Skip to content

ci: set cache-mode on release workflows - #306

Merged
MarshallOfSound merged 1 commit into
mainfrom
ci/cache-mode
Oct 6, 2026
Merged

MarshallOfSound merged 1 commit into
mainfrom
ci/cache-mode

Conversation

@claude

@claude claude Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Requested by David Sanders · Slack thread

Before: Whether a release run touched the GitHub Actions cache depended on per-step configuration. The Release workflow (push to main / 3-x-y) has no explicit cache opt-out on its setup-node step, and the test job it calls via uses: ./.github/workflows/test.yml runs with whatever cache settings test.yml has. Nothing enforced a "no cache on release" intent at the workflow level, so a step or action that restored a cache entry during a publish would silently be allowed.

After: The Release workflow declares cache-mode: none at the top level, so every job in a release run — including the test jobs pulled in from test.yml via uses: — is denied cache access by the runner regardless of what individual steps or actions ask for. A denied cache restore logs a message and continues as a cache miss; a denied cache save logs and becomes a no-op, so the release does not fail because of this setting. PR CI (test.yml on its own triggers) is untouched and keeps caching as before.

GitHub's new workflow-level cache-mode key makes this a declarative, enforced setting rather than a convention (see changelog and workflow syntax reference), which closes the cache-poisoning avenue on the path that publishes to npm.

How: Adds cache-mode: none (with a one-line comment) directly after the top-level permissions: {} block in .github/workflows/release.yml. No other lines changed. The file parses as YAML and zizmor 1.30.1 accepts the new key with no new findings. Note that PR CI does not exercise the release workflow, so the first push to main that triggers a semantic release after merge is the real test of this change.

🤖 Generated with Claude Code

https://claude.ai/code/session_01MYe3WCXtgiqomNuVQdi4Yd


Generated by Claude Code

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MYe3WCXtgiqomNuVQdi4Yd
@dsanders11
dsanders11 marked this pull request as ready for review September 18, 2026 22:39
@dsanders11
dsanders11 requested review from a team as code owners September 18, 2026 22:39
@MarshallOfSound
MarshallOfSound enabled auto-merge (squash) October 6, 2026 22:25
@MarshallOfSound
MarshallOfSound merged commit 927c214 into main Oct 6, 2026
8 checks passed
@MarshallOfSound
MarshallOfSound deleted the ci/cache-mode branch October 6, 2026 22:25
@electron-npm-package-publisher

Copy link
Copy Markdown

🎉 This PR is included in version 4.37.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants