From 43c73514570e22a82ac762b2b9a699b9058900eb Mon Sep 17 00:00:00 2001 From: Max Ghenis Date: Thu, 8 Oct 2026 13:06:58 -0400 Subject: [PATCH 1/2] Add timeouts to CI jobs No PR or push CI job had a timeout, so a hung job would hold one of the org's shared runners for the 6-hour default. Time out the test matrix at 60 minutes (slowest observed from 2026-10-06 to 10-08: 28) and the lint, changelog, mypy, smoke-import, bundle-verification, docs and paper jobs at 10 to 30 minutes. Release jobs (Versioning, Publish, NotifyConsumers) are unchanged. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/draft-pdf.yml | 1 + .github/workflows/pr_code_changes.yaml | 8 ++++++++ .github/workflows/pr_docs_changes.yaml | 1 + .github/workflows/push.yaml | 3 +++ changelog.d/ci-capacity-ci-hygiene.changed.md | 1 + 5 files changed, 14 insertions(+) create mode 100644 changelog.d/ci-capacity-ci-hygiene.changed.md diff --git a/.github/workflows/draft-pdf.yml b/.github/workflows/draft-pdf.yml index a43ecc8d..4bad7722 100644 --- a/.github/workflows/draft-pdf.yml +++ b/.github/workflows/draft-pdf.yml @@ -18,6 +18,7 @@ jobs: paper: runs-on: ubuntu-latest name: Draft PDF + timeout-minutes: 15 steps: - uses: actions/checkout@v4 - uses: openjournals/openjournals-draft-action@master diff --git a/.github/workflows/pr_code_changes.yaml b/.github/workflows/pr_code_changes.yaml index eb825e24..ff78828c 100644 --- a/.github/workflows/pr_code_changes.yaml +++ b/.github/workflows/pr_code_changes.yaml @@ -22,6 +22,7 @@ jobs: check-changelog: name: Check changelog fragment runs-on: ubuntu-latest + timeout-minutes: 10 steps: - uses: actions/checkout@v6 with: @@ -32,6 +33,7 @@ jobs: run: .github/check-changelog.sh Lint: runs-on: ubuntu-latest + timeout-minutes: 10 steps: - uses: actions/checkout@v6 - name: Install ruff @@ -44,6 +46,7 @@ jobs: run: ruff check . Mypy: runs-on: ubuntu-latest + timeout-minutes: 20 steps: - uses: actions/checkout@v6 - name: Install uv @@ -61,6 +64,7 @@ jobs: Python-Compat: name: Install + smoke-import (py${{ matrix.python-version }}) runs-on: ubuntu-latest + timeout-minutes: 15 strategy: fail-fast: false matrix: @@ -85,6 +89,7 @@ jobs: # Private manifest credentials are available only to trusted repository PRs. if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository runs-on: ubuntu-latest + timeout-minutes: 30 env: POLICYENGINE_SKIP_COUNTRY_IMPORTS: "1" steps: @@ -136,6 +141,9 @@ jobs: run: policyengine bundle verify --country us --country uk --packages-only --json Test: runs-on: ubuntu-latest + # Slowest observed 2026-10-06..08: 28 minutes. Fail a hung job instead of + # holding a shared org runner for the 6-hour default. + timeout-minutes: 60 strategy: fail-fast: false matrix: diff --git a/.github/workflows/pr_docs_changes.yaml b/.github/workflows/pr_docs_changes.yaml index d3f090c4..81a42f04 100644 --- a/.github/workflows/pr_docs_changes.yaml +++ b/.github/workflows/pr_docs_changes.yaml @@ -19,6 +19,7 @@ jobs: Test: runs-on: ubuntu-latest name: Test documentation builds + timeout-minutes: 30 steps: - name: Checkout repo uses: actions/checkout@v6 diff --git a/.github/workflows/push.yaml b/.github/workflows/push.yaml index 781a2f3e..6328c266 100644 --- a/.github/workflows/push.yaml +++ b/.github/workflows/push.yaml @@ -28,6 +28,7 @@ jobs: Lint: if: github.event.head_commit.message != 'Update package version' runs-on: ubuntu-latest + timeout-minutes: 10 steps: - uses: actions/checkout@v6 - name: Install ruff @@ -40,6 +41,8 @@ jobs: Test: if: github.event.head_commit.message != 'Update package version' runs-on: ubuntu-latest + # Slowest observed 2026-10-06..08: 26 minutes. + timeout-minutes: 60 strategy: fail-fast: false matrix: diff --git a/changelog.d/ci-capacity-ci-hygiene.changed.md b/changelog.d/ci-capacity-ci-hygiene.changed.md new file mode 100644 index 00000000..a33f4f39 --- /dev/null +++ b/changelog.d/ci-capacity-ci-hygiene.changed.md @@ -0,0 +1 @@ +Give every lint, test, docs and paper CI job a timeout, so a hung job frees its shared GitHub Actions runner instead of holding it for six hours. From 8a02987e348b360123fb979a52f5e6a0a42343b1 Mon Sep 17 00:00:00 2001 From: Max Ghenis Date: Thu, 8 Oct 2026 13:17:07 -0400 Subject: [PATCH 2/2] Build the JOSS draft on pushes to main only draft-pdf.yml ran on pushes to every branch and on pull requests, so a paper change on a PR branch built the draft twice. Limit the push trigger to main; pull requests still build it. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/draft-pdf.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/draft-pdf.yml b/.github/workflows/draft-pdf.yml index 4bad7722..6e4fc68d 100644 --- a/.github/workflows/draft-pdf.yml +++ b/.github/workflows/draft-pdf.yml @@ -1,5 +1,8 @@ on: + # Feature branches get the pull_request run below; building the draft again + # on every branch push duplicated it. push: + branches: [main] paths: - paper.md - paper.bib