Skip to content

fix(release-automation): drop the inert npm cache from pre-snapshot validation - #458

Merged
hdamker merged 1 commit into
camaraproject:mainfrom
hdamker:fix/ra-drop-inert-npm-cache
Sep 19, 2026
Merged

hdamker merged 1 commit into
camaraproject:mainfrom
hdamker:fix/ra-drop-inert-npm-cache

Conversation

@hdamker

@hdamker hdamker commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

What type of PR is this?

correction

What this PR does / why we need it:

#448 added cache: npm to both setup-node steps that feed the shared npm ci. The one in validation.yml works as intended, but the one in release-automation-reusable.yml cannot: snapshot creation is slash-command driven, so create-snapshot always runs on an issue_comment event, and the Actions cache token for that event is read-only. Every snapshot run logged cache write denied: token has no writable scopes and carried a failed-save warning annotation, while never populating a cache and having no default-branch entry to restore from. This drops that step's cache inputs and records why, so it does not get re-added.

  • Removes a warning-level annotation from every release snapshot run.
  • Leaves the working cache on the validation path untouched.
  • Corrects the scope claim in validation.yml's comment: entries are scoped per git ref, not per repository, so a pull request's first validation run still pays a cold install and only later pushes to the same PR hit the cache.

Which issue(s) this PR fixes:

No separate issue — follows up #448.

Special notes for reviewers:

Measured after #448 merged:

  • Validation path is verified warm. The canary's second firing re-dispatched all 18 regression/* branches (12 on ReleaseTest, 6 on CommonalitiesTest) against the caches its first firing had populated, and all 18 logged Cache restored from key — https://github.com/camaraproject/tooling/actions/runs/35378091248
  • RA path is read-only. The /create-snapshot round-trip from the RA canary shows Cache mode: read, then the denied save — https://github.com/camaraproject/ReleaseTest/actions/runs/35374610286
  • The trigger event is what decides it. Three RA caller runs on the same repo, same branch, identical permissions: — push → write, issues → read, issue_comment → read. Adding actions: write is not the lever; validation.yml does not declare it either and writes fine.
  • actionlint clean over all workflow files with the argument set from tooling-ci.yml.

Both call sites of shared-actions/run-validation keep the trimmed npm ci --ignore-scripts --no-audit --no-fund --prefer-offline; --prefer-offline simply no-ops where there is no cache.

Changelog input

 release-note
Removed the npm cache from release automation's pre-snapshot validation, where an `issue_comment`-triggered job cannot write one.

Additional documentation

This section can be blank.

docs

…alidation

Snapshot creation is slash-command driven, so the create-snapshot job
always runs on an issue_comment event, whose Actions cache token is
read-only. The step could never populate a cache and had no
default-branch entry to restore from, so its only observable effect was
a failed-save warning annotation on every release run. Also corrects
the cache-scope comment in validation.yml: entries are scoped per git
ref, not per repository.
@hdamker
hdamker merged commit 91bbbba into camaraproject:main Sep 19, 2026
8 checks passed
@hdamker
hdamker deleted the fix/ra-drop-inert-npm-cache branch September 19, 2026 09:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant