SShortSingh.
Back to feed

Static GitHub Actions Cache Key Silently Froze CI Dependencies for 23 Days

0
·7 views

A developer discovered that a GitHub Actions CI pipeline had been silently serving a 23-day-old dependency cache, causing install times to balloon from 38 seconds to nearly three minutes. The root cause was a static cache key that never changed, triggering GitHub Actions' built-in behavior of skipping cache saves whenever an exact key match is found. Because cache entries in GitHub Actions are immutable and cannot be overwritten, any dependency updates added after the initial cache save were re-downloaded from PyPI on every subsequent run without ever being persisted. The fix involves embedding a hash of the lockfile — using hashFiles() — directly into the cache key, so that any change to dependencies generates a new key and forces a fresh cache save. A restore-keys prefix fallback ensures partial cache reuse when the lockfile changes, keeping install times fast while guaranteeing the cache stays current.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

AWS Local Zones cut latency from 200ms to 5ms for Latin American apps

Applications hosted in US-based AWS regions like us-east-1 can suffer 150–200ms latency for users in cities such as Buenos Aires, Santiago, or Bogotá, which directly impacts revenue, user retention, and transaction success rates. AWS offers a layered infrastructure spectrum — including Local Zones, Wavelength, and Outposts — designed to bring compute closer to end users without replacing the core region. AWS Local Zones, now expanding across Latin America, are extensions of existing regions connected via AWS's private network, reducing latency to as low as 5–10ms for latency-sensitive workloads. Industries such as fintech, gaming, streaming, and industrial IoT stand to benefit most, as real-time fraud detection and competitive gaming both require sub-20ms processing. The recommended architecture is selective — latency-sensitive components run in the Local Zone while storage, analytics, and backups remain in the main region.

0
ProgrammingDEV Community ·

How to Pick Online Photoshop Alternatives for Web Dev Image Workflows

Web developers often need polished assets like hero images, social preview cards, and documentation screenshots without a full design process. Choosing the right browser-based image editor depends on whether it can handle your source file through editing, export, and future revisions without added friction. Tools like Photopea support layered PSD files, while lighter options like MockoFun suit simpler tasks. Organizing source files separately from exported public assets — and keeping editable working documents — helps maintain a clean, repeatable workflow. Developers are advised to check editor account restrictions, watermarks, and export limitations before committing to a tool.

0
ProgrammingDEV Community ·

KuruBeats: Free, Open-Source Android App Plays Local Files and YouTube Music

A developer has released KuruBeats, a free and open-source Android music player licensed under GPL-3.0, designed to handle both local audio playback and YouTube Music streaming without requiring an account, serving ads, or tracking users. The app was built out of frustration with existing players that were either ad-supported, subscription-based, or visually outdated. KuruBeats is developed in Kotlin using Jetpack Compose and Material 3, and supports Material You dynamic theming, synced lyrics, song recognition, and background playback. The project is currently in beta, and anonymous YouTube Music streaming may be blocked on some networks due to platform bot-detection measures. The source code and APK downloads are publicly available on GitHub at kurupdevs/KuruBeats.

0
ProgrammingDEV Community ·

Community feedback drives concurrency fixes and data privacy upgrades in Cubicle v0.7

Cubicle, a pixel-art office visualizer for AI agents, received significant technical improvements in version 0.7 following detailed feedback from community members. A race condition was identified where multiple simultaneous hook runs could silently overwrite each other's updates to a shared JSON file, causing roughly one-third of session registrations to be lost in testing. The fix introduced a lock-file mechanism using O_EXCL that prevents conflicting writes while ensuring the hook never stalls the AI agent for more than one second. A separate privacy concern was also addressed: the server now strips all unnecessary data fields before forwarding responses, and an optional redact mode removes task titles, commands, and error text server-side so sensitive information cannot be retrieved even by direct API calls. Additionally, a contributor highlighted that hooks meant to visualize activity and hooks meant to block tool calls carry opposite failure contracts, prompting Cubicle to enforce a strict always-exit-0 policy and install its hooks as separate entries rather than merging them with existing ones.