fix(ci): skip install + slow lanes on Windows in main test matrix (#3710)
* fix(ci): skip install + slow lanes on Windows in main test matrix Gates the `Run install tests` and `Run slow tests` steps in `.github/workflows/test.yml` to `matrix.os != 'windows-latest'`. The install lane performs `npm install -g <tarball>` 7× per invocation of release-tarball-smoke.install.test.cjs (1× in the shared before() hook + 1× per of the 6 test cases). On windows-latest each install costs 60–90 s (NTFS + Defender) so the lane alone consumes ~8–9 min on top of the ~7 min already spent on npm ci + build:sdk + unit + integration + security — overflowing the 15-min `timeout-minutes` cap and cancelling the job mid-install. The dedicated install-smoke.yml workflow already excludes Windows from its matrix (ubuntu + macOS only); the weekly windows-compat workflow provides Windows-specific regression coverage. Linux + macOS install and slow lanes remain on main push for parity. Refs #3709 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(deps): bump ws 8.20.0 → 8.20.1 to clear GHSA-58qx-3vcg-4xpx The bug-3588 `npm audit --omit=dev reports zero advisories` test (tests/bug-3588-npm-audit-clean.test.cjs) is failing on main after a new advisory dropped against ws@8.20.0: GHSA-58qx-3vcg-4xpx — Uninitialized memory disclosure ws: range >=8.0.0 <8.20.1 (CVSS 4.4, moderate, CWE-908) Fix: `npm audit fix --omit=dev` at both root and sdk/. Lockfile-only bump to ws@8.20.1; package.json untouched (ws is transitive). `npm audit --omit=dev` reports `found 0 vulnerabilities` in both workspaces after the bump. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
11
.github/workflows/test.yml
vendored
11
.github/workflows/test.yml
vendored
@@ -172,16 +172,23 @@ jobs:
|
||||
run: npm run test:security
|
||||
|
||||
# Install + slow lanes only on main-branch push (not PR CI) so PRs stay fast.
|
||||
# Windows is excluded from the install lane: `npm install -g <tarball>` runs
|
||||
# 7× per release-tarball-smoke.install.test.cjs invocation (1× before-hook
|
||||
# + 6× per-test) and each takes 60–90 s on windows-latest (NTFS + Defender),
|
||||
# so the lane alone consumes ~10 min and blows the 15-min job budget after
|
||||
# earlier steps. Linux + macOS coverage stays here; Windows tarball install
|
||||
# coverage is provided by the weekly windows-compat workflow.
|
||||
- name: Run install tests
|
||||
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
|
||||
if: github.event_name == 'push' && github.ref == 'refs/heads/main' && matrix.os != 'windows-latest'
|
||||
shell: bash
|
||||
run: npm run test:install
|
||||
|
||||
- name: Run slow tests
|
||||
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
|
||||
if: github.event_name == 'push' && github.ref == 'refs/heads/main' && matrix.os != 'windows-latest'
|
||||
shell: bash
|
||||
run: npm run test:slow
|
||||
|
||||
|
||||
# Dedicated coverage job. Runs only on ubuntu/Node 24 (the canonical lane)
|
||||
# because c8 coverage of one suite on one OS is enough signal — running it
|
||||
# across the full matrix would 9x the cost for no extra coverage data.
|
||||
|
||||
6
package-lock.json
generated
6
package-lock.json
generated
@@ -2043,9 +2043,9 @@
|
||||
"license": "ISC"
|
||||
},
|
||||
"node_modules/ws": {
|
||||
"version": "8.20.0",
|
||||
"resolved": "https://registry.npmjs.org/ws/-/ws-8.20.0.tgz",
|
||||
"integrity": "sha512-sAt8BhgNbzCtgGbt2OxmpuryO63ZoDk/sqaB/znQm94T4fCEsy/yV+7CdC1kJhOU9lboAEU7R3kquuycDoibVA==",
|
||||
"version": "8.20.1",
|
||||
"resolved": "https://registry.npmjs.org/ws/-/ws-8.20.1.tgz",
|
||||
"integrity": "sha512-It4dO0K5v//JtTXuPkfEOaI3uUN87iYPnqo/ZzqCoG3g8uhA66QUMs/SrM0YK7/NAu+r4LMh/9dq2A7k+rHs+w==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">=10.0.0"
|
||||
|
||||
6
sdk/package-lock.json
generated
6
sdk/package-lock.json
generated
@@ -2496,9 +2496,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/ws": {
|
||||
"version": "8.20.0",
|
||||
"resolved": "https://registry.npmjs.org/ws/-/ws-8.20.0.tgz",
|
||||
"integrity": "sha512-sAt8BhgNbzCtgGbt2OxmpuryO63ZoDk/sqaB/znQm94T4fCEsy/yV+7CdC1kJhOU9lboAEU7R3kquuycDoibVA==",
|
||||
"version": "8.20.1",
|
||||
"resolved": "https://registry.npmjs.org/ws/-/ws-8.20.1.tgz",
|
||||
"integrity": "sha512-It4dO0K5v//JtTXuPkfEOaI3uUN87iYPnqo/ZzqCoG3g8uhA66QUMs/SrM0YK7/NAu+r4LMh/9dq2A7k+rHs+w==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">=10.0.0"
|
||||
|
||||
Reference in New Issue
Block a user