Skip to content

feat: honour [skip-ci] org-wide; add a reusable revdeps workflow - #34

Merged
eliotmcintire merged 1 commit into
mainfrom
feat/revdeps-reusable-and-skip-ci
Sep 3, 2026
Merged

eliotmcintire merged 1 commit into
mainfrom
feat/revdeps-reusable-and-skip-ci

Conversation

@eliotmcintire

Copy link
Copy Markdown
Contributor

Two things callers were each solving for themselves. Both surfaced while
converting Require to thin callers (PredictiveEcology/Require#212).

Base is main — this repo has no development branch.

1. [skip-ci], org-wide

GitHub stops a run itself for its own keywords ([skip ci], [ci skip],
[no ci], [skip actions], [actions skip]). The hyphenated [skip-ci]
is a PE convention it does not know about, so every caller that wanted it was
carrying its own if: on a hand-rolled job — and moving to a thin caller
silently dropped it
, because these workflows had no equivalent. Require hit
exactly that. The guard now lives here, on all five reusable workflows.

One deliberate difference from the hand-rolled versions: this tests
github.event.head_commit.message, the tip of the push, matching GitHub's
own semantics. The old copies tested github.event.commits[0].message — the
oldest commit in the push — so a [skip-ci] on the tip of a multi-commit
push used to be ignored. head_commit is null on pull_request and
schedule, and contains(null, …) is false, so those always run.

2. New reusable workflow revdeps.yaml

revdeps-check is a composite action, so every caller has to write the same
job harness around it: checkout, geospatial system libraries, R, dependency
install. quickPlot and Require had each written one — that is the
duplication this removes.

Defaults are deliberately more conservative than the incumbent:

  • A single ubuntu-latest/release leg. quickPlot's version ran a
    three-OS matrix on every pull_request. The composite action's own README
    warns these checks are too heavy for standard runners, and each revdep gets a
    full R CMD check with its dependency closure installed first — that is
    hours of runner time on a signal almost no PR changes. config takes a JSON
    matrix for packages that genuinely need more.
  • Callers own their triggers. workflow_dispatch plus a weekly schedule
    is the sane default.

Inputs: config, cranonly, quiet, timeout, extra-packages,
extra-repositories.

The cranonly docs note something worth writing down: revdep sets go stale in
both directions. Require's stored revdep/cran.md said "no reverse
dependencies" because SpaDES.core had been archived on 2026-07-13 — and
SpaDES.core is back at 3.2.1, so that cached conclusion is now wrong.

Not added to self-test

self-test.yaml exercises the composite actions through local ./ refs, which
reusable workflows cannot use, and a revdep run is far too heavy to gate merges
on.

Risk

Purely additive. No existing caller changes behaviour unless it puts
[skip-ci] in a commit message. Follow-up worth doing separately: convert
quickPlot's hand-rolled revdeps.yaml to a thin caller — it is also pinned to
install-spatial-deps@v0.3 and actions/checkout@v4.

🤖 Generated with Claude Code

https://claude.ai/code/session_01NNLtKFXrNPN2XvuAjsy4Sy

Two things callers were each solving for themselves.

## [skip-ci]

GitHub stops a run itself for its own keywords ([skip ci], [ci skip],
[no ci], [skip actions], [actions skip]), but the hyphenated [skip-ci] is
a PE convention it does not know about. Every caller that wanted it was
carrying its own `if:` on a hand-rolled job -- and moving to a thin caller
silently dropped it, since these workflows had no equivalent. The guard
now lives here.

It tests `github.event.head_commit.message`, the tip of the push, which
matches GitHub's own semantics. The hand-rolled versions tested
`github.event.commits[0].message` -- the OLDEST commit in the push -- so a
[skip-ci] on the tip of a multi-commit push used to be ignored. null on
pull_request and schedule, so those always run.

## revdeps.yaml

`revdeps-check` is a composite action, so every caller had to write the
same job harness around it: checkout, geospatial system libraries, R, and
the dependency install. quickPlot and Require had each written one.

The default is a single ubuntu-latest/release leg. quickPlot's version ran
a three-OS matrix on every pull_request, which spends hours of runner time
on a signal almost no PR changes; `config` takes a JSON matrix for packages
that genuinely need more. Callers own their triggers -- workflow_dispatch
plus a weekly schedule is the sane default, given the composite action's
own warning that these checks are too heavy for standard runners.

Not added to self-test.yaml: that exercises the composite actions through
local `./` refs, which reusable workflows cannot use, and a revdep run is
far too heavy to gate merges on.

Purely additive -- no existing caller changes behaviour unless it puts
[skip-ci] in a commit message.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NNLtKFXrNPN2XvuAjsy4Sy
eliotmcintire added a commit to PredictiveEcology/Require that referenced this pull request Sep 3, 2026
Follows PredictiveEcology/actions#34, which adds both.

revdeps.yaml drops from 49 lines to 24: the job harness it was carrying
(checkout, geospatial system libraries, R, dependency install) is the
same one quickPlot had written, so it belongs upstream rather than here.
Adds the weekly schedule alongside workflow_dispatch.

The [skip-ci] caveat in R-CMD-check.yaml is gone -- the shared workflows
honour it now, so a thin caller no longer loses it. split-library-check,
the one job we still own, moves from commits[0] to head_commit to match
the shared guard: the tip of the push rather than the oldest commit in it.

Depends on PredictiveEcology/actions#34 being merged; revdeps is
workflow_dispatch/schedule only, so nothing here runs it before then.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NNLtKFXrNPN2XvuAjsy4Sy
@eliotmcintire
eliotmcintire merged commit 1b8eb4d into main Sep 3, 2026
1 check passed
eliotmcintire added a commit that referenced this pull request Sep 4, 2026
Every SpaDES module repository carries a hand-generated copy of this job,
written once by SpaDES.core::use_gha() and never regenerated. The survey in
#36 found 74 repositories carrying it across 96 repository/branch
combinations, in two generations that had drifted apart: 46 combinations
still on ubuntu-20.04 with checkout@v2 and setup-r@v1, and 50 on the newer
shape pinning five actions from this repository at @v0.2, @v0 or @v0.0.1.

Those pins are the main thing blocking retirement of v0.1-v0.5. A caller now
supplies its triggers and the module name; the pins live here and move once.

Fixes carried in by the move:

- [skip-ci] tested commits[0], the OLDEST commit in a push, and there is no
  commits field at all on pull_request -- so it worked on neither. Now uses
  head_commit, as in #34.
- No concurrency group, so superseded runs were never cancelled (#30).
- The hand-written apt-get install had no apt-get update, no retries and no
  timeout. That is the shape that left two LandWebUtils jobs sitting 6h on
  2026-08-19. Now uses the same retry wrapper as install-spatial-deps.
- The commit step ran on pull_request too, where github.ref is
  refs/pull/N/merge and the push cannot succeed; it failed silently every
  time, swallowed by `|| echo "No changes to commit"`. Now push-only.

Rendering and committing are separate jobs, as in citation.yaml (#35):
rendering installs the module's dependency tree and then executes the
module's own .Rmd, which must not share a job with a write-scoped token.

setup-r-deps is deliberately not used here. It delegates to
r-lib/actions/setup-r-dependencies, which resolves from a DESCRIPTION, and
modules have none -- their dependencies come from SpaDES.core::packages().
The apt hardening is reproduced instead.

The second install-Rmd-pkgs call is preserved rather than dropped: the
generated file had it, installing SpaDES can move versions the first call
settled, and #36 flags it for someone with the history to confirm or remove.

Refs #36.


Claude-Session: https://claude.ai/code/session_015ZoicL7829pkb5ZbS5Ciww

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@eliotmcintire
eliotmcintire deleted the feat/revdeps-reusable-and-skip-ci branch September 9, 2026 21:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant