Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/workflows/dependabot-auto-approve-and-merge.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ permissions:
jobs:
dependabot:
runs-on: ubuntu-latest
timeout-minutes: 15
# Check the actor, only run for Dependabot PRs, prevent failing on non-Dependabot PRs.
if: ${{ github.actor == 'dependabot[bot]' }}
steps:
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ on:
jobs:
run:
runs-on: ubuntu-latest
timeout-minutes: 20
environment:
name: pypi
permissions:
Expand Down
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@

## Unreleased

- Add `timeout-minutes` to the `release.yml` and Dependabot workflow jobs, which were left unbounded when the CI jobs got theirs.
- Test on Python 3.15 (release candidate) against Django 6.1 and `main`. The job is
non-blocking and 3.15 is not yet advertised as supported.
- Remove the `<7.0` upper bound on the `Django` dependency.
Expand Down
6 changes: 6 additions & 0 deletions PACKAGING.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,12 @@ as a PR in that sibling's own repo — never push straight to `main`.
`apt-get update` is a known hang risk — it once stalled on an unreachable Ubuntu mirror
and burned six hours before GitHub's cap; `timeout-minutes` on every job bounds it.

Every job in every workflow carries `timeout-minutes`. Without it a job falls back to
GitHub's 6 hour default, and a job that hangs rather than fails burns the whole allowance
before anyone notices. 15 minutes is the default here, 20 where a job builds and publishes
(`release.yml`). This was once read as "every job in `ci.yml`", which left `release.yml` and
the Dependabot workflow unbounded in all five repos until 2026-09.

## Synced with per-package substitution

`pyproject.toml` sections `[build-system]`, `[tool.uv.build-backend]`, `[tool.check-manifest]`,
Expand Down
Loading