You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Adds a push trigger for the main branch to the Conformance Tests workflow so the suite also runs after commits land on main, not only on pull requests.
Change
Under on:, a push: { branches: ["main"] } trigger is added immediately before the existing pull_request trigger.
Behavior
Conformance now runs on every push to main (e.g. after a PR merges), providing post-merge validation of the integrated state.
The existing pull_request trigger and its paths filters are unchanged, so PR-time path filtering behaves exactly as before.
workflow_dispatch, concurrency, and all jobs are untouched.
Note: the push trigger intentionally has no paths filter, so any push to main runs the suite.
No actionable findings. This PR adds a push: { branches: ["main"] } trigger to .github/workflows/conformance-tests.yml so the conformance suite also runs after commits land on main.
The change is correct: the YAML is valid, same-repo push events have access to the required secrets and id-token: write for AWS OIDC, and AWS_REGION falls back to us-west-2 since github.event.inputs is undefined outside workflow_dispatch. The existing global concurrency lock (conformance-tests-global, cancel-in-progress: false) already serializes runs against the shared per-suite CloudFormation stacks, so a post-merge push run safely queues behind any in-flight PR run rather than colliding on the shared --no-cleanup stacks. The pull_request trigger and its paths filter are unchanged.
Residual (non-blocking) risk, not a defect:
The push trigger deliberately has no paths filter (called out in the PR description), so the full conformance suite — which deploys real AWS infrastructure and holds the repo-wide serialized lock — now runs on every push to main, including doc-only or unrelated-package changes. This increases cost and queue contention on the global lock.
With cancel-in-progress: false and a static concurrency group, only one run can be pending at a time; rapid successive pushes to main can cause an earlier queued run to be superseded by a newer one, so not literally every push completes a conformance run. If per-push post-merge validation matters, consider mirroring the pull_requestpaths filter on the push trigger.
Reviewed commit b75570d92b4301978a979722fd15085caca9fdf2. Workflow run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a
pushtrigger for themainbranch to the Conformance Tests workflow so the suite also runs after commits land onmain, not only on pull requests.Change
Under
on:, apush: { branches: ["main"] }trigger is added immediately before the existingpull_requesttrigger.Behavior
main(e.g. after a PR merges), providing post-merge validation of the integrated state.pull_requesttrigger and itspathsfilters are unchanged, so PR-time path filtering behaves exactly as before.workflow_dispatch, concurrency, and all jobs are untouched.Note: the
pushtrigger intentionally has nopathsfilter, so any push tomainruns the suite.