Repository navigation
improvement(ci): fix the stripe-sync flake, stop helm cancelling a publish, attest via actions/attest - #8873
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
All reported issues were addressed across 14 files
Reply with feedback, questions, or to request a fix.
Turn on auto-fix | Re-trigger cubic
|
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
All reported issues were addressed across 14 files
Reply with feedback, questions, or to request a fix.
Turn on auto-fix | Re-trigger cubic
80ff371 to
bae6756
Compare
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
All reported issues were addressed across 13 files
Reply with feedback, questions, or to request a fix.
Turn on auto-fix | Re-trigger cubic
bae6756 to
0bc2fa1
Compare
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
0bc2fa1 to
e592345
Compare
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
e592345 to
a26ead8
Compare
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
…proven checks on main, fix the top flake - e2e (mobile): Chromium and WebKit run as two processes against one app instead of back to back (each seeds its own fixtures and writes its own report), and every e2e group restores its own Turbopack dev cache. The job was the PR critical path at ~19.5 min: Chromium's pass (718 s median) carried the cold compile and WebKit waited it out (310 s). `suite setup` failures are now logged instead of only reaching the uploaded report. - dev-cache action: one mount shared by desktop-live and the e2e groups, keyed by app, event, fork, Next version and the hash of the file that sets the app's environment, so a cache is never read under NEXT_PUBLIC_* values it was not compiled with. http-e2e.sh stops apps with SIGINT so the cache write completes, drops a cache Turbopack reports as corrupt, and retries a startup it aborted once from an empty cache. - desktop-live-changes.sh: run the live desktop suite when a pull request touches a path it exercises instead of skipping only docs-like paths. Every genuine desktop-live failure since the layout change was on a PR the new rule still runs; pushes always run it. - ci.yml: a `proof` job lets a main push skip the checks when it is a merge whose tree is identical to its staging parent and a staging push run of that parent passed `checks / ci`; migrate gates on that proof instead. Any other shape or any error runs the full checks. - codeql, helm, desktop-e2e skip the staging -> main release PR (main's push and schedule still run them); helm never cancels a push mid-publish; trigger-promote on 2 vCPU; attestations via actions/attest with artifact-metadata: write. - stripe-sync-convergence: start each contender only after the parked transaction holds its locks, wait on a deadline rather than 200 polls, and release the transaction before failing, so a lost race no longer hangs the suite's teardown. It was the most frequent flake (9 red runs). - Integration shard weights refreshed from a recent run; /ship runs the affected workspaces' suites instead of the full suite locally.
… to this repository, give a cache-retry boot the full deadline
…ase-PR skips, gate desktop-live on workspace permissions
a26ead8 to
c63fce8
Compare
|
@cubic-dev-ai review this PR |
@waleedlatif1 I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
All reported issues were addressed across 5 files
Reply with feedback, questions, or to request a fix.
Turn on auto-fix | Re-trigger cubic
Summary
actions/attest(the actionattest-sbomandattest-build-provenancenow wrap) withartifact-metadata: write, which clears the deprecation and storage-record warnings on every release.suite setupfailures instead of only writing them to the uploaded report.Tried on this PR and dropped, because none was a strict improvement:
proofjob skipping checks on main for trees staging already passed: it would skip the release-wide block and migration audits, which catch deltas from staging runs cancelled while pending./ship's local tests.Type of Change
Testing
Checklist
test-auditauthoring gate)