diff --git a/.gitea/workflows/pr-checks.yml b/.gitea/workflows/pr-checks.yml index 36a067b..b7d3a11 100644 --- a/.gitea/workflows/pr-checks.yml +++ b/.gitea/workflows/pr-checks.yml @@ -5,6 +5,13 @@ on: branches: - main +# Cancel superseded runs: pushing a new commit to a PR (or an empty +# re-trigger) aborts the previous still-running checks instead of running +# a second full matrix alongside them. +concurrency: + group: pr-checks-${{ gitea.event.pull_request.number }} + cancel-in-progress: true + env: REGISTRY: privaterepo.sitaru.org BACKEND_IMAGE_NAME: ${{ gitea.repository }}-backend @@ -23,12 +30,22 @@ jobs: uses: actions/setup-node@v4 with: node-version: 22 - cache: npm - cache-dependency-path: nextjs-app/package-lock.json + + # Cache the resolved node_modules (452 MB / 460 packages) keyed on the + # lockfile. On a hit — the common case, since deps change rarely — the + # whole `npm ci` step is skipped, not just its download phase. The key + # pins OS + node major so we never restore incompatible native binaries. + - name: Cache node_modules + id: node-modules-cache + uses: actions/cache@v4 + with: + path: nextjs-app/node_modules + key: nextjs-node-modules-${{ runner.os }}-node22-${{ hashFiles('nextjs-app/package-lock.json') }} - name: Install dependencies + if: steps.node-modules-cache.outputs.cache-hit != 'true' working-directory: nextjs-app - run: npm ci + run: npm ci --prefer-offline --no-audit --no-fund - name: Typecheck working-directory: nextjs-app