v1.2.0 – Pruning, Integrity Checks, Safe Concurrent Saves & Opt-in Streaming
No breaking changes. Caches saved by v1.1 stay valid, and the default save and restore paths still
work the same way, apart from the additions below.
Added
cloud-cache-action/prunesub-action that deletes cache archives older than
older-than-days. It supportsref,scoped-to-ref,scoped-to-repository,prefixand
dry-run.- It only deletes objects whose whole key matches the resolved
s3-key-pattern, so other
repositories, other refs and non-archive objects under the same listing prefix are never
touched. - It refuses to run when a pattern can't be scoped safely.
- An invalid
dry-runvalue fails the step before any S3 call.
- It only deletes objects whose whole key matches the resolved
- Archive integrity. File-mode saves store a sha256 of the archive in the
cloud-cache-sha256object metadata, and restores verify it.- A mismatch counts as a cache miss with a warning.
- It only fails the step when both
dual-cacheanddual-cache-strictaretrue. - Objects without the metadata (any v1.1 cache, or a streamed save) skip the check.
- Safe concurrent saves. Saves send
If-None-Match: *, so when two jobs save the same key,
the first one wins and the second keeps the existing cache.- If a provider rejects the condition, the save retries once without it and doesn't send it
again for the rest of the run. - A
409 ConditionalRequestConflictis retried once. - Providers that ignore the condition, such as Garage, keep last-writer-wins.
- If a provider rejects the condition, the save retries once without it and doesn't send it
- Job summary. Restore and save each write a step summary table with the key, hit and
source, size and duration. The newjob-summaryinput defaults totrue. - Opt-in streaming (
streaming: true, defaultfalse): pipes tar straight to a multipart
upload and downloads straight into tar, with no temporary archive file.- The file-based path stays the default and is unchanged.
- A streamed upload is only completed after tar exits successfully, so a failed tar never
leaves a truncated cache. - It falls back to file mode for BSD tar with zstd on Windows and for rejected conditions.
- Maintenance. Dependabot for npm and GitHub Actions, with minor and patch updates grouped
and major updates proposed separately. - Release workflow (
.github/workflows/release.yml), which runs when a GitHub release is
published.- It verifies the tag against
package.jsonand checks thatdistis up to date. - It then moves the major tag, but only for the highest stable release of that major.
- It verifies the tag against
Changed
- The main action,
restoreandsavegain thejob-summaryandstreaminginputs. - A bare
$ref,$key,$prefix,$version,$archive_filenameor$GITHUB_REPOSITORYin
s3-key-patternis no longer expanded from the environment. It stays literal and logs one
warning per name.
Fixed
- A strict dual-cache save where
pathmatches nothing no longer fails the step. The GitHub
tier's "Path Validation Error" now counts as a skipped save, as it already did for the S3 tier. - With
scoped-to-repository: falseorscoped-to-ref: false, removing the placeholder no longer
leaves a leading, doubled or trailing/. A/is only removed when the placeholder fills a
whole path segment, so custom patterns keep their v1.1 keys. - When
CompleteMultipartUploadfails (for example, a lost save race), the multipart upload is
aborted instead of leaving billed parts behind. - Errors rewrapped by the restore and save steps keep the original error as
cause.
Full changelog: v1.1.0...v1.2.0