ci: bound runtime and force sandboxed builds

The test workflow currently relies on GitHub Actions defaults for both
job lifetime and Nix sandboxing. That is acceptable when everything
behaves, but it makes failures noisier: a hung job can run indefinitely
until the platform kills it, and the macOS leg inherits a weaker sandbox
default than Linux.

Add explicit timeout-minutes values to the lightweight change-detection
job and the main test matrix job, and pass sandbox = true through
install-nix-action. The sandbox setting is primarily about making the
macOS runner match the stricter execution model we already expect on
Linux.
This commit is contained in:
Austin Horstman
2026-04-21 08:24:02 -05:00
parent 6658732d33
commit 7076272297
+4
View File
@@ -10,6 +10,7 @@ permissions: {}
jobs:
changes:
runs-on: ubuntu-latest
timeout-minutes: 5
outputs:
docs: ${{ steps.changes.outputs.docs }}
format: ${{ steps.changes.outputs.format }}
@@ -46,6 +47,7 @@ jobs:
- 'flake.lock'
tests:
needs: changes
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
@@ -61,6 +63,8 @@ jobs:
if: github.event_name == 'schedule' || needs.changes.outputs.docs == 'true' || needs.changes.outputs.tests == 'true' || needs.changes.outputs.hm == 'true' || needs.changes.outputs.format == 'true'
with:
nix_path: nixpkgs=https://github.com/NixOS/nixpkgs/archive/${{ steps.get-nixpkgs.outputs.rev }}.tar.gz
extra_nix_config: |
sandbox = true
- name: Build docs
if: github.event_name == 'schedule' || needs.changes.outputs.docs == 'true'
run: nix build --show-trace .#docs-jsonModuleMaintainers