From b9b13f8c635ec69b705c39e970f38d5b5f135e1b Mon Sep 17 00:00:00 2001 From: Michael Ernst Date: Sat, 19 Sep 2026 19:33:44 -0700 Subject: [PATCH 1/2] Keep Actions caches under the repository's 10GB quota The repository held 10.78GB of caches against a 10GB quota, so GitHub was evicting caches that jobs were about to use. CodeQL accounted for 5.97GB of that, and closed pull requests for another 1.3GB. Replace code scanning's default setup with this advanced setup, which is the only form in which "dependency-caching" can be turned off. Each Java dependency cache holds about 1GB of "~/.m2/repository" and "~/.gradle/caches", and its key covers every "*.gradle" file, so several of them existed at once. Delete a pull request's caches when it closes, rather than waiting the 7 days after which GitHub removes an unused cache. Co-Authored-By: Claude Opus 5 --- .github/workflows/cache-cleanup.yaml | 46 +++++++++++++++++++++ .github/workflows/codeql.yaml | 61 ++++++++++++++++++++++++++++ 2 files changed, 107 insertions(+) create mode 100644 .github/workflows/cache-cleanup.yaml create mode 100644 .github/workflows/codeql.yaml diff --git a/.github/workflows/cache-cleanup.yaml b/.github/workflows/cache-cleanup.yaml new file mode 100644 index 000000000000..480f79160af0 --- /dev/null +++ b/.github/workflows/cache-cleanup.yaml @@ -0,0 +1,46 @@ +# Delete the Actions caches that a pull request created, as soon as it closes. +# Caches count against a repository-wide 10GB quota, and GitHub evicts the +# least recently used cache once that is exceeded, so a closed pull request's +# caches would otherwise evict caches that are still in use. +name: Cache cleanup + +# "pull_request_target" rather than "pull_request", because under +# "pull_request" a pull request from a fork gets a read-only token, which +# cannot delete a cache. This workflow runs no code from the pull request, +# which is what makes "pull_request_target" safe here. +"on": + pull_request_target: + types: + - closed + +permissions: + actions: write + +jobs: + cleanup: + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - name: Delete the caches of the closed pull request + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GH_REPO: ${{ github.repository }} + HEAD_REF: ${{ github.event.pull_request.head.ref }} + HEAD_REPO: ${{ github.event.pull_request.head.repo.full_name }} + PR_NUMBER: ${{ github.event.pull_request.number }} + THIS_REPO: ${{ github.repository }} + run: | + refs="refs/pull/${PR_NUMBER}/merge" + # A pull request from a branch of this repository also ran the "push" + # trigger, under the branch's own ref, and so has a second set of + # caches. + if [ "$HEAD_REPO" = "$THIS_REPO" ]; then + refs="$refs refs/heads/${HEAD_REF}" + fi + for ref in $refs; do + echo "Deleting the caches of $ref" + ids="$(gh cache list --ref "$ref" --limit 100 --json id --jq '.[].id' || true)" + for id in $ids; do + gh cache delete "$id" || true + done + done diff --git a/.github/workflows/codeql.yaml b/.github/workflows/codeql.yaml new file mode 100644 index 000000000000..a52bc2db7432 --- /dev/null +++ b/.github/workflows/codeql.yaml @@ -0,0 +1,61 @@ +# CodeQL analysis, in place of code scanning's "default setup". +# Only advanced setup, which is to say this file, makes "dependency-caching" +# configurable; default setup turns it on and offers no way to turn it off. +name: CodeQL + +"on": + push: + branches: + - master + pull_request: + branches: + - master + schedule: + # Weekly, matching the schedule that default setup used. + - cron: "37 4 * * 1" + +# Auto-cancel any in-progress jobs from the same branch or PR. +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + analyze: + name: analyze (${{ matrix.language }}) + runs-on: ubuntu-latest + timeout-minutes: 60 + permissions: + actions: read + contents: read + packages: read + security-events: write + strategy: + fail-fast: false + matrix: + language: + - actions + - java-kotlin + - python + steps: + - uses: actions/checkout@v7 + with: + persist-credentials: false + - name: Initialize CodeQL + uses: github/codeql-action/init@v4 + with: + languages: ${{ matrix.language }} + build-mode: none + # Each Java dependency cache holds about 1GB of "~/.m2/repository" and + # "~/.gradle/caches", and its key covers every "*.gradle" file, so a + # handful of them crowds every other cache out of the repository's + # 10GB quota. + dependency-caching: false + - name: Perform CodeQL analysis + uses: github/codeql-action/analyze@v4 + with: + # Matches the category that default setup used, so that existing + # alerts keep their identity rather than being reported anew. + category: /language:${{ matrix.language }} From 2dc9dea04cfe77d30580cad14be664065b5a6eed Mon Sep 17 00:00:00 2001 From: Michael Ernst Date: Sat, 19 Sep 2026 19:35:46 -0700 Subject: [PATCH 2/2] Drop the cache-cleanup workflow Co-Authored-By: Claude Opus 5 --- .github/workflows/cache-cleanup.yaml | 46 ---------------------------- 1 file changed, 46 deletions(-) delete mode 100644 .github/workflows/cache-cleanup.yaml diff --git a/.github/workflows/cache-cleanup.yaml b/.github/workflows/cache-cleanup.yaml deleted file mode 100644 index 480f79160af0..000000000000 --- a/.github/workflows/cache-cleanup.yaml +++ /dev/null @@ -1,46 +0,0 @@ -# Delete the Actions caches that a pull request created, as soon as it closes. -# Caches count against a repository-wide 10GB quota, and GitHub evicts the -# least recently used cache once that is exceeded, so a closed pull request's -# caches would otherwise evict caches that are still in use. -name: Cache cleanup - -# "pull_request_target" rather than "pull_request", because under -# "pull_request" a pull request from a fork gets a read-only token, which -# cannot delete a cache. This workflow runs no code from the pull request, -# which is what makes "pull_request_target" safe here. -"on": - pull_request_target: - types: - - closed - -permissions: - actions: write - -jobs: - cleanup: - runs-on: ubuntu-latest - timeout-minutes: 10 - steps: - - name: Delete the caches of the closed pull request - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - GH_REPO: ${{ github.repository }} - HEAD_REF: ${{ github.event.pull_request.head.ref }} - HEAD_REPO: ${{ github.event.pull_request.head.repo.full_name }} - PR_NUMBER: ${{ github.event.pull_request.number }} - THIS_REPO: ${{ github.repository }} - run: | - refs="refs/pull/${PR_NUMBER}/merge" - # A pull request from a branch of this repository also ran the "push" - # trigger, under the branch's own ref, and so has a second set of - # caches. - if [ "$HEAD_REPO" = "$THIS_REPO" ]; then - refs="$refs refs/heads/${HEAD_REF}" - fi - for ref in $refs; do - echo "Deleting the caches of $ref" - ids="$(gh cache list --ref "$ref" --limit 100 --json id --jq '.[].id' || true)" - for id in $ids; do - gh cache delete "$id" || true - done - done