JovieInc/Jovie GitHub Actions scorecardPublic GitHub Actions data, last 30 days. Updated .
Data sourced from public GitHub. GitSpider is not affiliated with or endorsed by this repository's owners. Request removal.
Biggest wins first, each with the exact config fix.
CIRuns on every push/PR with no `paths:` filter, so docs-only changes still trigger full CI. Add a `paths:` filter if that's common.
on:
pull_request:
paths:
- 'src/**'
- 'package.json'CITests run under an auto-retry wrapper, so each retry re-bills the same minutes and masks the flaky tests it papers over. Track, fix or quarantine the flakes, then drop the wrapper.
CIA test/build job is bound to a GitHub environment, so every run counts as a deployment: PR and deployments-API noise. Use repository secrets or OIDC for non-deploy jobs.
Dependabot Auto-MergeNo job sets `timeout-minutes`, so a hung step can run to GitHub's 6-hour default. Add `timeout-minutes` to each job.
jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 15CodeQL Security AnalysismacOS bills ~10x and Windows ~2x a Linux minute. The cost estimate above assumes Linux, so your real spend is higher. Move any job that doesn't need them to `ubuntu-latest`.
jobs:
build:
runs-on: ubuntu-latest # ~10x cheaper than macos-latestCodeQL Security AnalysisThe schedule has no repository guard, so forks that enable Actions inherit the cron and burn their own minutes. Gate the job with `if: github.repository == 'owner/repo'`.
jobs:
nightly:
if: github.repository == 'owner/repo'
runs-on: ubuntu-latestClaude CodeNo job sets `timeout-minutes`, so a hung step can run to GitHub's 6-hour default. Add `timeout-minutes` to each job.
jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 15Claude Codecheckout fetches the entire git history every run (`fetch-depth: 0`) and nothing in the workflow appears to read it. Remove the line; the default shallow clone is much faster on big repos. Keep it if a step genuinely needs history.
- uses: actions/checkout@v4
# fetch-depth: 0 removed — default shallow clone is enough hereSecurity ScanningNo job sets `timeout-minutes`, so a hung step can run to GitHub's 6-hour default. Add `timeout-minutes` to each job.
jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 15Security Scanningcheckout fetches the entire git history every run (`fetch-depth: 0`) and nothing in the workflow appears to read it. Remove the line; the default shallow clone is much faster on big repos. Keep it if a step genuinely needs history.
- uses: actions/checkout@v4
# fetch-depth: 0 removed — default shallow clone is enough hereFork PR GateRuns on every push/PR with no `paths:` filter, so docs-only changes still trigger full CI. Add a `paths:` filter if that's common.
on:
pull_request:
paths:
- 'src/**'
- 'package.json'desktop-releaseSet `cache: 'pnpm'` on your `actions/setup-node` step, or add an `actions/cache@v4` step keyed on your lockfile.
- uses: actions/setup-node@v4
with:
node-version: 20
cache: 'pnpm'desktop-releasemacOS bills ~10x and Windows ~2x a Linux minute. The cost estimate above assumes Linux, so your real spend is higher. Move any job that doesn't need them to `ubuntu-latest`.
jobs:
build:
runs-on: ubuntu-latest # ~10x cheaper than macos-latestiOS TestFlightmacOS bills ~10x and Windows ~2x a Linux minute. The cost estimate above assumes Linux, so your real spend is higher. Move any job that doesn't need them to `ubuntu-latest`.
jobs:
build:
runs-on: ubuntu-latest # ~10x cheaper than macos-latestPR Size GuardRuns on every push/PR with no `paths:` filter, so docs-only changes still trigger full CI. Add a `paths:` filter if that's common.
on:
pull_request:
paths:
- 'src/**'
- 'package.json'Merge Queue Auto-EnrollRuns on every push/PR with no `paths:` filter, so docs-only changes still trigger full CI. Add a `paths:` filter if that's common.
on:
pull_request:
paths:
- 'src/**'
- 'package.json'Runner HeartbeatA schedule cron fires >4x/hour, so scheduled runs cost minutes around the clock. Loosen the cadence.
on:
schedule:
- cron: '*/30 * * * *' # every 30 min instead of every minuteRunner HeartbeatThe schedule has no repository guard, so forks that enable Actions inherit the cron and burn their own minutes. Gate the job with `if: github.repository == 'owner/repo'`.
jobs:
nightly:
if: github.repository == 'owner/repo'
runs-on: ubuntu-latestPost-Deploy ProbesThis looks like a deploy/release workflow with `cancel-in-progress: true`, which cancels queued runs too, so a queued deploy is silently dropped when a newer run arrives. Use a group-only `concurrency:` block on deploys.
concurrency:
group: ${{ github.workflow }}
# queued deploys run in order; none are droppedFleet Gate RefreshRuns on every push/PR with no `paths:` filter, so docs-only changes still trigger full CI. Add a `paths:` filter if that's common.
on:
pull_request:
paths:
- 'src/**'
- 'package.json'Delivery Control ReceiptsThe schedule has no repository guard, so forks that enable Actions inherit the cron and burn their own minutes. Gate the job with `if: github.repository == 'owner/repo'`.
jobs:
nightly:
if: github.repository == 'owner/repo'
runs-on: ubuntu-latest# No path filters on triggers (applies to: CI, Fork PR Gate, PR Size Guard, Merge Queue Auto-Enroll, Fleet Gate Refresh)
on:
pull_request:
paths:
- 'src/**'
- 'package.json'
# No job timeout (applies to: Dependabot Auto-Merge, Claude Code, Security Scanning)
jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 15
# Premium runners (macOS / Windows) (applies to: CodeQL Security Analysis, desktop-release, iOS TestFlight)
jobs:
build:
runs-on: ubuntu-latest # ~10x cheaper than macos-latest
# Scheduled workflow runs in forks (applies to: CodeQL Security Analysis, Runner Heartbeat, Delivery Control Receipts)
jobs:
nightly:
if: github.repository == 'owner/repo'
runs-on: ubuntu-latest
# Full-history clone (fetch-depth: 0) (applies to: Claude Code, Security Scanning)
- uses: actions/checkout@v4
# fetch-depth: 0 removed — default shallow clone is enough here
# Missing dependency cache (pnpm) (applies to: desktop-release)
- uses: actions/setup-node@v4
with:
node-version: 20
cache: 'pnpm'
# Frequent scheduled runs (applies to: Runner Heartbeat)
on:
schedule:
- cron: '*/30 * * * *' # every 30 min instead of every minute
# cancel-in-progress on a deploy workflow (applies to: Post-Deploy Probes)
concurrency:
group: ${{ github.workflow }}
# queued deploys run in order; none are droppedEach snippet is representative. Merge into the named workflow files rather than pasting wholesale.
This scorecard is a one-time snapshot. Install the free GitHub App to track this repo continuously: new regressions caught as they land, trends over time, on your public and private repos. Team adds the offending commit on the PR + Slack alerts.
Install & monitor this repo →💬 On Team, this same analysis posts automatically to every PR: the regression, and the exact commit that caused it, right where your team already looks. See plans →
Not ready to install? Get this report by email. No spam, unsubscribe anytime.