Skip to content

ci: bound every job, and allow manual runs - #48

Merged
tcheeric merged 4 commits into
developfrom
ci/timeouts-and-dispatch
Sep 24, 2026
Merged

tcheeric merged 4 commits into
developfrom
ci/timeouts-and-dispatch

Conversation

@tcheeric

Copy link
Copy Markdown
Owner

Carrying two fixes across from nap-java, where both were found the hard way.

Timeouts

Neither job had timeout-minutes, so both inherited GitHub's 360 minute default. In nap-java that same gap let a stuck Dependency-Check scan run for 50 minutes before I noticed, and it would have reached six hours unattended.

Both jobs finish in about a minute today. The caps are sized for a hang rather than for slowness, so the suite has room to grow without the cap becoming the thing that fails:

  • validate: 20 minutes. vitest spawns workers and the voucher suite talks to a local mint, so a child that never exits is the realistic hang.
  • audit: 15 minutes, covering the npm advisory endpoint failing to answer rather than refusing.

workflow_dispatch

The audit job asks npm's advisory database a question whose answer changes without this repository changing. Re-checking it should not require inventing a commit.

What this repository does not have

Worth stating, since it was the expensive bug next door: cache: npm is managed by setup-node and restores from the registry. It does not have nap-java's problem, where an 80 minute artifact was discarded every time the job failed, because actions/cache saves in a post step and post steps are skipped on failure.

Checked rather than assumed.

tcheeric and others added 4 commits August 20, 2026 21:01
release: 0.10.1 — audience host allowlist, signer capabilities, TypeScript floor
docs: NAP specification, tutorials and comparisons
Release 0.11.0: AppSec audit remediation and accumulated develop work

Closes #33, #34, #35, #36, #38.

Breaking: the session cookie now carries Secure by default, so a
deployment terminating TLS nowhere loses its sessions. See UPGRADING.md.

Deploy alongside nap-java 0.9.0: both now put the access token in the
cookie, so a mixed fleet rejects the other side's cookies.
Neither job had timeout-minutes, so both inherited GitHub's 360 minute
default. The same gap in nap-java let a stuck scan run for 50 minutes
before I noticed, and it would have gone to six hours unattended. vitest
spawns workers and the voucher suite talks to a local mint, so a child
that never exits is the realistic way this hangs.

Caps are sized for a hang rather than for slowness: both jobs finish in
about a minute today, so 20 and 15 leave room for the suite to grow
without the cap becoming the thing that fails.

workflow_dispatch for the same reason it was added to nap-java. The audit
job asks npm's advisory database a question whose answer changes without
this repository changing, so re-checking it should not require inventing a
commit.

Nothing here caches on failure. `cache: npm` is managed by setup-node and
restores from the registry, so it does not have nap-java's problem of an
expensive artifact discarded whenever the job fails.
@tcheeric
tcheeric merged commit 5a46763 into develop Sep 24, 2026
5 checks passed
@tcheeric
tcheeric deleted the ci/timeouts-and-dispatch branch September 24, 2026 23:58
tcheeric added a commit that referenced this pull request Sep 25, 2026
ci: bound every job, and allow manual runs

Promotes #48 so master is covered too.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant