Static GitHub Actions Cache Key Silently Froze CI Dependencies for 23 Days
A developer discovered that a GitHub Actions CI pipeline had been silently serving a 23-day-old dependency cache, causing install times to balloon from 38 seconds to nearly three minutes. The root cause was a static cache key that never changed, triggering GitHub Actions' built-in behavior of skipping cache saves whenever an exact key match is found. Because cache entries in GitHub Actions are immutable and cannot be overwritten, any dependency updates added after the initial cache save were re-downloaded from PyPI on every subsequent run without ever being persisted. The fix involves embedding a hash of the lockfile — using hashFiles() — directly into the cache key, so that any change to dependencies generates a new key and forces a fresh cache save. A restore-keys prefix fallback ensures partial cache reuse when the lockfile changes, keeping install times fast while guaranteeing the cache stays current.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in