Skip to content

ci: bound the release and Dependabot jobs too - #684

Open
dyve wants to merge 1 commit into
mainfrom
ci-timeout-every-workflow
Open

dyve wants to merge 1 commit into
mainfrom
ci-timeout-every-workflow

Conversation

@dyve

@dyve dyve commented Sep 21, 2026

Copy link
Copy Markdown
Member

26.2 added "a 15-minute timeout-minutes to every CI job", and that got applied to ci.yml only. release.yml and the Dependabot workflow were left on GitHub's 6 hour default, in all five Zostera repos. A job that hangs rather than fails burns the whole allowance before anyone notices it is stuck, which is the case the bound exists for, and release.yml is the workflow that publishes to PyPI.

release.yml gets 20 rather than 15. It does everything the ci.yml build job does, uv build, twine check, check-manifest, check-wheel-contents and both smoke tests, and then uploads to PyPI. A bound that fires part way through a publish is worse than one that never fires, so it gets headroom over the job it otherwise mirrors. The Dependabot job gets 15 against a runtime measured in seconds.

PACKAGING.md now states the rule as every job in every workflow, with the values and the reason, so it does not get read as "every job in ci.yml" a second time.

Found while bounding jobs in observation/wrnpro and observation/meetnetten, where the same gap was wider. Both files are on PACKAGING.md's copy-verbatim list, so this propagates unchanged to the four siblings once the current queue of pull requests there is merged.

🤖 Generated with Claude Code

"A 15-minute timeout-minutes to every CI job" in 26.2 was applied to ci.yml
only. release.yml and the Dependabot workflow were left on GitHub's 6 hour
default, in all five Zostera repos. A job that hangs rather than fails burns
the whole allowance before anyone notices.

release.yml gets 20 rather than 15. It does everything the ci.yml build job
does, then uploads to PyPI, and a bound that fires during a publish is worse
than one that never fires at all. Dependabot gets 15, against a runtime in
seconds.

PACKAGING.md now says every job in every workflow carries a bound, so the rule
does not get read as "every job in ci.yml" a second time.

Found while bounding the jobs in observation/wrnpro and observation/meetnetten,
where the same gap was wider.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant