From 6c4ad709c8da77a5ffa2613f8e3a2f5f81ab3f76 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miguel=20=C3=81ngel?= Date: Fri, 25 Sep 2026 11:44:42 -0400 Subject: [PATCH 1/2] ci: stop running CodeQL on merge queue groups, where its upload races the merge The code scanning rule does not apply to merge queue groups, and the queue deletes a group ref when it merges, so the upload failed on about half the groups. Pull requests and pushes to main keep scanning. --- .github/workflows/codeql.yml | 4 ++-- package.json | 2 +- scripts/merge-queue-workflows.test.mjs | 23 +++++++++++++++++++++++ 3 files changed, 26 insertions(+), 3 deletions(-) create mode 100644 scripts/merge-queue-workflows.test.mjs diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index b0e717db61..48897827cb 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -10,9 +10,9 @@ # changes show up as a normal PR diff. name: CodeQL +# No merge_group: the code scanning rule does not apply to merge queue groups, +# and the queue deletes a group's ref when it merges, before the upload lands. on: - merge_group: - types: [checks_requested] workflow_dispatch: push: branches: [main] diff --git a/package.json b/package.json index d7cb5d63c9..baaae21297 100644 --- a/package.json +++ b/package.json @@ -52,7 +52,7 @@ "player:perf": "bun run --filter @hyperframes/player perf", "format:check": "oxfmt --check .", "knip": "knip", - "test:scripts": "node --import tsx --test scripts/animejs-v4-guidance.test.mjs scripts/check-tracked-artifacts.test.mjs scripts/check-registry-set-delta.test.mjs scripts/check-no-main-deletions.test.mjs scripts/check-pr-captures.test.mjs scripts/check-comment-citations.test.mjs scripts/comments-workflow.test.mjs scripts/comment-ratchet.test.mjs scripts/check-docs-snippet-motion.test.mjs scripts/registry-target-paths.test.mjs scripts/check-workspace-contracts.test.mjs scripts/check-media-use-copy-parity.test.mjs scripts/check-svg-sanitize-parity.test.mjs scripts/check-media-use-svg-sanitize-generated.test.mjs scripts/check-package-cycles.test.mjs scripts/check-cli-process-ownership.test.mjs scripts/check-large-files.test.mjs scripts/package-subpaths.test.mjs scripts/validate-release-channel.test.mjs scripts/publish-workflow.test.mjs scripts/pr-edit-concurrency.test.mjs scripts/install-workspace-dependencies.test.mjs scripts/draft-changelog.test.ts scripts/set-version.test.ts scripts/release-prepare.test.ts scripts/cli-options.test.ts scripts/changelog-weekly.test.ts scripts/claude-plugin-compression.test.ts scripts/catalog-payload-assets.test.ts scripts/host-registry-assets.test.ts scripts/catalog-preview-temp.test.ts scripts/catalog-hosted-files.test.ts scripts/player-cdn-pin.test.ts scripts/studio-runtime-smoke.test.mjs scripts/verify-packed-manifests.test.mjs scripts/lint-skills.test.mjs scripts/creator-editing-recipes.test.mjs packages/gcp-cloud-run/check-dockerfile-workspaces.test.mjs packages/core/scripts/writeGeneratedFile.test.ts scripts/catalog-publication.test.mjs scripts/ci/resolve-workflow-pr.test.mjs scripts/check-catalog-source-pr.test.mjs scripts/generate-registry-items.test.ts scripts/catalog-drift.test.ts scripts/catalog-fetch-mirror.test.ts scripts/catalog-script-inlining.test.ts scripts/catalog-detail.test.ts scripts/generate-catalog-pages.test.ts scripts/verify-catalog-payloads.test.ts scripts/registry-skill-files.test.ts scripts/creator-editing-capabilities.test.mjs scripts/generate-catalog-previews.test.ts scripts/registry-primitive-payloads.test.ts registry/components/pan-stations/pan-stations.test.mjs && vitest run scripts/catalog/ scripts/contrastRatchet.test.ts scripts/generate-catalog-payloads.test.ts", + "test:scripts": "node --import tsx --test scripts/animejs-v4-guidance.test.mjs scripts/check-tracked-artifacts.test.mjs scripts/check-registry-set-delta.test.mjs scripts/check-no-main-deletions.test.mjs scripts/check-pr-captures.test.mjs scripts/check-comment-citations.test.mjs scripts/comments-workflow.test.mjs scripts/comment-ratchet.test.mjs scripts/check-docs-snippet-motion.test.mjs scripts/registry-target-paths.test.mjs scripts/check-workspace-contracts.test.mjs scripts/check-media-use-copy-parity.test.mjs scripts/check-svg-sanitize-parity.test.mjs scripts/check-media-use-svg-sanitize-generated.test.mjs scripts/check-package-cycles.test.mjs scripts/check-cli-process-ownership.test.mjs scripts/check-large-files.test.mjs scripts/package-subpaths.test.mjs scripts/validate-release-channel.test.mjs scripts/publish-workflow.test.mjs scripts/pr-edit-concurrency.test.mjs scripts/merge-queue-workflows.test.mjs scripts/install-workspace-dependencies.test.mjs scripts/draft-changelog.test.ts scripts/set-version.test.ts scripts/release-prepare.test.ts scripts/cli-options.test.ts scripts/changelog-weekly.test.ts scripts/claude-plugin-compression.test.ts scripts/catalog-payload-assets.test.ts scripts/host-registry-assets.test.ts scripts/catalog-preview-temp.test.ts scripts/catalog-hosted-files.test.ts scripts/player-cdn-pin.test.ts scripts/studio-runtime-smoke.test.mjs scripts/verify-packed-manifests.test.mjs scripts/lint-skills.test.mjs scripts/creator-editing-recipes.test.mjs packages/gcp-cloud-run/check-dockerfile-workspaces.test.mjs packages/core/scripts/writeGeneratedFile.test.ts scripts/catalog-publication.test.mjs scripts/ci/resolve-workflow-pr.test.mjs scripts/check-catalog-source-pr.test.mjs scripts/generate-registry-items.test.ts scripts/catalog-drift.test.ts scripts/catalog-fetch-mirror.test.ts scripts/catalog-script-inlining.test.ts scripts/catalog-detail.test.ts scripts/generate-catalog-pages.test.ts scripts/verify-catalog-payloads.test.ts scripts/registry-skill-files.test.ts scripts/creator-editing-capabilities.test.mjs scripts/generate-catalog-previews.test.ts scripts/registry-primitive-payloads.test.ts registry/components/pan-stations/pan-stations.test.mjs && vitest run scripts/catalog/ scripts/contrastRatchet.test.ts scripts/generate-catalog-payloads.test.ts", "typecheck:scripts": "tsc --noEmit -p scripts/tsconfig.json", "test:skills": "node --test 'skills/**/*.test.mjs' 'packages/cli/src/media-use/**/*.test.mjs'", "generate:previews": "tsx scripts/generate-template-previews.ts", diff --git a/scripts/merge-queue-workflows.test.mjs b/scripts/merge-queue-workflows.test.mjs new file mode 100644 index 0000000000..b97dcbee0a --- /dev/null +++ b/scripts/merge-queue-workflows.test.mjs @@ -0,0 +1,23 @@ +import assert from "node:assert/strict"; +import { readdirSync, readFileSync } from "node:fs"; +import { join } from "node:path"; +import test from "node:test"; +import { parse } from "yaml"; + +const workflowsDir = join(import.meta.dirname, "..", ".github", "workflows"); + +// The queue waits only for required checks and deletes a group's ref when it merges, +// so any other workflow on merge_group races that deletion and fails at random. +test("only the workflows that report required checks run on merge queue groups", () => { + const queued = readdirSync(workflowsDir).filter( + (file) => + file.endsWith(".yml") && + parse(readFileSync(join(workflowsDir, file), "utf8")).on?.merge_group !== undefined, + ); + assert.deepEqual(queued.sort(), [ + "ci.yml", + "pr-captures.yml", + "regression.yml", + "windows-render.yml", + ]); +}); From b287850bd60d017abecb6651174d72a2e3e05d5e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miguel=20=C3=81ngel?= Date: Fri, 25 Sep 2026 12:04:50 -0400 Subject: [PATCH 2/2] ci: catch merge_group in any trigger form and say the upload race is intermittent --- .github/workflows/codeql.yml | 2 +- scripts/merge-queue-workflows.test.mjs | 6 ++++-- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 48897827cb..159b501b68 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -11,7 +11,7 @@ name: CodeQL # No merge_group: the code scanning rule does not apply to merge queue groups, -# and the queue deletes a group's ref when it merges, before the upload lands. +# and the queue often merges a group and deletes its ref before the upload lands. on: workflow_dispatch: push: diff --git a/scripts/merge-queue-workflows.test.mjs b/scripts/merge-queue-workflows.test.mjs index b97dcbee0a..983fd8b35d 100644 --- a/scripts/merge-queue-workflows.test.mjs +++ b/scripts/merge-queue-workflows.test.mjs @@ -5,14 +5,16 @@ import test from "node:test"; import { parse } from "yaml"; const workflowsDir = join(import.meta.dirname, "..", ".github", "workflows"); +const events = (on) => + typeof on === "string" ? [on] : Array.isArray(on) ? on : Object.keys(on ?? {}); // The queue waits only for required checks and deletes a group's ref when it merges, // so any other workflow on merge_group races that deletion and fails at random. test("only the workflows that report required checks run on merge queue groups", () => { const queued = readdirSync(workflowsDir).filter( (file) => - file.endsWith(".yml") && - parse(readFileSync(join(workflowsDir, file), "utf8")).on?.merge_group !== undefined, + /\.ya?ml$/.test(file) && + events(parse(readFileSync(join(workflowsDir, file), "utf8")).on).includes("merge_group"), ); assert.deepEqual(queued.sort(), [ "ci.yml",