From 661b84d889109548d8332b5b24916ae4587d2793 Mon Sep 17 00:00:00 2001 From: Felix Kotschenreuther Date: Sat, 26 Sep 2026 08:42:53 +0200 Subject: [PATCH 1/2] ci: cancel superseded PR runs Co-Authored-By: Claude --- .github/workflows/ci.yml | 7 +++++++ .github/workflows/docs.yml | 7 +++++++ 2 files changed, 14 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 5658b97..4eb81ca 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -5,6 +5,13 @@ on: branches: [main] pull_request: +# A newer push to the same PR supersedes the run in flight, so cancel it rather than +# let both occupy the org's concurrent-job slots. Pushes to main are never cancelled: +# every main commit keeps its own result. +concurrency: + group: ci-${{ github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + # Least privilege: this workflow only ever reads the checkout. Without an explicit # block the token inherits the org default, which is often read-write. permissions: diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index 51e437e..cb7df8b 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -34,6 +34,13 @@ on: - ".github/workflows/docs.yml" - ".github/scripts/docs-staleness.mjs" +# A newer push to the same PR supersedes the run in flight, so cancel it rather than +# let both occupy the org's concurrent-job slots. Pushes to main are never cancelled: +# every main commit keeps its own result. +concurrency: + group: docs-${{ github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + permissions: contents: read From d99ec83df8c6bccdfb5b5b5c993b9ec8e9502589 Mon Sep 17 00:00:00 2001 From: Felix Kotschenreuther Date: Sat, 26 Sep 2026 11:04:07 +0200 Subject: [PATCH 2/2] ci: give main pushes a per-commit concurrency group A shared group keeps only one pending run and cancels the older pending one when a third push arrives, even with cancel-in-progress off, so a burst of merges to main could leave a commit without a CI/Docs result. Verified with a probe workflow: A success, B cancelled, C success; with the per-SHA key all three ran. --- .github/workflows/ci.yml | 6 ++++-- .github/workflows/docs.yml | 6 ++++-- 2 files changed, 8 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4eb81ca..7d14884 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -7,9 +7,11 @@ on: # A newer push to the same PR supersedes the run in flight, so cancel it rather than # let both occupy the org's concurrent-job slots. Pushes to main are never cancelled: -# every main commit keeps its own result. +# every main commit keeps its own result. That needs a per-commit group for pushes — +# a shared group still holds only one pending run and cancels the older pending one +# when a third arrives, even with cancel-in-progress off. concurrency: - group: ci-${{ github.ref }} + group: ${{ github.workflow }}-${{ github.event_name == 'pull_request' && github.ref || github.sha }} cancel-in-progress: ${{ github.event_name == 'pull_request' }} # Least privilege: this workflow only ever reads the checkout. Without an explicit diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index cb7df8b..a817c0e 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -36,9 +36,11 @@ on: # A newer push to the same PR supersedes the run in flight, so cancel it rather than # let both occupy the org's concurrent-job slots. Pushes to main are never cancelled: -# every main commit keeps its own result. +# every main commit keeps its own result. That needs a per-commit group for pushes — +# a shared group still holds only one pending run and cancels the older pending one +# when a third arrives, even with cancel-in-progress off. concurrency: - group: docs-${{ github.ref }} + group: ${{ github.workflow }}-${{ github.event_name == 'pull_request' && github.ref || github.sha }} cancel-in-progress: ${{ github.event_name == 'pull_request' }} permissions: