Skip to content

ci: fix macOS/release build (Xcode pin) and optimize workflows - #123

Merged
aelam merged 1 commit into
mainfrom
ci/optimize-workflows
Aug 6, 2026
Merged

aelam merged 1 commit into
mainfrom
ci/optimize-workflows

Conversation

@aelam

@aelam aelam commented Aug 6, 2026

Copy link
Copy Markdown
Owner

Problem

CI and Release stopped compiling. The workflows pinned Xcode 16.2, whose bundled Swift 6.0 is older than this package's swift-tools-version: 6.1. Once the GitHub runner image rotated Xcode away from 16.2, setup-xcode could no longer select it and the build broke.

Fixes

  • Pin Xcode to latest-stable in ci.yml and release.yml (currently Swift 6.3, backward-compatible with the declared 6.1 floor). No more breakage when runner images rotate Xcode.
  • Drop the redundant swift-actions/setup-swift step on macOS — on macOS the Swift toolchain comes from the selected Xcode; installing a second toolchain conflicts with it.

Optimizations

  • Concurrency groups on macOS + Linux workflows — cancel superseded runs on the same ref (saves CI minutes).
  • Least-privilege permissions blocks (contents: read; contents: write for release).
  • timeout-minutes on every job to kill hung runs.
  • Security Scan moved to ubuntu-latest (it's Python + grep only, no Xcode needed) with semgrep installed via pip — much faster/cheaper than a macOS runner.
  • Standardized the lint job onto macos-latest (was macos-14, which won't have current Xcode).

Scope

CI/workflow files only — no source changes.

File Change
.github/workflows/ci.yml Xcode fix, concurrency, permissions, timeouts, security-scan → Linux
.github/workflows/release.yml Xcode fix, permissions, timeout
.github/workflows/linux-ci.yml concurrency, permissions, timeout

🤖 Generated with Claude Code

The workflows pinned Xcode 16.2, whose bundled Swift 6.0 is older than the
package's swift-tools-version (6.1), so CI and Release stopped compiling once
the runner image rotated Xcode away from 16.2.

Fixes:
- Pin Xcode to `latest-stable` in ci.yml and release.yml (currently Swift 6.3,
  backward compatible with the declared 6.1 floor).
- Drop the redundant `swift-actions/setup-swift` step on macOS — the Swift
  toolchain comes from the selected Xcode and installing a second one conflicts.

Optimizations:
- Add concurrency groups to cancel superseded runs (macOS + Linux).
- Add least-privilege `permissions` blocks.
- Add `timeout-minutes` to every job to kill hung runs.
- Move the Security Scan job to `ubuntu-latest` (Python + grep only, no Xcode)
  and install semgrep via pip — much faster/cheaper than a macOS runner.
- Standardize the lint job onto `macos-latest` (was `macos-14`).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@codecov

codecov Bot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 35.61%. Comparing base (7481b0c) to head (edd4d61).

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #123      +/-   ##
==========================================
+ Coverage   34.99%   35.61%   +0.62%     
==========================================
  Files         143      143              
  Lines        5949     5949              
==========================================
+ Hits         2082     2119      +37     
+ Misses       3867     3830      -37     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@aelam
aelam merged commit fd26e4e into main Aug 6, 2026
7 checks passed
@aelam
aelam deleted the ci/optimize-workflows branch August 6, 2026 05:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant