diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 5658b97..7d14884 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -5,6 +5,15 @@ on: branches: [main] pull_request: +# A newer push to the same PR supersedes the run in flight, so cancel it rather than +# let both occupy the org's concurrent-job slots. Pushes to main are never cancelled: +# every main commit keeps its own result. That needs a per-commit group for pushes — +# a shared group still holds only one pending run and cancels the older pending one +# when a third arrives, even with cancel-in-progress off. +concurrency: + group: ${{ github.workflow }}-${{ github.event_name == 'pull_request' && github.ref || github.sha }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + # Least privilege: this workflow only ever reads the checkout. Without an explicit # block the token inherits the org default, which is often read-write. permissions: diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index 51e437e..a817c0e 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -34,6 +34,15 @@ on: - ".github/workflows/docs.yml" - ".github/scripts/docs-staleness.mjs" +# A newer push to the same PR supersedes the run in flight, so cancel it rather than +# let both occupy the org's concurrent-job slots. Pushes to main are never cancelled: +# every main commit keeps its own result. That needs a per-commit group for pushes — +# a shared group still holds only one pending run and cancels the older pending one +# when a third arrives, even with cancel-in-progress off. +concurrency: + group: ${{ github.workflow }}-${{ github.event_name == 'pull_request' && github.ref || github.sha }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + permissions: contents: read