ci: use GitHub-hosted runners for all Actions workflows - #707
Merged
Merged
Conversation
LeXwDeX
marked this pull request as ready for review
October 3, 2026 15:19
|
The account paying for this security review has reached its Codex usage limits. The payer can check the Codex usage dashboard. For personal accounts, using credits requires enabling “Use credits for security reviews” in Code review settings. If you do not manage the paying account, contact this repository's admins. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
CI, release, and runner smoke jobs currently use the owner's self-hosted machines. They must run on GitHub-hosted runners for every supported event.
What changed
Use ubuntu-latest for Linux and windows-latest for Windows. Keep macos-latest for macOS builds. Match verification evidence to the selected runner label and update the existing routing tests. Remove self-hosted provisioning branches while retaining Ubuntu dependency installation.
Run Linux workspace test tasks sequentially on hosted runners to reduce CPU competition during tests of Node worker startup. The existing 250 ms worker budget and every test remain in place.
The Nix workflow, required check names, permissions, action pins, and release guards are preserved.
Closes #706
Evidence
The 56 runner, evidence, fingerprint, and toolchain tests passed. The three focused desktop server asset tests passed, including the real Node worker fixture from an ASAR archive. Actionlint passed for all five workflows. Prettier and git diff --check passed for the six changed files. The pinned toolchain and required lint/typecheck hooks passed; all 31 typecheck tasks succeeded. Astra reviewed the final patch. The focused schema budget and Goal production wiring tests passed; five isolated Goal wiring/judge repeats also passed (130 tests).
All four required native checks passed on
0b35b33039396fbb48d5e878bf50ab9d0600107e: Typecheck and CI test. Typecheck and Linux Unit each required one complete rerun after existing deadline tests failed. Every test and its original limits remain in place.Checklist