Skip to content
Latchkey

ci workflow (expressjs/morgan)

The ci workflow from expressjs/morgan, explained and optimized by Latchkey.

C

CI health: C - fair

The optimized version below adds run de-duplication, job timeouts.

Source: expressjs/morgan.github/workflows/ci.ymlLicense MITView source

What it does

This is the ci workflow from the expressjs/morgan repository, a real project running GitHub Actions. It is shown here with attribution under its MIT license.

Below, Latchkey shows a faster, safer version produced by its optimization engine.

The workflow

workflow (.yml)
name: ci

on:
- pull_request
- push

permissions:
  contents: read

jobs:
  test:
    permissions:
      checks: write  # for coverallsapp/github-action to create new checks
      contents: read  # for actions/checkout to fetch code
    runs-on: ubuntu-latest
    strategy:
      matrix:
        name:
        - Node.js 0.8
        - Node.js 0.10
        - Node.js 0.12
        - io.js 1.x
        - io.js 2.x
        - io.js 3.x
        - Node.js 4.x
        - Node.js 5.x
        - Node.js 6.x
        - Node.js 7.x
        - Node.js 8.x
        - Node.js 9.x
        - Node.js 10.x
        - Node.js 11.x
        - Node.js 12.x
        - Node.js 13.x
        - Node.js 14.x
        - Node.js 15.x
        - Node.js 16.x
        - Node.js 17.x
        - Node.js 18.x
        - Node.js 19.x
        - Node.js 20.x
        - Node.js 21.x
        - Node.js 22.x

        include:
        - name: Node.js 0.8
          node-version: "0.8"
          npm-i: mocha@2.5.3 supertest@1.1.0
          npm-rm: nyc

        - name: Node.js 0.10
          node-version: "0.10"
          npm-i: mocha@3.5.3 nyc@10.3.2 supertest@2.0.0

        - name: Node.js 0.12
          node-version: "0.12"
          npm-i: mocha@3.5.3 nyc@10.3.2 supertest@2.0.0

        - name: io.js 1.x
          node-version: "1.8"
          npm-i: mocha@3.5.3 nyc@10.3.2 supertest@2.0.0

        - name: io.js 2.x
          node-version: "2.5"
          npm-i: mocha@3.5.3 nyc@10.3.2 supertest@2.0.0

        - name: io.js 3.x
          node-version: "3.3"
          npm-i: mocha@3.5.3 nyc@10.3.2 supertest@2.0.0

        - name: Node.js 4.x
          node-version: "4.9"
          npm-i: mocha@5.2.0 nyc@11.9.0 supertest@3.4.2

        - name: Node.js 5.x
          node-version: "5.12"
          npm-i: mocha@5.2.0 nyc@11.9.0 supertest@3.4.2

        - name: Node.js 6.x
          node-version: "6.17"
          npm-i: mocha@6.2.2 nyc@14.1.1

        - name: Node.js 7.x
          node-version: "7.10"
          npm-i: mocha@6.2.2 nyc@14.1.1

        - name: Node.js 8.x
          node-version: "8.17"
          npm-i: mocha@7.1.2 nyc@14.1.1

        - name: Node.js 9.x
          node-version: "9.11"
          npm-i: mocha@7.1.2 nyc@14.1.1

        - name: Node.js 10.x
          node-version: "10.24"
          npm-i: mocha@8.4.0

        - name: Node.js 11.x
          node-version: "11.15"
          npm-i: mocha@8.4.0

        - name: Node.js 12.x
          node-version: "12.22"
          npm-i: mocha@9.2.2

        - name: Node.js 13.x
          node-version: "13.14"
          npm-i: mocha@9.2.2

        - name: Node.js 14.x
          node-version: "14.21"

        - name: Node.js 15.x
          node-version: "15.14"

        - name: Node.js 16.x
          node-version: "16.20"

        - name: Node.js 17.x
          node-version: "17.9"

        - name: Node.js 18.x
          node-version: "18.18"

        - name: Node.js 19.x
          node-version: "19.9"

        - name: Node.js 20.x
          node-version: "20.9"

        - name: Node.js 21.x
          node-version: "21.1"

        - name: Node.js 22.x
          node-version: "22.0"

    steps:
    - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1

    - name: Install Node.js ${{ matrix.node-version }}
      shell: bash -eo pipefail -l {0}
      run: |
        nvm install --default ${{ matrix.node-version }}
        if [[ "${{ matrix.node-version }}" == 0.* && "$(cut -d. -f2 <<< "${{ matrix.node-version }}")" -lt 10 ]]; then
          nvm install --alias=npm 0.10
          nvm use ${{ matrix.node-version }}
          if [[ "$(npm -v)" == 1.1.* ]]; then
            nvm exec npm npm install -g npm@1.1
            ln -fs "$(which npm)" "$(dirname "$(nvm which npm)")/npm"
          else
            sed -i '1s;^.*$;'"$(printf '#!%q' "$(nvm which npm)")"';' "$(readlink -f "$(which npm)")"
          fi
          npm config set strict-ssl false
        fi
        dirname "$(nvm which ${{ matrix.node-version }})" >> "$GITHUB_PATH"

    - name: Configure npm
      run: |
        if [[ "$(npm config get package-lock)" == "true" ]]; then
          npm config set package-lock false
        else
          npm config set shrinkwrap false
        fi

    - name: Remove npm module(s) ${{ matrix.npm-rm }}
      run: npm rm --silent --save-dev ${{ matrix.npm-rm }}
      if: matrix.npm-rm != ''

    - name: Install npm module(s) ${{ matrix.npm-i }}
      run: npm install --save-dev ${{ matrix.npm-i }}
      if: matrix.npm-i != ''

    - name: Setup Node.js version-specific dependencies
      shell: bash
      run: |
        # eslint for linting
        # - remove on Node.js < 12
        if [[ "$(cut -d. -f1 <<< "${{ matrix.node-version }}")" -lt 12 ]]; then
          node -pe 'Object.keys(require("./package").devDependencies).join("\n")' | \
            grep -E '^eslint(-|$)' | \
            sort -r | \
            xargs -n1 npm rm --silent --save-dev
        fi

    - name: Install Node.js dependencies
      run: npm install

    - name: List environment
      id: list_env
      shell: bash
      run: |
        echo "node@$(node -v)"
        echo "npm@$(npm -v)"
        npm -s ls ||:
        (npm -s ls --depth=0 ||:) | awk -F'[ @]' 'NR>1 && $2 { print $2 "=" $3 }' >> "$GITHUB_OUTPUT"

    - name: Run tests
      shell: bash
      run: |
        if npm -ps ls nyc | grep -q nyc; then
          npm run test-ci
        else
          npm test
        fi

    - name: Lint code
      if: steps.list_env.outputs.eslint != ''
      run: npm run lint

    - name: Collect code coverage
      uses: coverallsapp/github-action@648a8eb78e6d50909eff900e4ec85cab4524a45b # v2.3.6
      if: steps.list_env.outputs.nyc != ''
      with:
        github-token: ${{ secrets.GITHUB_TOKEN }}
        flag-name: run-${{ matrix.test_number }}
        parallel: true

  coverage:
    permissions:
      checks: write  # for coverallsapp/github-action to create new checks
    needs: test
    runs-on: ubuntu-latest
    steps:
    - name: Upload code coverage
      uses: coverallsapp/github-action@648a8eb78e6d50909eff900e4ec85cab4524a45b # v2.3.6
      with:
        github-token: ${{ secrets.GITHUB_TOKEN }}
        parallel-finished: true

The same workflow, on Latchkey

Removes redundant runs and caps runaway jobs. Added and changed lines are highlighted.

name: ci on:- pull_request- push permissions:  contents: read concurrency:  group: ${{ github.workflow }}-${{ github.ref }}  cancel-in-progress: true jobs:  test:    timeout-minutes: 30    permissions:      checks: write  # for coverallsapp/github-action to create new checks      contents: read  # for actions/checkout to fetch code    runs-on: latchkey-small    strategy:      matrix:        name:        - Node.js 0.8        - Node.js 0.10        - Node.js 0.12        - io.js 1.x        - io.js 2.x        - io.js 3.x        - Node.js 4.x        - Node.js 5.x        - Node.js 6.x        - Node.js 7.x        - Node.js 8.x        - Node.js 9.x        - Node.js 10.x        - Node.js 11.x        - Node.js 12.x        - Node.js 13.x        - Node.js 14.x        - Node.js 15.x        - Node.js 16.x        - Node.js 17.x        - Node.js 18.x        - Node.js 19.x        - Node.js 20.x        - Node.js 21.x        - Node.js 22.x         include:        - name: Node.js 0.8          node-version: "0.8"          npm-i: mocha@2.5.3 supertest@1.1.0          npm-rm: nyc         - name: Node.js 0.10          node-version: "0.10"          npm-i: mocha@3.5.3 nyc@10.3.2 supertest@2.0.0         - name: Node.js 0.12          node-version: "0.12"          npm-i: mocha@3.5.3 nyc@10.3.2 supertest@2.0.0         - name: io.js 1.x          node-version: "1.8"          npm-i: mocha@3.5.3 nyc@10.3.2 supertest@2.0.0         - name: io.js 2.x          node-version: "2.5"          npm-i: mocha@3.5.3 nyc@10.3.2 supertest@2.0.0         - name: io.js 3.x          node-version: "3.3"          npm-i: mocha@3.5.3 nyc@10.3.2 supertest@2.0.0         - name: Node.js 4.x          node-version: "4.9"          npm-i: mocha@5.2.0 nyc@11.9.0 supertest@3.4.2         - name: Node.js 5.x          node-version: "5.12"          npm-i: mocha@5.2.0 nyc@11.9.0 supertest@3.4.2         - name: Node.js 6.x          node-version: "6.17"          npm-i: mocha@6.2.2 nyc@14.1.1         - name: Node.js 7.x          node-version: "7.10"          npm-i: mocha@6.2.2 nyc@14.1.1         - name: Node.js 8.x          node-version: "8.17"          npm-i: mocha@7.1.2 nyc@14.1.1         - name: Node.js 9.x          node-version: "9.11"          npm-i: mocha@7.1.2 nyc@14.1.1         - name: Node.js 10.x          node-version: "10.24"          npm-i: mocha@8.4.0         - name: Node.js 11.x          node-version: "11.15"          npm-i: mocha@8.4.0         - name: Node.js 12.x          node-version: "12.22"          npm-i: mocha@9.2.2         - name: Node.js 13.x          node-version: "13.14"          npm-i: mocha@9.2.2         - name: Node.js 14.x          node-version: "14.21"         - name: Node.js 15.x          node-version: "15.14"         - name: Node.js 16.x          node-version: "16.20"         - name: Node.js 17.x          node-version: "17.9"         - name: Node.js 18.x          node-version: "18.18"         - name: Node.js 19.x          node-version: "19.9"         - name: Node.js 20.x          node-version: "20.9"         - name: Node.js 21.x          node-version: "21.1"         - name: Node.js 22.x          node-version: "22.0"     steps:    - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1     - name: Install Node.js ${{ matrix.node-version }}      shell: bash -eo pipefail -l {0}      run: |        nvm install --default ${{ matrix.node-version }}        if [[ "${{ matrix.node-version }}" == 0.* && "$(cut -d. -f2 <<< "${{ matrix.node-version }}")" -lt 10 ]]; then          nvm install --alias=npm 0.10          nvm use ${{ matrix.node-version }}          if [[ "$(npm -v)" == 1.1.* ]]; then            nvm exec npm npm install -g npm@1.1            ln -fs "$(which npm)" "$(dirname "$(nvm which npm)")/npm"          else            sed -i '1s;^.*$;'"$(printf '#!%q' "$(nvm which npm)")"';' "$(readlink -f "$(which npm)")"          fi          npm config set strict-ssl false        fi        dirname "$(nvm which ${{ matrix.node-version }})" >> "$GITHUB_PATH"     - name: Configure npm      run: |        if [[ "$(npm config get package-lock)" == "true" ]]; then          npm config set package-lock false        else          npm config set shrinkwrap false        fi     - name: Remove npm module(s) ${{ matrix.npm-rm }}      run: npm rm --silent --save-dev ${{ matrix.npm-rm }}      if: matrix.npm-rm != ''     - name: Install npm module(s) ${{ matrix.npm-i }}      run: npm install --save-dev ${{ matrix.npm-i }}      if: matrix.npm-i != ''     - name: Setup Node.js version-specific dependencies      shell: bash      run: |        # eslint for linting        # - remove on Node.js < 12        if [[ "$(cut -d. -f1 <<< "${{ matrix.node-version }}")" -lt 12 ]]; then          node -pe 'Object.keys(require("./package").devDependencies).join("\n")' | \            grep -E '^eslint(-|$)' | \            sort -r | \            xargs -n1 npm rm --silent --save-dev        fi     - name: Install Node.js dependencies      run: npm install     - name: List environment      id: list_env      shell: bash      run: |        echo "node@$(node -v)"        echo "npm@$(npm -v)"        npm -s ls ||:        (npm -s ls --depth=0 ||:) | awk -F'[ @]' 'NR>1 && $2 { print $2 "=" $3 }' >> "$GITHUB_OUTPUT"     - name: Run tests      shell: bash      run: |        if npm -ps ls nyc | grep -q nyc; then          npm run test-ci        else          npm test        fi     - name: Lint code      if: steps.list_env.outputs.eslint != ''      run: npm run lint     - name: Collect code coverage      uses: coverallsapp/github-action@648a8eb78e6d50909eff900e4ec85cab4524a45b # v2.3.6      if: steps.list_env.outputs.nyc != ''      with:        github-token: ${{ secrets.GITHUB_TOKEN }}        flag-name: run-${{ matrix.test_number }}        parallel: true   coverage:    timeout-minutes: 30    permissions:      checks: write  # for coverallsapp/github-action to create new checks    needs: test    runs-on: latchkey-small    steps:    - name: Upload code coverage      uses: coverallsapp/github-action@648a8eb78e6d50909eff900e4ec85cab4524a45b # v2.3.6      with:        github-token: ${{ secrets.GITHUB_TOKEN }}        parallel-finished: true 

What changed

  • Run on Latchkey managed runners with one line (runs-on), which apply the fixes below automatically and self-heal transient failures. This example uses latchkey-small; pick the runner size that fits the job.
  • Cancel superseded runs when a branch or PR gets a newer push.
  • Add a job timeout so a hung step cannot burn hours of runner time.

What Latchkey heals here

This workflow has steps that commonly fail on transient issues (network, registries, flaky browsers). On Latchkey managed runners they are detected, retried, and self-healed instead of failing your build:

  • Dependency installs

This workflow runs 2 jobs (26 with the matrix expanded) per trigger. On Latchkey the same minutes cost up to 58% less than GitHub-hosted, with zero queue time.

Actions used in this workflow

actions/checkout coverallsapp/github-action

Frequently asked questions

What does the ci workflow (expressjs/morgan) workflow do?
This is the ci workflow from the expressjs/morgan repository, a real project running GitHub Actions. It is shown here with attribution under its MIT license.
What CI health grade does this workflow get?
This Automation and other workflow grades C. Paste your own workflow into the Latchkey grader to see its grade and the exact fixes.
How can I improve this Automation and other workflow?
Apply run de-duplication, job timeouts. Latchkey applies these automatically on managed runners when you point runs-on at Latchkey.

References