mirror of
https://github.com/pchuan98/codex.git
synced 2026-07-01 00:31:56 +08:00
93c79046d6
## Why CI jobs should not silently leave tracked changes or untracked files in the repository worktree. ## What - Add a shared final worktree-cleanliness action to 19 checkout-bearing PR and main CI jobs. - Ignore the intentional SDK scratch directory and nested V8 checkout. - Pin Bazelisk in shared CI setup so `.bazelversion` remains authoritative, avoiding `MODULE.bazel.lock` deltas on Windows runners. - Leave `rust-ci-full` and release-only workflows unchanged. - Update `AGENTS.md` to discourage review bots from asking for `MODULE.bazel.lock` changes.
39 lines
1.2 KiB
YAML
39 lines
1.2 KiB
YAML
name: blob-size-policy
|
|
|
|
on:
|
|
pull_request: {}
|
|
|
|
jobs:
|
|
check:
|
|
name: Blob size policy
|
|
runs-on: ubuntu-24.04
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || github.sha }}
|
|
fetch-depth: 0
|
|
persist-credentials: false
|
|
|
|
- name: Determine PR comparison range
|
|
id: range
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
echo "base=${{ github.event.pull_request.base.sha }}" >> "$GITHUB_OUTPUT"
|
|
echo "head=${{ github.event.pull_request.head.sha }}" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Check changed blob sizes
|
|
env:
|
|
BASE_SHA: ${{ steps.range.outputs.base }}
|
|
HEAD_SHA: ${{ steps.range.outputs.head }}
|
|
run: |
|
|
python3 scripts/check_blob_size.py \
|
|
--base "$BASE_SHA" \
|
|
--head "$HEAD_SHA" \
|
|
--max-bytes 512000 \
|
|
--allowlist .github/blob-size-allowlist.txt
|
|
|
|
- name: Check for a clean worktree
|
|
if: always() && !cancelled()
|
|
uses: ./.github/actions/check-clean-worktree
|