Skip to content

fix: avoid GitHub API rate limits for the Node manifest - #1627

Draft
BridgeAR wants to merge 3 commits into
actions:mainfrom
BridgeAR:BridgeAR/2026-09-03-setup-node-manifest
Draft

BridgeAR wants to merge 3 commits into
actions:mainfrom
BridgeAR:BridgeAR/2026-09-03-setup-node-manifest

Conversation

@BridgeAR

@BridgeAR BridgeAR commented Sep 3, 2026

Copy link
Copy Markdown

Large matrices can exhaust the repository GITHUB_TOKEN rate limit because each cold manifest lookup resolves a repository tree and blob through REST.

This reads the fixed raw manifest path first and caches the nonempty response for later setup-node steps in the job. check-latest always bypasses that cache. The existing authenticated API path remains the fallback.

Refs: https://github.com/DataDog/dd-trace-js/actions/runs/33776938250/job/100720885063?pr=9406

@BridgeAR
BridgeAR marked this pull request as ready for review September 3, 2026 18:57
@BridgeAR
BridgeAR requested a review from a team as a code owner September 3, 2026 18:57
@BridgeAR
BridgeAR force-pushed the BridgeAR/2026-09-03-setup-node-manifest branch from 07c11e9 to 7fef00e Compare September 21, 2026 16:30
@BridgeAR

Copy link
Copy Markdown
Author

@v-HarithaVattikuti @v-gowridurgad @v-priyagupta108 @v-chiranjib-swain PTAL, this would help us a lot :)

@v-priyagupta108

Copy link
Copy Markdown
Contributor

Hi @BridgeAR,
Thanks for working on this! Reducing manifest rate-limit failures is a valuable improvement. We have a few suggestions on the approach:

  1. Fetch order: Could we keep the authenticated GitHub API as the primary source and add the raw URL as the fallback, consistent with setup-go and setup-python? Making anonymous raw-first the default may run into the raw host's own rate limits and adds delays on networks that block raw.githubusercontent.com.
  2. check-latest: Runs with check-latest: true still go only to the API, so they're still exposed to rate limits. Point 1 would cover this too.
  3. RUNNER_TEMP cache: This only helps when setup-node runs more than once in the same job. It also adds some risk: cached entries aren't fully validated, and the write isn't atomic. Could we drop it from this PR to keep the fix focused?

Looking forward to your thoughts. Happy to discuss!

Large job matrices exhaust the shared GITHUB_TOKEN rate limit because each cold manifest lookup resolves a repository tree and blob through the REST API.

Use the fixed raw manifest and reuse it within a job. check-latest always refreshes it, and the authenticated API remains a fallback.
Raw manifest responses can remain cached for five minutes, so check-latest keeps the GitHub API path while normal setup steps reuse the job manifest.
@BridgeAR
BridgeAR marked this pull request as draft October 6, 2026 08:59
LTS resolution with check-latest cannot recover from API failures because it
bypasses raw retrieval. The disk cache cannot reduce requests across matrix
jobs and introduces unneeded state.
@BridgeAR
BridgeAR force-pushed the BridgeAR/2026-09-03-setup-node-manifest branch from 7fef00e to 7abcbab Compare October 7, 2026 06:53

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants