Switch CI to pull_request and remove broken nightly publish workflow - #260
Merged
Merged
Conversation
The nightly publish workflow has failed on every run for ~1.5 years (setup-python can no longer provide Python 3.7 on ubuntu-24.04), so no nightly has been published in that time. Remove it rather than fix it -- installing from source covers the use case. Add an explicit read-only permissions block to pypi_release.yml, which only needs to check out and upload via Twine secrets.
An internal branch with an open PR matched both push: and pull_request:, launching the SageMaker jobs twice per commit. Restrict push to the long-lived branches that publish docs, and keep an explicit tags filter so tagged releases still build versioned docs -- adding a branches filter alone would stop matching tag pushes entirely.
|
Job PR-260-9db7535 is done. |
|
Job PR-260- is done. |
1 similar comment
|
Job PR-260- is done. |
|
Job PR-260-280bb36 is done. |
|
Job PR-260-3c38682 is done. |
|
Job PR-260- is done. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CI trigger
Switches CI from
pull_request_targettopull_request.pull_request_targetrequired apermission_checkjob plus asafe to testlabel to decide whether a PR's code should run, and every job needed a duplicate checkout step to pick up the PR head. Withpull_requestthe trigger itself scopes what runs, so all of that goes away.This is also already broken on
master:actions/checkout@v5now refuses the fork-head checkout the old config relies on, failing with "Refusing to check out fork pull request code from apull_request_targetworkflow" unlessallow-unsafe-pr-checkout: trueis set. So fork PRs get no CI today regardless.Fork PRs can't obtain the CI credentials, so the AWS-touching jobs (
test_general_cloud,test_tabular_cloud,test_timeseries_cloud) andbuild_docare gated ongithub.event.pull_request.head.repo.full_name == github.repository. They skip cleanly on forks rather than failing, leaving lint as the only check. Maintainer branches pushed to this repo still get the full run — as this PR itself shows.permission_checkjob and thesafe to testlabel handlingCONTRIBUTING.mdandtests/README.mdfor the new processPublish workflows
pythonpublish.yml. This nightly has failed on every run for ~1.5 years —setup-pythoncan no longer provide Python 3.7 onubuntu-24.04, so it dies before building and no nightly has been published in that time. Installing from source covers the use case.permissions: contents: readtopypi_release.yml, which previously inherited the repo default. It only needs to check out and upload via the Twine secrets.Note for reviewers: if branch protection lists required status checks, it needs updating —
permission_checkno longer exists, and the guarded jobs now report as skipped on fork PRs.Push trigger
push:was unfiltered, so an internal branch with an open PR matched bothpush:andpull_request:and launched the SageMaker jobs twice per commit. Restricted to the long-lived branches that publish docs, plus an explicittags: ['v*']filter.The tags filter is load-bearing:
push.branchesalone stops matching tag pushes entirely, and tagged releases do run this workflow to publish versioned docs (v0.5.0did on 2026-06-04). Note this PR's own branch no longer gets push runs — only thepull_requestones.