Skip to content

v1.2.0 – Pruning, Integrity Checks, Safe Concurrent Saves & Opt-in Streaming

Choose a tag to compare

@xSAVIKx xSAVIKx released this 15 Sep 19:41
· 42 commits to main since this release

No breaking changes. Caches saved by v1.1 stay valid, and the default save and restore paths still
work the same way, apart from the additions below.

Added

  • cloud-cache-action/prune sub-action that deletes cache archives older than
    older-than-days. It supports ref, scoped-to-ref, scoped-to-repository, prefix and
    dry-run.
    • It only deletes objects whose whole key matches the resolved s3-key-pattern, so other
      repositories, other refs and non-archive objects under the same listing prefix are never
      touched.
    • It refuses to run when a pattern can't be scoped safely.
    • An invalid dry-run value fails the step before any S3 call.
  • Archive integrity. File-mode saves store a sha256 of the archive in the
    cloud-cache-sha256 object metadata, and restores verify it.
    • A mismatch counts as a cache miss with a warning.
    • It only fails the step when both dual-cache and dual-cache-strict are true.
    • Objects without the metadata (any v1.1 cache, or a streamed save) skip the check.
  • Safe concurrent saves. Saves send If-None-Match: *, so when two jobs save the same key,
    the first one wins and the second keeps the existing cache.
    • If a provider rejects the condition, the save retries once without it and doesn't send it
      again for the rest of the run.
    • A 409 ConditionalRequestConflict is retried once.
    • Providers that ignore the condition, such as Garage, keep last-writer-wins.
  • Job summary. Restore and save each write a step summary table with the key, hit and
    source, size and duration. The new job-summary input defaults to true.
  • Opt-in streaming (streaming: true, default false): pipes tar straight to a multipart
    upload and downloads straight into tar, with no temporary archive file.
    • The file-based path stays the default and is unchanged.
    • A streamed upload is only completed after tar exits successfully, so a failed tar never
      leaves a truncated cache.
    • It falls back to file mode for BSD tar with zstd on Windows and for rejected conditions.
  • Maintenance. Dependabot for npm and GitHub Actions, with minor and patch updates grouped
    and major updates proposed separately.
  • Release workflow (.github/workflows/release.yml), which runs when a GitHub release is
    published.
    • It verifies the tag against package.json and checks that dist is up to date.
    • It then moves the major tag, but only for the highest stable release of that major.

Changed

  • The main action, restore and save gain the job-summary and streaming inputs.
  • A bare $ref, $key, $prefix, $version, $archive_filename or $GITHUB_REPOSITORY in
    s3-key-pattern is no longer expanded from the environment. It stays literal and logs one
    warning per name.

Fixed

  • A strict dual-cache save where path matches nothing no longer fails the step. The GitHub
    tier's "Path Validation Error" now counts as a skipped save, as it already did for the S3 tier.
  • With scoped-to-repository: false or scoped-to-ref: false, removing the placeholder no longer
    leaves a leading, doubled or trailing /. A / is only removed when the placeholder fills a
    whole path segment, so custom patterns keep their v1.1 keys.
  • When CompleteMultipartUpload fails (for example, a lost save race), the multipart upload is
    aborted instead of leaving billed parts behind.
  • Errors rewrapped by the restore and save steps keep the original error as cause.

Full changelog: v1.1.0...v1.2.0