Repository navigation
[FSSDK-13238] ci: build all platforms on Xcode 16 and 27, check API breaks, harden workflows - #660
Merged
Merged
Conversation
This comment has been minimized.
This comment has been minimized.
muzahidul-opti
force-pushed
the
muzahid/ci-hardening
branch
3 times, most recently
from
October 6, 2026 17:51
ca8bf28 to
2d0ccd9
Compare
…workflows - Compile the package for iOS, tvOS, watchOS and macOS on the newest (27.0) and oldest supported (16.0) Xcode; watchOS was never built in CI - Fail PRs that break public API vs. the base branch (swift package diagnose-api-breaking-changes) - Cancel superseded PR runs; add timeouts to macOS jobs - Upgrade actions/checkout v3 -> v7, pin all actions to commit SHAs, stop persisting checkout credentials, add Dependabot for actions - Call reusable workflows from the same commit instead of @master - Pipe unit test output through xcbeautify for inline PR annotations Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tools The trigger scripts only call the GitHub API with curl using the token from the environment, so no git credentials are needed on disk. Addresses Arnica's artipacked finding. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Major tags pick up patch and minor fixes without bot PRs. The ticket checker stays SHA-pinned since it only has a master branch and hasn't changed since 2022. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
It's Optimizely-owned, so pinning adds little and would hide future fixes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A shared group with cancel-in-progress=false still lets a newer pending master run replace an older pending one; give non-PR runs a unique group. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A job that needs all 3 retry attempts runs 60-70 minutes; 60 cancelled a legitimate run. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
muzahidul-opti
force-pushed
the
muzahid/ci-hardening
branch
from
October 7, 2026 01:01
b9a1dda to
5e1af29
Compare
- package_validation: its swift build is covered by build (Xcode_27.0) and SourceClear still scans master via source_clear_cron.yml - upload-artifact v4 -> v7 (v4 runs on deprecated Node 20; name/path inputs unchanged) - run_unit_tests.sh: drop the unused buildoutput tee - lint_markdown: Ruby 2.6 (EOL) -> 3.3; drop bundler-cache (no Gemfile) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-up to #659. Adds compile-only gates (deterministic, no flaky tests) and cleans up CI, modeled on Alamofire / firebase-ios-sdk.
package_validationremoved:swift buildis the first step ofbuild (Xcode_27.0)swift package resolveis a no-op, since there are no dependenciesmasteron every push and weekly viasource_clear_cron.ymlactions/checkoutv3 → v7 andactions/upload-artifactv4 → v7 (both off the deprecated Node 20)persist-credentials: falseon every checkout, including theCI_USER_TOKENPAT checkout ofci-helper-tools(Arnica artipacked finding; its scripts only call the API withcurland the env token)buildoutputtee inrun_unit_tests.shlint_markdownRuby 2.6 (EOL) → 3.3, droppingbundler-cache(there's no Gemfile)Test plan
PR CI on this branch (run, before the cleanup commit):
api_breaking_changes: pass (first real run, no breaks vsmaster)build (Xcode_16.0)onmacos-15: macOS, iphoneos, appletvos, watchos allBuild complete!build (Xcode_27.0), integration tests, lint, iPhone 17 + tvOS unit tests: passxcbeautifyoutput is present onxcode-27Local, Xcode 27.0, API check:
No breaking changes detected in OptimizelypublicfromgetEnabledFeatures:💔 API breakage: func OptimizelyClient.getEnabledFeatures(userId:attributes:) has been removed, exit 1 (change reverted)Lint and cleanup commit:
actionlintclean (ignoring the customxcode-27runner label and pre-existing SC2086 infos)upload-artifact@v7are verified by this PR's CI runMerge Danger
Door: two-way. Workflow-only changes that revert cleanly.
Blast Radius:
api_breaking_changesfails on intentional breaks, so keep it a non-required check.master(push + weekly). Revisit if the SDK gains third-party dependencies or security requires pre-merge SCA.unittests (27.0, …); the current(27, …)entries never reportbuild (Xcode_16.0),build (Xcode_27.0),jira_ticket_reference_checkIssues
🤖 Generated with Claude Code