Skip to content

ci: Blender Smoke runs on docs-only PRs and downloads Blender uncached and unverified (no sha256) #294

Description

@TMHSDigital

Why it matters

Blender Smoke is the slowest and heaviest workflow, and it runs in full on every PR, including README typo fixes. It downloads two complete Blender builds (5.2 and 4.5) fresh each time without verifying them. Two problems follow: wasted CI minutes and slower feedback, and an unverified binary executing repo code in a job with a token.

Evidence

  • .github/workflows/blender-smoke.yml: the pull_request trigger has no paths: / paths-ignore: filter, so docs-only PRs pay the full cost.
  • blender-smoke.yml:119-130: the tarball is fetched from download.blender.org on every leg, with no actions/cache and no check against the published .sha256 that Blender ships next to each release.
  • The 96 catalog entries run serially under a 45-minute timeout.
  • test_harness.py runs in validate-harness and again in every smoke leg (blender-smoke.yml:93).
  • .github/workflows/pages.yml:76: pip install Jinja2 is unpinned, while scripts/site/requirements.txt pins Jinja2>=3.1,<4.0. Dependabot (.github/dependabot.yml) covers only github-actions, not pip.

Suggested approach

  1. Add paths-ignore for **.md, docs/** (except anything smoke reads) and assets/**. Keep a required-check-friendly no-op job if needed (see ci: main cannot enforce required status checks while owned by a user account #192).
  2. Cache the extracted Blender under a key of <series>-<resolved point version>. The resolver already computes the exact version.
  3. Download <tarball>.sha256 and run sha256sum -c before extracting.
  4. Drop the duplicate test_harness.py run from smoke legs.
  5. pip install -r scripts/site/requirements.txt in pages.yml, and add a pip ecosystem to Dependabot for scripts/site/.

Done when

  • A docs-only PR does not start Blender Smoke.
  • A cache hit skips the download.
  • A corrupted tarball fails the checksum step, with a falsifier recorded.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions