Skip to content

improvement(ci): fix the stripe-sync flake, stop helm cancelling a publish, attest via actions/attest - #8873

Merged
waleedlatif1 merged 7 commits into
stagingfrom
chore/ci-opt-3
Oct 10, 2026
Merged

waleedlatif1 merged 7 commits into
stagingfrom
chore/ci-opt-3

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 10, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • stripe-sync-convergence was the most frequent flake: 9 red runs, staging included.
    • Cause: the contender could take the row lock before the parked transaction did. The 200-poll wait then threw without releasing the transaction, so teardown hung.
    • Fix: the contender now starts only once the parked transaction holds its locks, the wait is deadline-based, and the transaction is released before the test fails.
  • helm cancels superseded pull-request runs only, never a push mid-publish.
  • trigger-promote runs on 2 vCPU; it mostly waits on the ECS cutover.
  • Attestations go through actions/attest (the action attest-sbom and attest-build-provenance now wrap) with artifact-metadata: write, which clears the deprecation and storage-record warnings on every release.
  • e2e (mobile) logs suite setup failures instead of only writing them to the uploaded report.
  • Integration shard weights are refreshed from a recent run. 24 files no longer use the default weight.

Tried on this PR and dropped, because none was a strict improvement:

  • A narrower desktop-live gate: every review round found more paths the suite depends on.
  • Parallel mobile browsers and a restored Turbopack dev cache for the e2e apps: restored-cache runs rendered pages missing UI, while cold runs and staging passed.
  • A proof job skipping checks on main for trees staging already passed: it would skip the release-wide block and migration audits, which catch deltas from staging runs cancelled while pending.
  • Skipping CodeQL, helm and desktop-e2e on the release PR: without required checks, it is their last run before production.
  • Scoping /ship's local tests.

Type of Change

  • Improvement

Testing

  • CI is the verification; no heavy local runs.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 10, 2026 4:03am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 14 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread .github/workflows/ci.yml Outdated
Comment thread .github/scripts/desktop-live-changes.sh Outdated
Comment thread .github/workflows/helm.yml Outdated
Comment thread .github/scripts/http-e2e.sh Outdated
@greptile-apps

greptile-apps Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High impact] The PR appears safe to merge, with no outstanding actionable findings.

Summary

This PR keeps Helm pushes from cancelling an active publish, switches attestations to actions/attest, and uses a smaller runner for background-task promotion.

  • Trigger.dev promotion now uses a smaller runner.
  • Image and chart attestations now use actions/attest.
  • Helm pushes keep running when a newer push arrives.
  • Stripe lock tests start competing work after the lock is held.
  • Mobile E2E setup failures now appear in the workflow log.
  • Integration test shards use refreshed run-time estimates.

Reviews (7) · Last reviewed commit: "ci: drop the main proof job and the rele..." · Reviewed by Greptile

Comment thread .github/workflows/helm.yml Outdated
Comment thread .github/scripts/desktop-live-changes.sh Outdated
Comment thread .github/scripts/http-e2e.sh Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 14 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread .github/workflows/codeql.yml Outdated
Comment thread .github/scripts/desktop-live-changes.sh Outdated
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@waleedlatif1 waleedlatif1 changed the title improvement(ci): halve the mobile job, narrow the desktop gate, skip proven checks on main, fix the top flake improvement(ci): run mobile browsers in parallel with a shared dev cache, narrow the desktop gate, skip proven checks on main, fix the top flake Oct 10, 2026

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 13 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread .github/scripts/desktop-live-changes.sh Outdated
Comment thread .github/scripts/desktop-live-changes.sh Outdated
@waleedlatif1 waleedlatif1 changed the title improvement(ci): run mobile browsers in parallel with a shared dev cache, narrow the desktop gate, skip proven checks on main, fix the top flake improvement(ci): run mobile browsers in parallel with a shared dev cache, skip proven checks on main, fix the top flake Oct 10, 2026
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 11 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

@waleedlatif1 waleedlatif1 changed the title improvement(ci): run mobile browsers in parallel with a shared dev cache, skip proven checks on main, fix the top flake improvement(ci): shared Turbopack dev cache for e2e apps, skip proven checks on main, fix the top flake Oct 10, 2026
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 11 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

Comment thread .agents/skills/ship/SKILL.md Outdated
@waleedlatif1 waleedlatif1 changed the title improvement(ci): shared Turbopack dev cache for e2e apps, skip proven checks on main, fix the top flake improvement(ci): skip proven checks on main, trim release-PR runs, fix the stripe-sync flake Oct 10, 2026
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 7 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Turn on auto-fix | Re-trigger cubic

Comment thread .github/workflows/ci.yml Outdated
…proven checks on main, fix the top flake

- e2e (mobile): Chromium and WebKit run as two processes against one app instead of back to back
  (each seeds its own fixtures and writes its own report), and every e2e group restores its own
  Turbopack dev cache. The job was the PR critical path at ~19.5 min: Chromium's pass (718 s
  median) carried the cold compile and WebKit waited it out (310 s). `suite setup` failures are
  now logged instead of only reaching the uploaded report.
- dev-cache action: one mount shared by desktop-live and the e2e groups, keyed by app, event,
  fork, Next version and the hash of the file that sets the app's environment, so a cache is never
  read under NEXT_PUBLIC_* values it was not compiled with. http-e2e.sh stops apps with SIGINT so
  the cache write completes, drops a cache Turbopack reports as corrupt, and retries a startup it
  aborted once from an empty cache.
- desktop-live-changes.sh: run the live desktop suite when a pull request touches a path it
  exercises instead of skipping only docs-like paths. Every genuine desktop-live failure since the
  layout change was on a PR the new rule still runs; pushes always run it.
- ci.yml: a `proof` job lets a main push skip the checks when it is a merge whose tree is
  identical to its staging parent and a staging push run of that parent passed `checks / ci`;
  migrate gates on that proof instead. Any other shape or any error runs the full checks.
- codeql, helm, desktop-e2e skip the staging -> main release PR (main's push and schedule still
  run them); helm never cancels a push mid-publish; trigger-promote on 2 vCPU; attestations via
  actions/attest with artifact-metadata: write.
- stripe-sync-convergence: start each contender only after the parked transaction holds its locks,
  wait on a deadline rather than 200 polls, and release the transaction before failing, so a lost
  race no longer hangs the suite's teardown. It was the most frequent flake (9 red runs).
- Integration shard weights refreshed from a recent run; /ship runs the affected workspaces' suites
  instead of the full suite locally.
… to this repository, give a cache-retry boot the full deadline
…ase-PR skips, gate desktop-live on workspace permissions
@waleedlatif1 waleedlatif1 changed the title improvement(ci): skip proven checks on main, trim release-PR runs, fix the stripe-sync flake improvement(ci): fix the stripe-sync flake, stop helm cancelling a publish, attest via actions/attest Oct 10, 2026
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 5 files

Reply with feedback, questions, or to request a fix.

Turn on auto-fix | Re-trigger cubic

Comment thread .github/workflows/helm.yml
@waleedlatif1
waleedlatif1 merged commit 071e7db into staging Oct 10, 2026
54 checks passed
@waleedlatif1
waleedlatif1 deleted the chore/ci-opt-3 branch October 10, 2026 12:56

This branch was successfully deployed

1 active deployment
Preview — c63fce8d Deployed Oct 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant