You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Blender Smoke is the slowest and heaviest workflow, and it runs in full on every PR, including README typo fixes. It downloads two complete Blender builds (5.2 and 4.5) fresh each time without verifying them. Two problems follow: wasted CI minutes and slower feedback, and an unverified binary executing repo code in a job with a token.
Evidence
.github/workflows/blender-smoke.yml: the pull_request trigger has no paths: / paths-ignore: filter, so docs-only PRs pay the full cost.
blender-smoke.yml:119-130: the tarball is fetched from download.blender.org on every leg, with no actions/cache and no check against the published .sha256 that Blender ships next to each release.
The 96 catalog entries run serially under a 45-minute timeout.
test_harness.py runs in validate-harnessand again in every smoke leg (blender-smoke.yml:93).
.github/workflows/pages.yml:76: pip install Jinja2 is unpinned, while scripts/site/requirements.txt pins Jinja2>=3.1,<4.0. Dependabot (.github/dependabot.yml) covers only github-actions, not pip.
Why it matters
Blender Smoke is the slowest and heaviest workflow, and it runs in full on every PR, including README typo fixes. It downloads two complete Blender builds (5.2 and 4.5) fresh each time without verifying them. Two problems follow: wasted CI minutes and slower feedback, and an unverified binary executing repo code in a job with a token.
Evidence
.github/workflows/blender-smoke.yml: thepull_requesttrigger has nopaths:/paths-ignore:filter, so docs-only PRs pay the full cost.blender-smoke.yml:119-130: the tarball is fetched from download.blender.org on every leg, with noactions/cacheand no check against the published.sha256that Blender ships next to each release.test_harness.pyruns invalidate-harnessand again in every smoke leg (blender-smoke.yml:93)..github/workflows/pages.yml:76:pip install Jinja2is unpinned, whilescripts/site/requirements.txtpinsJinja2>=3.1,<4.0. Dependabot (.github/dependabot.yml) covers onlygithub-actions, notpip.Suggested approach
paths-ignorefor**.md,docs/**(except anything smoke reads) andassets/**. Keep a required-check-friendly no-op job if needed (see ci: main cannot enforce required status checks while owned by a user account #192).<series>-<resolved point version>. The resolver already computes the exact version.<tarball>.sha256and runsha256sum -cbefore extracting.test_harness.pyrun from smoke legs.pip install -r scripts/site/requirements.txtinpages.yml, and add apipecosystem to Dependabot forscripts/site/.Done when