ci: bound every job, and allow manual runs - #48
Merged
Merged
Conversation
release: 0.10.1 — audience host allowlist, signer capabilities, TypeScript floor
docs: NAP specification, tutorials and comparisons
Release 0.11.0: AppSec audit remediation and accumulated develop work Closes #33, #34, #35, #36, #38. Breaking: the session cookie now carries Secure by default, so a deployment terminating TLS nowhere loses its sessions. See UPGRADING.md. Deploy alongside nap-java 0.9.0: both now put the access token in the cookie, so a mixed fleet rejects the other side's cookies.
Neither job had timeout-minutes, so both inherited GitHub's 360 minute default. The same gap in nap-java let a stuck scan run for 50 minutes before I noticed, and it would have gone to six hours unattended. vitest spawns workers and the voucher suite talks to a local mint, so a child that never exits is the realistic way this hangs. Caps are sized for a hang rather than for slowness: both jobs finish in about a minute today, so 20 and 15 leave room for the suite to grow without the cap becoming the thing that fails. workflow_dispatch for the same reason it was added to nap-java. The audit job asks npm's advisory database a question whose answer changes without this repository changing, so re-checking it should not require inventing a commit. Nothing here caches on failure. `cache: npm` is managed by setup-node and restores from the registry, so it does not have nap-java's problem of an expensive artifact discarded whenever the job fails.
tcheeric
added a commit
that referenced
this pull request
Sep 25, 2026
ci: bound every job, and allow manual runs Promotes #48 so master is covered too.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Carrying two fixes across from
nap-java, where both were found the hard way.Timeouts
Neither job had
timeout-minutes, so both inherited GitHub's 360 minute default. Innap-javathat same gap let a stuck Dependency-Check scan run for 50 minutes before I noticed, and it would have reached six hours unattended.Both jobs finish in about a minute today. The caps are sized for a hang rather than for slowness, so the suite has room to grow without the cap becoming the thing that fails:
validate: 20 minutes. vitest spawns workers and the voucher suite talks to a local mint, so a child that never exits is the realistic hang.audit: 15 minutes, covering the npm advisory endpoint failing to answer rather than refusing.workflow_dispatchThe audit job asks npm's advisory database a question whose answer changes without this repository changing. Re-checking it should not require inventing a commit.
What this repository does not have
Worth stating, since it was the expensive bug next door:
cache: npmis managed bysetup-nodeand restores from the registry. It does not havenap-java's problem, where an 80 minute artifact was discarded every time the job failed, becauseactions/cachesaves in a post step and post steps are skipped on failure.Checked rather than assumed.