tokio-rs/tokio GitHub Actions scorecardPublic GitHub Actions data, last 30 days. Updated .
Data sourced from public GitHub. GitSpider is not affiliated with or endorsed by this repository's owners. Request removal.
Biggest wins first, each with the exact config fix.
Security AuditNo job sets `timeout-minutes`, so a hung step can run to GitHub's 6-hour default. Add `timeout-minutes` to each job.
jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 15Security AuditThe schedule fires at minute :00, GitHub's peak window, where scheduled runs get delayed or skipped. Shift to any other minute for the same cadence with less contention.
on:
schedule:
- cron: '45 2 * * *' # was '0 2 * * *' — any non-:00 minute avoids the herdSecurity AuditThe schedule has no repository guard, so forks that enable Actions inherit the cron and burn their own minutes. Gate the job with `if: github.repository == 'owner/repo'`.
jobs:
nightly:
if: github.repository == 'owner/repo'
runs-on: ubuntu-latestCIRuns on every push/PR with no `paths:` filter, so docs-only changes still trigger full CI. Add a `paths:` filter if that's common.
on:
pull_request:
paths:
- 'src/**'
- 'package.json'CImacOS bills ~10x and Windows ~2x a Linux minute. The cost estimate above assumes Linux, so your real spend is higher. Move any job that doesn't need them to `ubuntu-latest`.
jobs:
build:
runs-on: ubuntu-latest # ~10x cheaper than macos-latestCISystem packages install from the network on every run with no cache. Cache them (cache-apt-pkgs-action) or check whether the runner image already has the tool.
- uses: awalsh128/cache-apt-pkgs-action@latest
with:
packages: <your packages>
version: 1.0CI41 third-party actions pinned to a branch or other mutable ref, which can change under you (supply-chain risk, non-reproducible builds). Pin to a full commit SHA instead. (63 more on a major-version tag like @v4; consider full-SHA pinning there too.)
uses: dtolnay/rust-toolchain@<full-sha> # was @stablePull Request LabelerNo job sets `timeout-minutes`, so a hung step can run to GitHub's 6-hour default. Add `timeout-minutes` to each job.
jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 15LoomNo job sets `timeout-minutes`, so a hung step can run to GitHub's 6-hour default. Add `timeout-minutes` to each job.
jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 15LoomRuns on every push/PR with no `paths:` filter, so docs-only changes still trigger full CI. Add a `paths:` filter if that's common.
on:
pull_request:
paths:
- 'src/**'
- 'package.json'Loom6 third-party actions pinned to a branch or other mutable ref, which can change under you (supply-chain risk, non-reproducible builds). Pin to a full commit SHA instead. (6 more on a major-version tag like @v4; consider full-SHA pinning there too.)
uses: dtolnay/rust-toolchain@<full-sha> # was @masterPull Request Security AuditNo job sets `timeout-minutes`, so a hung step can run to GitHub's 6-hour default. Add `timeout-minutes` to each job.
jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 15Stress TestNo job sets `timeout-minutes`, so a hung step can run to GitHub's 6-hour default. Add `timeout-minutes` to each job.
jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 15Stress TestRuns on every push/PR with no `paths:` filter, so docs-only changes still trigger full CI. Add a `paths:` filter if that's common.
on:
pull_request:
paths:
- 'src/**'
- 'package.json'Stress Test2 third-party actions pinned to a branch or other mutable ref, which can change under you (supply-chain risk, non-reproducible builds). Pin to a full commit SHA instead. (1 more on a major-version tag like @v4; consider full-SHA pinning there too.)
uses: dtolnay/rust-toolchain@<full-sha> # was @master# No job timeout (applies to: Security Audit, Pull Request Labeler, Loom, Pull Request Security Audit, Stress Test)
jobs:
build:
runs-on: ubuntu-latest
timeout-minutes: 15
# Scheduled at the top of the hour (applies to: Security Audit)
on:
schedule:
- cron: '45 2 * * *' # was '0 2 * * *' — any non-:00 minute avoids the herd
# Scheduled workflow runs in forks (applies to: Security Audit)
jobs:
nightly:
if: github.repository == 'owner/repo'
runs-on: ubuntu-latest
# No path filters on triggers (applies to: CI, Loom, Stress Test)
on:
pull_request:
paths:
- 'src/**'
- 'package.json'
# Premium runners (macOS / Windows) (applies to: CI)
jobs:
build:
runs-on: ubuntu-latest # ~10x cheaper than macos-latest
# System packages reinstalled every run (applies to: CI)
- uses: awalsh128/cache-apt-pkgs-action@latest
with:
packages: <your packages>
version: 1.0
# Third-party actions pinned to a mutable ref (applies to: CI)
uses: dtolnay/rust-toolchain@<full-sha> # was @stable
# Third-party actions pinned to a mutable ref (applies to: Loom, Stress Test)
uses: dtolnay/rust-toolchain@<full-sha> # was @masterEach snippet is representative. Merge into the named workflow files rather than pasting wholesale.
This scorecard is a one-time snapshot. Install the free GitHub App to track this repo continuously: new regressions caught as they land, trends over time, on your public and private repos. Team adds the offending commit on the PR + Slack alerts.
Install & monitor this repo →💬 On Team, this same analysis posts automatically to every PR: the regression, and the exact commit that caused it, right where your team already looks. See plans →
Not ready to install? Get this report by email. No spam, unsubscribe anytime.