Files
Gitea/.github/workflows/cache-prune.yml
T
silverwind d8c3a1afda ci: pin containers to digest, enable more zizmor rules (#38779)
Enable more strict "pedantic" zizmor rules and fix issues. Service
containers are pinned to hash and renovate will update them. Enabled
rules:

- https://docs.zizmor.sh/audits/#excessive-permissions
- https://docs.zizmor.sh/audits/#unpinned-images
- https://docs.zizmor.sh/audits/#template-injection

---------

Signed-off-by: silverwind <me@silverwind.io>
2026-08-06 05:16:07 +00:00

39 lines
1.2 KiB
YAML

name: cache-prune
# Keeps the repository's total cache size below a fixed limit, so that GitHub never
# rejects a save for being over the allowance.
on:
schedule:
- cron: "37 2 * * *" # every day at 02:37 UTC
workflow_dispatch:
workflow_call:
permissions: {}
concurrency:
group: cache-prune
jobs:
prune:
runs-on: ubuntu-latest
if: github.repository == 'go-gitea/gitea'
permissions:
actions: write # to delete caches
env:
GH_TOKEN: ${{ github.token }}
GH_REPO: ${{ github.repository }}
steps:
# Deletes least recently used first, the order GitHub itself evicts in, which takes
# superseded generations first as those stop being restored once a newer one exists.
- name: delete caches over the size limit
run: |
caches=$(gh cache list --limit 1000 --sort last_accessed_at --order asc --json id,key,sizeInBytes)
size=$(jq '[.[].sizeInBytes] | add // 0' <<< "$caches")
echo "cache usage: $((size / 1000000)) MB"
while [ "$size" -gt 6500000000 ] && read -r id bytes key; do
echo "deleting $key"
gh cache delete "$id"
size=$((size - bytes))
done <<< "$(jq -r '.[] | "\(.id) \(.sizeInBytes) \(.key)"' <<< "$caches")"