Skip to content

ci: run Go jobs only when code changes - #7

Closed
bahram-bahrambeigy-cdt wants to merge 1 commit into
mainfrom
ci/skip-tests-on-doc-changes
Closed

bahram-bahrambeigy-cdt wants to merge 1 commit into
mainfrom
ci/skip-tests-on-doc-changes

Conversation

@bahram-bahrambeigy-cdt

Copy link
Copy Markdown
Collaborator

Doc, example and config-only PRs were starting a full OpenMetadata stack (MySQL + Elasticsearch + OM server, ~3 min) to prove nothing. lint, build and Acceptance Tests now run only when the change can affect them.

Why not a paths: filter

All four checks are required by branch protection. A workflow skipped by a paths: filter never reports its check, so the PR sits at "Expected — waiting for status" and can never merge. A job skipped by an if: condition reports as passing. So the gate is a changes job whose output the other jobs read.

What still runs on every PR

  • Every resource has an acceptance test — 6 seconds, and it is a structural invariant worth enforcing on every change
  • The changes job itself

Fails open

Manual workflow_dispatch, a missing or zeroed base sha (new branch, force push), or a failed diff all return code=true and run everything. A change that cannot be classified is treated as code.

Paths that count as code: internal/, tools/, main.go, go.mod, go.sum, .golangci.yml, docker/test/, scripts/testacc.sh, and .github/workflows/ plus the script itself — so a workflow edit always proves itself.

Also

The workflow_dispatch version input now reaches sed through env: instead of being interpolated into the shell. It needs write access to set, so it was not an outsider risk, but it was an injection point.

Verified the classifier against real commit ranges and a table of representative paths: source, build and workflow files run; README, docs/, examples/, AGENTS.md, dependabot.yml and the PR template skip.

🤖 Generated with Claude Code

Doc, example and config-only PRs were spinning up a full OpenMetadata
stack for nothing. Gate lint, build and acceptance on a changed-paths
job instead.

Uses a job-level if, not a workflow paths filter: a path-filtered
required check never reports and blocks the PR forever, while a skipped
job counts as passing.

The detection fails open — manual runs, a missing base sha, or a failed
diff all run the full suite.

Also passes the workflow_dispatch version input through env rather than
interpolating it into the shell.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@bahram-bahrambeigy-cdt

Copy link
Copy Markdown
Collaborator Author

Superseded by the simpler path-filter approach. Closing in favour of the six-line version.

@bahram-bahrambeigy-cdt
bahram-bahrambeigy-cdt deleted the ci/skip-tests-on-doc-changes branch September 23, 2026 10:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant