core/tests/fixtures/composer-version-vectors.json' + - 'crates/socket-patch-core/src/crawlers/composer_crawler.rs' + - 'crates/socket-patch-core/src/crawlers/composer_crawler/**' + - 'crates/socket-patch-core/src/utils/composer*.rs' + - 'crates/socket-patch-core/src/utils/purl.rs' + - 'crates/socket-patch-core/src/utils/group_commit.rs' + - 'crates/socket-patch-core/src/utils/durability.rs' + - 'crates/socket-patch-core/src/vex/**' + - 'crates/socket-patch-cli/src/commands/vendor*' + - 'crates/socket-patch-cli/src/commands/vendored_backend/**' + - 'crates/socket-patch-cli/src/commands/get*.rs' + - 'crates/socket-patch-cli/src/commands/apply.rs' + - 'crates/socket-patch-cli/src/commands/rollback.rs' + - 'crates/socket-patch-cli/src/commands/remove.rs' + - 'crates/socket-patch-cli/src/commands/composer_hints.rs' + - 'crates/socket-patch-cli/src/commands/scan/**' + - 'crates/socket-patch-cli/src/commands/vex*.rs' + - 'crates/socket-patch-cli/tests/e2e_*composer*.rs' + - 'crates/socket-patch-cli/tests/docker_e2e_vendor_composer.rs' + - 'crates/socket-patch-cli/tests/composer_e2e_common/**' + - 'crates/socket-patch-cli/tests/docker_vendor_common/**' + - 'crates/socket-patch-cli/tests/e2e_vex_lockfile/composer.rs' + - 'crates/socket-patch-cli/tests/vex_e2e_common/**' + - 'crates/*/src/**/*composer*' + - 'crates/*/src/**/*composer*/**' + - 'rust-toolchain.toml' + - '.cargo/**' + schedule: + # Nightly full matrix, so a main change outside the push filter + # still gets a run within a day. + - cron: '17 4 * * *' workflow_dispatch: permissions: diff --git a/.github/workflows/go-compatibility.yml b/.github/workflows/go-compatibility.yml index 8cd27a6e3..3066d36bd 100644 --- a/.github/workflows/go-compatibility.yml +++ b/.github/workflows/go-compatibility.yml @@ -10,7 +10,8 @@ on: types: [opened, synchronize, reopened, ready_for_review] # Only this ecosystem's own files. A change to shared engine code # (vendor/, patch/, vex/, scan/, Cargo.lock, ...) runs the full matrix on - # push to main, or on demand via workflow_dispatch on the PR branch; + # push to main (when it is in the push filter below) or nightly, or on + # demand via workflow_dispatch on the PR branch; # ci.yml's per-ecosystem blocking slice still runs on every PR and in # the merge queue (#1198). paths: @@ -26,6 +27,35 @@ on: - 'crates/socket-patch-cli/tests/e2e_vex_lockfile/golang.rs' push: branches: [main] + # The ecosystem's pre-#1198 relevance set (the shared engine code its + # cells run through), its PR paths and the toolchain files. A main + # push outside this set waits for the nightly run below. + paths: + - '.github/workflows/go-compatibility.yml' + - 'crates/socket-patch-core/src/vendor/go*.rs' + - 'crates/socket-patch-core/src/vendor/golang.rs' + - 'crates/socket-patch-core/src/patch/redirect/**' + - 'crates/socket-patch-core/src/crawlers/go_crawler.rs' + - 'crates/socket-patch-core/src/vex/**' + - 'crates/socket-patch-cli/src/commands/vex*.rs' + - 'crates/socket-patch-cli/src/commands/vendor*' + - 'crates/socket-patch-cli/tests/e2e_golang_*build.rs' + - 'crates/socket-patch-cli/tests/e2e_vendor_golang_build.rs' + - 'crates/socket-patch-cli/tests/golang_e2e_matrix/**' + - 'crates/socket-patch-cli/tests/e2e_vex_lockfile/golang.rs' + - 'crates/socket-patch-cli/tests/vex_e2e_common/**' + - 'crates/*/src/**/*golang*' + - 'crates/*/src/**/*golang*/**' + - 'crates/socket-patch-core/src/crawlers/go_crawler/**' + - 'Cargo.lock' + - 'Cargo.toml' + - 'crates/*/Cargo.toml' + - 'rust-toolchain.toml' + - '.cargo/**' + schedule: + # Nightly full matrix, so a main change outside the push filter + # still gets a run within a day. + - cron: '17 4 * * *' workflow_dispatch: permissions: diff --git a/.github/workflows/npm-compatibility.yml b/.github/workflows/npm-compatibility.yml index 17fc79063..9ef2ae22c 100644 --- a/.github/workflows/npm-compatibility.yml +++ b/.github/workflows/npm-compatibility.yml @@ -9,12 +9,13 @@ name: npm hosted/vendored compatibility on: # PRs: any crate source, but only the test files these capstones # compile (a later `!` pattern excludes, a later plain one re-includes). - # Main pushes stay unfiltered. + # Main pushes use the wider push filter below, plus a nightly full run. pull_request: types: [opened, synchronize, reopened, ready_for_review] # Only this ecosystem's own files. A change to shared engine code # (vendor/, patch/, vex/, scan/, Cargo.lock, ...) runs the full matrix on - # push to main, or on demand via workflow_dispatch on the PR branch; + # push to main (when it is in the push filter below) or nightly, or on + # demand via workflow_dispatch on the PR branch; # ci.yml's per-ecosystem blocking slice still runs on every PR and in # the merge queue (#1198). paths: @@ -32,6 +33,32 @@ on: - 'crates/socket-patch-cli/tests/npm_e2e_common/**' push: branches: [main] + # The ecosystem's pre-#1198 relevance set (the shared engine code its + # cells run through), its PR paths and the toolchain files. A main + # push outside this set waits for the nightly run below. + paths: + - '.github/actions/upload-artifact/**' + - 'Cargo.lock' + - 'Cargo.toml' + - 'rust-toolchain.toml' + - '.cargo/config.toml' + - '.github/workflows/npm-compatibility.yml' + - 'docs/testing/npm-compatibility.md' + - 'crates/**' + - '!crates/**/*.md' + - '!crates/socket-patch-node/**' + - '!crates/socket-patch-core/tests/**' + - '!crates/socket-patch-cli/tests/**' + - 'crates/socket-patch-cli/tests/vex_e2e_common/**' + - 'crates/socket-patch-cli/tests/e2e_redirect_npm_build.rs' + - 'crates/socket-patch-cli/tests/e2e_vendor_npm_build.rs' + - 'crates/socket-patch-cli/tests/npm_e2e_common/**' + - 'crates/socket-patch-cli/tests/common/cache_env.rs' + - '.cargo/**' + schedule: + # Nightly full matrix, so a main change outside the push filter + # still gets a run within a day. + - cron: '17 4 * * *' workflow_dispatch: permissions: diff --git a/.github/workflows/pipenv-compatibility.yml b/.github/workflows/pipenv-compatibility.yml index 630e96030..27e07c721 100644 --- a/.github/workflows/pipenv-compatibility.yml +++ b/.github/workflows/pipenv-compatibility.yml @@ -12,7 +12,8 @@ on: types: [opened, synchronize, reopened, ready_for_review] # Only this ecosystem's own files. A change to shared engine code # (vendor/, patch/, vex/, scan/, Cargo.lock, ...) runs the full matrix on - # push to main, or on demand via workflow_dispatch on the PR branch; + # push to main (when it is in the push filter below) or nightly, or on + # demand via workflow_dispatch on the PR branch; # ci.yml's per-ecosystem blocking slice still runs on every PR and in # the merge queue (#1198). paths: @@ -26,6 +27,38 @@ on: - 'scripts/tests/test_backtest_harnesses.py' push: branches: [main] + # The ecosystem's pre-#1198 relevance set (the shared engine code its + # cells run through), its PR paths and the toolchain files. A main + # push outside this set waits for the nightly run below. + paths: + - '.github/actions/upload-artifact/**' + - 'crates/socket-patch-core/src/patch/redirect/pipenv.rs' + - 'crates/socket-patch-core/src/vendor/pypi_pipenv.rs' + - 'crates/socket-patch-core/src/vendor/pypi.rs' + - 'crates/socket-patch-core/src/vendor/lock_inventory/**' + - 'crates/socket-patch-core/src/crawlers/python_crawler.rs' + - 'crates/socket-patch-core/src/utils/pipenv.rs' + - 'crates/socket-patch-cli/src/commands/scan/hosted.rs' + - 'crates/socket-patch-cli/src/commands/vendor.rs' + - 'crates/socket-patch-cli/src/commands/rollback.rs' + - 'crates/socket-patch-cli/src/commands/vex.rs' + - 'crates/socket-patch-core/src/patch/redirect/replay.rs' + - 'scripts/backtest-pipenv.py' + - 'scripts/tests/test_backtest_harnesses.py' + - 'crates/socket-patch-core/src/vex/**' + - 'crates/socket-patch-cli/src/commands/vex_sources.rs' + - '.github/workflows/pipenv-compatibility.yml' + - 'crates/*/src/**/*pipenv*' + - 'crates/*/src/**/*pipenv*/**' + - 'Cargo.lock' + - 'Cargo.toml' + - 'crates/*/Cargo.toml' + - 'rust-toolchain.toml' + - '.cargo/**' + schedule: + # Nightly full matrix, so a main change outside the push filter + # still gets a run within a day. + - cron: '17 4 * * *' workflow_dispatch: permissions: diff --git a/.github/workflows/pnpm-compatibility.yml b/.github/workflows/pnpm-compatibility.yml index 426bbc1b9..271117272 100644 --- a/.github/workflows/pnpm-compatibility.yml +++ b/.github/workflows/pnpm-compatibility.yml @@ -3,12 +3,13 @@ name: pnpm hosted compatibility on: # PRs: any crate source, but only the test files these capstones # compile (a later `!` pattern excludes, a later plain one re-includes). - # Main pushes stay unfiltered. + # Main pushes use the wider push filter below, plus a nightly full run. pull_request: types: [opened, synchronize, reopened, ready_for_review] # Only this ecosystem's own files. A change to shared engine code # (vendor/, patch/, vex/, scan/, Cargo.lock, ...) runs the full matrix on - # push to main, or on demand via workflow_dispatch on the PR branch; + # push to main (when it is in the push filter below) or nightly, or on + # demand via workflow_dispatch on the PR branch; # ci.yml's per-ecosystem blocking slice still runs on every PR and in # the merge queue (#1198). paths: @@ -20,6 +21,30 @@ on: - 'crates/socket-patch-cli/tests/e2e_vendor_pnpm_build.rs' push: branches: [main] + # The ecosystem's pre-#1198 relevance set (the shared engine code its + # cells run through), its PR paths and the toolchain files. A main + # push outside this set waits for the nightly run below. + paths: + - '.github/actions/upload-artifact/**' + - 'Cargo.lock' + - 'Cargo.toml' + - 'rust-toolchain.toml' + - '.cargo/config.toml' + - '.github/workflows/pnpm-compatibility.yml' + - 'crates/**' + - '!crates/**/*.md' + - '!crates/socket-patch-node/**' + - '!crates/socket-patch-core/tests/**' + - '!crates/socket-patch-cli/tests/**' + - 'crates/socket-patch-cli/tests/vex_e2e_common/**' + - 'crates/socket-patch-cli/tests/e2e_redirect_pnpm_build.rs' + - 'crates/socket-patch-cli/tests/e2e_vendor_pnpm_build.rs' + - 'crates/socket-patch-cli/tests/common/cache_env.rs' + - '.cargo/**' + schedule: + # Nightly full matrix, so a main change outside the push filter + # still gets a run within a day. + - cron: '17 4 * * *' workflow_dispatch: permissions: diff --git a/.github/workflows/sbt-compatibility.yml b/.github/workflows/sbt-compatibility.yml index adf030e81..26cc6c768 100644 --- a/.github/workflows/sbt-compatibility.yml +++ b/.github/workflows/sbt-compatibility.yml @@ -24,7 +24,8 @@ on: types: [opened, synchronize, reopened, ready_for_review] # Only this ecosystem's own files. A change to shared engine code # (vendor/, patch/, vex/, scan/, Cargo.lock, ...) runs the full matrix on - # push to main, or on demand via workflow_dispatch on the PR branch; + # push to main (when it is in the push filter below) or nightly, or on + # demand via workflow_dispatch on the PR branch; # ci.yml's per-ecosystem blocking slice still runs on every PR and in # the merge queue (#1198). paths: @@ -51,6 +52,50 @@ on: - 'crates/socket-patch-cli/tests/sbt_common/**' push: branches: [main] + # The ecosystem's pre-#1198 relevance set (the shared engine code its + # cells run through), its PR paths and the toolchain files. A main + # push outside this set waits for the nightly run below. + paths: + - '.github/workflows/sbt-compatibility.yml' + - 'scripts/sbt-compat-matrix.sh' + - 'scripts/sbt-warm-seed.sh' + - 'docs/testing/sbt-compatibility.md' + - 'tests/docker/Dockerfile.sbt' + - 'tests/docker/Dockerfile.base' + - 'Cargo.toml' + - '.github/actions/upload-artifact/**' + - 'Cargo.lock' + - 'crates/*/Cargo.toml' + - 'crates/socket-patch-core/src/formats/**' + - 'crates/socket-patch-core/src/crawlers/**' + - 'crates/socket-patch-core/src/hosted/**' + - 'crates/socket-patch-core/src/patch/**' + - 'crates/socket-patch-core/src/manifest/**' + - 'crates/socket-patch-core/src/api/**' + - 'crates/socket-patch-core/src/utils/**' + - 'crates/socket-patch-core/src/vendor/**' + - 'crates/socket-patch-core/src/vex/**' + - 'crates/socket-patch-cli/src/**' + - 'crates/socket-patch-cli/tests/docker_e2e_sbt.rs' + - 'crates/socket-patch-cli/tests/e2e_sbt_build.rs' + - 'crates/socket-patch-cli/tests/e2e_sbt_vendor_build.rs' + - 'crates/socket-patch-cli/tests/e2e_scala_cli_vendor.rs' + - 'crates/socket-patch-cli/tests/sbt_build_common/**' + - 'crates/socket-patch-cli/tests/sbt_vendor_build_common/**' + - 'crates/socket-patch-cli/tests/sbt_e2e_shared/**' + - 'crates/socket-patch-cli/tests/sbt_common/**' + - 'crates/*/src/**/*sbt*' + - 'crates/*/src/**/*sbt*/**' + - 'crates/*/src/**/*scala*' + - 'crates/*/src/**/*scala*/**' + - 'crates/*/src/**/*coursier*' + - 'crates/*/src/**/*ivy*' + - 'rust-toolchain.toml' + - '.cargo/**' + schedule: + # Nightly full matrix, so a main change outside the push filter + # still gets a run within a day. + - cron: '17 4 * * *' workflow_dispatch: permissions: