From d3628523844d6ff6b12f95131786d0413e6b5ee7 Mon Sep 17 00:00:00 2001 From: Claude Code Date: Sun, 27 Sep 2026 04:29:10 +0200 Subject: [PATCH] ci(workflows): add job timeout-minutes and concurrency guard Part of a fleet-wide CI-speed pass. ci.yml's three jobs (quality, security, contracts) had no timeout-minutes, so a hung step could run indefinitely and tie up a scarce runner. Added 30min for the build/test jobs (quality, contracts) and 15min for the single-check security scan (Trivy). ci.yml also triggers on both push and pull_request with no branch filter, which fires the full CI suite twice per PR commit. Added the same concurrency group pattern already used elsewhere in the fleet (admin/serv0, admin/s0cial, admin/ppl0, admin/pers0n) to cancel the superseded run instead of changing the triggers themselves. masterplan-lock.yml is schedule-only and not on the hot path, so left untouched. Co-Authored-By: Claude Sonnet 5 --- .gitea/workflows/ci.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index c96e7c6..74503be 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -1,8 +1,12 @@ name: CI (SIAX Cloud) on: [push, pull_request, workflow_dispatch] +concurrency: + group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} + cancel-in-progress: true jobs: quality: runs-on: ubuntu-latest + timeout-minutes: 30 steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 @@ -23,6 +27,7 @@ jobs: run: pnpm run build security: runs-on: ubuntu-latest + timeout-minutes: 15 steps: - uses: actions/checkout@v4 - name: Install Trivy @@ -31,6 +36,7 @@ jobs: run: trivy fs --scanners vuln,secret --severity HIGH,CRITICAL --exit-code 0 . contracts: runs-on: ubuntu-latest + timeout-minutes: 30 steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4