You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We are going to start enforcing that all GitHub Actions are SHA pinned, and that you can't introduce a new action without updating the allowlist. The change is already made, this is just updating documentation.
Implementation details
Adds some docs about the process.
Locked down the GitHub Actions in Settings -> Actions -> General
Also updated some "incorrect" SHA values:
octokit/request-action: SHA replaced, The SHA 786351db... turned out to be a that doesn't correspond to any release tag, it was pinned to a random post-release commit rather than the v2.4.0 release.
.github/actions/create-system-test-docker-base-images/action.yml: fixed space #v4.1.0 → # v4.1.0.
dependabot.yml: Both cooldown: blocks were inside their correct list items syntactically, but were visually after comment lines describing the next entry, so just moved them up
Found 0 performance improvements and 1 performance regressions! Performance is the same for 71 metrics, 0 unstable metrics, 62 known flaky benchmarks, 64 flaky benchmarks without significant changes.
Explanation
This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:
🟩 = significantly better candidate vs. baseline
🟥 = significantly worse candidate vs. baseline
We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.
If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.
Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.
More details about the CI and significant changes
You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.
CIs of the difference of means are often centered around 0%, because often changes are not that big:
---------------------------------(------|---^--------)-------------------------------->
-0.6% 0% 0.3% +1.2%
| | |
lower bound of the CI --' | |
sample mean (center of the CI) -------------' |
upper bound of the CI ----------------------'
As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).
For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:
----------------------------------------|---------|---(---------^---------)---------->
0% 1% 1.3% 2.2% 3.1%
| | | |
significant impact threshold --------------' | | |
lower bound of CI --------------' | |
sample mean (center of the CI) --------------------------' |
upper bound of CI ----------------------------------'
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary of changes
Reason for change
We are going to start enforcing that all GitHub Actions are SHA pinned, and that you can't introduce a new action without updating the allowlist. The change is already made, this is just updating documentation.
Implementation details
Also updated some "incorrect" SHA values:
octokit/request-action: SHA replaced, The SHA786351db...turned out to be a that doesn't correspond to any release tag, it was pinned to a random post-release commit rather than thev2.4.0release..github/actions/create-system-test-docker-base-images/action.yml: fixed space#v4.1.0→# v4.1.0.dependabot.yml: Bothcooldown:blocks were inside their correct list items syntactically, but were visually after comment lines describing the next entry, so just moved them upTest coverage
N/A