diff --git a/.github/workflows/pr-trusted.yml b/.github/workflows/pr-trusted.yml index b87e5115b9..745b349bb7 100644 --- a/.github/workflows/pr-trusted.yml +++ b/.github/workflows/pr-trusted.yml @@ -1002,6 +1002,20 @@ jobs: - name: Build run: pnpm build + # This verification only needs `pnpm build` output (the verifier stages + # the public packages' dist and reuses ui/dist itself), yet it ran at the + # end of Canary Dry Run, serially after the ~210-295s release.sh dry run. + # That made Canary Dry Run the slowest check in every green PR run: + # 484s, 572s and 483s in runs 37310951026, 37309272947 and 37308895471 + # (2026-10-05), with this step alone at 210-223s of each. The Build lane + # finished its `pnpm build` in ~206s total in those same runs, so it + # absorbs the step at ~416s while Canary Dry Run drops to ~275-350s and + # neither remains the critical path (server 2/12 at ~437-467s is). + # docker-runner-check.yml runs the same verifier after `pnpm build`. + - name: Verify built-in Grok from a clean public npm install + if: ${{ hashFiles('scripts/verify-grok-npm-install.mjs') != '' }} + run: node scripts/verify-grok-npm-install.mjs + verify_serialized_server: name: Verify serialized server suites (${{ matrix.shard_label }}) needs: [gate] @@ -1246,9 +1260,11 @@ jobs: commit --no-verify -m "ci(canary): stage regenerated lockfile" fi ./scripts/release.sh canary --skip-verify --dry-run - - name: Verify built-in Grok from a clean public npm install - if: ${{ hashFiles('scripts/verify-grok-npm-install.mjs') != '' }} - run: node scripts/verify-grok-npm-install.mjs + + # The clean public npm install verification for the built-in Grok + # provider used to run here, after the dry run. It only needs `pnpm + # build` output, which the Build lane also produces, so it moved there: + # see "Verify built-in Grok from a clean public npm install" in `build`. e2e_shards: