perf(ci): cache pnpm verification records on Linux (#23568)

* perf(ci): pilot pnpm verification record caching on Linux

* test(ci): review pnpm verification record in mobile cache audit
This commit is contained in:
Neil
2026-09-28 01:50:30 -07:00
committed by GitHub
parent 3dd7d29455
commit e6fbbdf684
4 changed files with 113 additions and 1 deletions
@@ -2,6 +2,10 @@ name: Install Node dependencies
description: Installs the Node toolchain and repository dependencies for CI jobs, with optional Electron archive caching.
inputs:
cache-pnpm-verification:
description: Restore pnpm's policy-checked lockfile verification record on Linux.
required: false
default: 'true'
native-runtime:
description: Native runtime to prepare after the script-free install (none, node, or electron).
required: false
@@ -24,6 +28,15 @@ inputs:
default: 'false'
outputs:
verification-cache-hit:
description: Whether pnpm's verification record was restored.
value: ${{ steps.verification-cache-restore.outputs.cache-hit }}
verification-cache-path:
description: The small pnpm-owned verification record, without registry metadata.
value: ${{ steps.verification-cache.outputs.path }}
verification-cache-key:
description: Exact verification record key, also used by the isolated PR benchmark.
value: ${{ steps.verification-cache.outputs.key }}
node-version:
description: Resolved Node.js version used for the install.
value: ${{ steps.requested-node.outputs.node-version || steps.default-node.outputs.node-version }}
@@ -86,6 +99,25 @@ runs:
path: ${{ steps.pnpm-store.outputs.path }}
key: node-cache-${{ runner.os }}-${{ steps.pnpm-store.outputs.arch }}-pnpm-${{ hashFiles(inputs.cache-dependency-path) }}
- name: Resolve pnpm verification cache
id: verification-cache
if: runner.os == 'Linux' && inputs.cache-pnpm-verification == 'true'
shell: bash
env:
POLICY_HASH: ${{ hashFiles('pnpm-lock.yaml', 'pnpm-workspace.yaml', '.npmrc') }}
run: |
printf 'path=%s/lockfile-verified.jsonl\n' "$(pnpm cache path)" >> "$GITHUB_OUTPUT"
printf 'key=pnpm-verification-v1-%s-%s-%s-%s\n' "$RUNNER_OS" "$RUNNER_ARCH" "$(pnpm --version)" "$POLICY_HASH" >> "$GITHUB_OUTPUT"
- name: Restore pnpm verification record
id: verification-cache-restore
if: steps.verification-cache.outputs.key != ''
continue-on-error: true
uses: actions/cache/restore@v5
with:
path: ${{ steps.verification-cache.outputs.path }}
key: ${{ steps.verification-cache.outputs.key }}
- name: Validate native runtime
shell: bash
env:
@@ -120,6 +152,15 @@ runs:
git -C "$GITHUB_WORKSPACE" diff --exit-code -- package.json pnpm-lock.yaml pnpm-workspace.yaml
fi
# pnpm checks the cached record's policy and validity; never bypass verification.
- name: Save pnpm verification record on main
if: github.ref == 'refs/heads/main' && github.event_name != 'pull_request' && steps.verification-cache.outputs.key != '' && steps.verification-cache-restore.outputs.cache-hit != 'true'
continue-on-error: true
uses: actions/cache/save@v5
with:
path: ${{ steps.verification-cache.outputs.path }}
key: ${{ steps.verification-cache.outputs.key }}
- name: Resolve Electron package cache
id: electron-package-cache
if: inputs.native-runtime == 'electron' || inputs.cache-electron-package == 'true'
@@ -0,0 +1,65 @@
name: pnpm verification cache pilot
on:
pull_request:
paths: ['.github/workflows/ci-pnpm-verification-pilot.yml']
workflow_dispatch:
permissions:
contents: read
concurrency:
group: pnpm-verification-pilot-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
env:
ORCA_BACKGROUND_LAUNCH: '1'
jobs:
seed:
strategy:
matrix:
runner: [ubuntu-latest, ubuntu-24.04-arm]
runs-on: ${{ matrix.runner }}
timeout-minutes: 15
steps:
- uses: actions/checkout@v6
with:
persist-credentials: false
- uses: ./.github/actions/install-node-dependencies
id: deps
# PR caches are scoped to the PR merge ref; main never restores them.
- uses: actions/cache/save@v5
if: steps.deps.outputs.verification-cache-hit != 'true'
with:
path: ${{ steps.deps.outputs.verification-cache-path }}
key: ${{ steps.deps.outputs.verification-cache-key }}
measure:
needs: seed
name: measure ${{ matrix.runner }} sample ${{ matrix.sample }} cache ${{ matrix.cache }}
strategy:
fail-fast: false
max-parallel: 4
matrix:
runner: [ubuntu-latest, ubuntu-24.04-arm]
sample: [1, 2, 3]
cache: ['false', 'true']
runs-on: ${{ matrix.runner }}
timeout-minutes: 15
steps:
- uses: actions/checkout@v6
with:
persist-credentials: false
- uses: ./.github/actions/install-node-dependencies
id: deps
with:
cache-pnpm-verification: ${{ matrix.cache }}
- name: Validate treatment and frozen install
env:
CACHE_ENABLED: ${{ matrix.cache }}
CACHE_HIT: ${{ steps.deps.outputs.verification-cache-hit }}
run: |
if [ "$CACHE_ENABLED" = true ]; then test "$CACHE_HIT" = true; fi
git diff --exit-code -- package.json pnpm-lock.yaml pnpm-workspace.yaml
node -e "require.resolve('vitest'); require.resolve('electron')"
@@ -48,7 +48,11 @@ describe('CI dependency download caches', () => {
action.runs.steps.findIndex((step) => step.name === 'Install dependencies')
)
const saves = action.runs.steps.filter((step) => step.uses === 'actions/cache/save@v5')
expect(saves).toEqual([])
expect(saves).toHaveLength(1)
expect(saves[0].name).toBe('Save pnpm verification record on main')
expect(saves[0].if).toContain("github.ref == 'refs/heads/main'")
expect(saves[0].if).toContain("github.event_name != 'pull_request'")
expect(saves[0].with.path).toBe('${{ steps.verification-cache.outputs.path }}')
})
it('restores Windows packaging downloads from the release cache without a PR upload', () => {
@@ -120,6 +120,8 @@ const BUNDLER_CACHE_PATHS = ['metro-cache', '.expo', 'node_modules/.cache']
const REVIEWED_COMPUTED_PATHS = [
'${{ steps.electron-package-cache.outputs.cache-root }}',
'${{ steps.pnpm-store.outputs.path }}',
// Only pnpm's lockfile-verified.jsonl record, never Metro transforms.
'${{ steps.verification-cache.outputs.path }}',
"${{ github.event_name != 'pull_request' && 'pnpm' || '' }} store"
]