Skip to content

Switch CI to pull_request and remove broken nightly publish workflow - #260

Merged
shchur merged 4 commits into
masterfrom
switch-to-pull-request
Aug 7, 2026
Merged

shchur merged 4 commits into
masterfrom
switch-to-pull-request

Conversation

@shchur

@shchur shchur commented Jul 31, 2026 •

Copy link
Copy Markdown
Collaborator

CI trigger

Switches CI from pull_request_target to pull_request.

pull_request_target required a permission_check job plus a safe to test label to decide whether a PR's code should run, and every job needed a duplicate checkout step to pick up the PR head. With pull_request the trigger itself scopes what runs, so all of that goes away.

This is also already broken on master: actions/checkout@v5 now refuses the fork-head checkout the old config relies on, failing with "Refusing to check out fork pull request code from a pull_request_target workflow" unless allow-unsafe-pr-checkout: true is set. So fork PRs get no CI today regardless.

Fork PRs can't obtain the CI credentials, so the AWS-touching jobs (test_general_cloud, test_tabular_cloud, test_timeseries_cloud) and build_doc are gated on github.event.pull_request.head.repo.full_name == github.repository. They skip cleanly on forks rather than failing, leaving lint as the only check. Maintainer branches pushed to this repo still get the full run — as this PR itself shows.

  • Drop the permission_check job and the safe to test label handling
  • Collapse the duplicated per-job checkout steps into one
  • Add the fork guard to the four jobs needing AWS credentials or PR write access
  • Update CONTRIBUTING.md and tests/README.md for the new process

Publish workflows

  • Delete pythonpublish.yml. This nightly has failed on every run for ~1.5 years — setup-python can no longer provide Python 3.7 on ubuntu-24.04, so it dies before building and no nightly has been published in that time. Installing from source covers the use case.
  • Add permissions: contents: read to pypi_release.yml, which previously inherited the repo default. It only needs to check out and upload via the Twine secrets.

Note for reviewers: if branch protection lists required status checks, it needs updating — permission_check no longer exists, and the guarded jobs now report as skipped on fork PRs.

Push trigger

push: was unfiltered, so an internal branch with an open PR matched both push: and pull_request: and launched the SageMaker jobs twice per commit. Restricted to the long-lived branches that publish docs, plus an explicit tags: ['v*'] filter.

The tags filter is load-bearing: push.branches alone stops matching tag pushes entirely, and tagged releases do run this workflow to publish versioned docs (v0.5.0 did on 2026-06-04). Note this PR's own branch no longer gets push runs — only the pull_request ones.

shchur added 2 commits July 31, 2026 12:31
The nightly publish workflow has failed on every run for ~1.5 years
(setup-python can no longer provide Python 3.7 on ubuntu-24.04), so no
nightly has been published in that time. Remove it rather than fix it --
installing from source covers the use case.

Add an explicit read-only permissions block to pypi_release.yml, which
only needs to check out and upload via Twine secrets.
@shchur shchur changed the title Switch CI trigger from pull_request_target to pull_request Switch CI to pull_request and remove broken nightly publish workflow Jul 31, 2026
@shchur
shchur requested a review from prateekdesai04 July 31, 2026 12:47
An internal branch with an open PR matched both push: and pull_request:,
launching the SageMaker jobs twice per commit. Restrict push to the
long-lived branches that publish docs, and keep an explicit tags filter
so tagged releases still build versioned docs -- adding a branches filter
alone would stop matching tag pushes entirely.
@github-actions

Copy link
Copy Markdown

Job PR-260-9db7535 is done.
Docs are uploaded to https://d12sc05jpx1wj5.cloudfront.net/PR-260/9db7535/index.html

@github-actions

Copy link
Copy Markdown

Job PR-260- is done.
Docs are uploaded to https://d12sc05jpx1wj5.cloudfront.net/PR-260//index.html

1 similar comment
@github-actions

Copy link
Copy Markdown

Job PR-260- is done.
Docs are uploaded to https://d12sc05jpx1wj5.cloudfront.net/PR-260//index.html

@github-actions

Copy link
Copy Markdown

Job PR-260-280bb36 is done.
Docs are uploaded to https://d12sc05jpx1wj5.cloudfront.net/PR-260/280bb36/index.html

@shchur
shchur merged commit 9b04152 into master Aug 7, 2026
12 checks passed
@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown

Job PR-260-3c38682 is done.
Docs are uploaded to https://d12sc05jpx1wj5.cloudfront.net/PR-260/3c38682/index.html

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown

Job PR-260- is done.
Docs are uploaded to https://d12sc05jpx1wj5.cloudfront.net/PR-260//index.html

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant