ci: fix macOS/release build (Xcode pin) and optimize workflows - #123
Merged
Merged
Conversation
The workflows pinned Xcode 16.2, whose bundled Swift 6.0 is older than the package's swift-tools-version (6.1), so CI and Release stopped compiling once the runner image rotated Xcode away from 16.2. Fixes: - Pin Xcode to `latest-stable` in ci.yml and release.yml (currently Swift 6.3, backward compatible with the declared 6.1 floor). - Drop the redundant `swift-actions/setup-swift` step on macOS — the Swift toolchain comes from the selected Xcode and installing a second one conflicts. Optimizations: - Add concurrency groups to cancel superseded runs (macOS + Linux). - Add least-privilege `permissions` blocks. - Add `timeout-minutes` to every job to kill hung runs. - Move the Security Scan job to `ubuntu-latest` (Python + grep only, no Xcode) and install semgrep via pip — much faster/cheaper than a macOS runner. - Standardize the lint job onto `macos-latest` (was `macos-14`). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #123 +/- ##
==========================================
+ Coverage 34.99% 35.61% +0.62%
==========================================
Files 143 143
Lines 5949 5949
==========================================
+ Hits 2082 2119 +37
+ Misses 3867 3830 -37 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
CI and Release stopped compiling. The workflows pinned Xcode 16.2, whose bundled Swift 6.0 is older than this package's
swift-tools-version: 6.1. Once the GitHub runner image rotated Xcode away from 16.2,setup-xcodecould no longer select it and the build broke.Fixes
latest-stableinci.ymlandrelease.yml(currently Swift 6.3, backward-compatible with the declared 6.1 floor). No more breakage when runner images rotate Xcode.swift-actions/setup-swiftstep on macOS — on macOS the Swift toolchain comes from the selected Xcode; installing a second toolchain conflicts with it.Optimizations
permissionsblocks (contents: read;contents: writefor release).timeout-minuteson every job to kill hung runs.ubuntu-latest(it's Python + grep only, no Xcode needed) with semgrep installed via pip — much faster/cheaper than a macOS runner.macos-latest(wasmacos-14, which won't have current Xcode).Scope
CI/workflow files only — no source changes.
.github/workflows/ci.yml.github/workflows/release.yml.github/workflows/linux-ci.yml🤖 Generated with Claude Code