ci: Include root pubspec.yaml in pub cache key#189826
Merged
Merged
Conversation
The `pub package cache` step in composite-flutter-setup keys its cache on a hash of the pubspec.yaml files found under dev/, examples/, and packages/, but omits the root workspace pubspec.yaml. The root pubspec pins the versions of all transitive dependencies, so a pub roll that only touches the root, leaves the hash, and therefore the hash key, unchanged. This is exactly what happens on pub package rolls like flutter#189760. When that happens the cache still hits and restores a stale pubspec.lock over the freshly checked-out one. At that point, the following `flutter update-packages` then fails when run with `--enforce-lockfile`, since the lock file we just restored from cache no longer matches the pinned versions in the checked-out root pubspec.yaml, which breaks the Tree Analyze step tree-wide until the cache is manually invalidated. We now include the root pubspec.yaml in the hash so that a packages only roll changes the cache key, forcing a fresh package resolve rather than restoring a stale lock. Fixes: flutter#189825
Contributor
There was a problem hiding this comment.
Code Review
This pull request updates the GitHub Action composite-flutter-setup to include the root pubspec.yaml file when generating the stable hash for dependency caching. Feedback was provided to correct a typo in the updated comment, which incorrectly refers to pubspec.yaml as package.yaml.
jtmcdole
reviewed
Jul 22, 2026
| # Generate a stable hash for github caching from the pubspec.yaml | ||
| # files that drive dependency resolution. Includes the root | ||
| # pubspec.yaml and all pubspec.yaml files from dev/examples/packages. | ||
| find pubspec.yaml dev examples packages -name "pubspec.yaml" -print0 | sort -z | xargs -0 cat | sha256sum >> "$RUNNER_TEMP/pub_deps_sha" |
Member
There was a problem hiding this comment.
Hash only tracked pubspec.yaml files in the tree and their contents... its faster because the objects are already in the git db:
git ls-tree HEAD -- $(git ls-files '*/pubspec.yaml') | git hash-object --stdin
jtmcdole
previously approved these changes
Jul 22, 2026
Updated the method for generating a stable hash for GitHub caching from pubspec.yaml files to use git commands for improved accuracy.
jtmcdole
approved these changes
Jul 22, 2026
jtmcdole
left a comment
Member
There was a problem hiding this comment.
my approval isn't enough since I made the last commit.
ievdokdm
approved these changes
Jul 22, 2026
auto-submit Bot
pushed a commit
to flutter/packages
that referenced
this pull request
Jul 22, 2026
flutter/flutter@1ac2e82...2a2a79d 2026-07-22 [email protected] Clear cached directional focus history on a non-directional focus request (flutter/flutter#187957) 2026-07-22 [email protected] ci: Include root pubspec.yaml in pub cache key (flutter/flutter#189826) 2026-07-22 [email protected] Remove codecov badge from README (flutter/flutter#189728) 2026-07-22 [email protected] Clean android engine/embedding tests (flutter/flutter#189276) 2026-07-22 [email protected] Add barrierBuilder support to showDialog and showGeneralDialog (flutter/flutter#187992) 2026-07-22 [email protected] Fix Mockito dynamic agent loading warnings in Robolectric tests (flutter/flutter#189804) 2026-07-22 [email protected] [iOS] Remove dead RasterThreadMerger plumbing from platform views (flutter/flutter#189753) 2026-07-22 [email protected] Add OverlayPortal.overlayChildLayoutBuilder sample (flutter/flutter#188930) 2026-07-22 [email protected] Automate recurring tasks via workflows - localizations (flutter/flutter#189750) 2026-07-21 [email protected] [iOS] Remove dead parameters and no-op overrides (flutter/flutter#189754) 2026-07-21 [email protected] [iOS] Inject DisplayLinkManager into FlutterViewController (flutter/flutter#189764) 2026-07-21 [email protected] Support custom BoxBorder animation in BoxDecoration (flutter/flutter#186348) 2026-07-21 [email protected] Rename CpuArch.x86_64 to CpuArch.x64 (flutter/flutter#189478) 2026-07-21 [email protected] Roll Skia from 569534e9fa59 to 5e183e5aeac5 (3 revisions) (flutter/flutter#189795) 2026-07-21 [email protected] Roll Dart SDK from 3b2f5ad7718d to 1e65011ee004 (4 revisions) (flutter/flutter#189791) 2026-07-21 [email protected] Run delete-bot-branches.yaml on `pull_request_target` instead of `pull_request` so that we can access secrets. (flutter/flutter#189793) 2026-07-21 [email protected] Batch release directory correction (flutter/flutter#189738) 2026-07-21 [email protected] [flutter_test][Test cross imports] Move TestWidgetsApp to flutter_test (flutter/flutter#189435) 2026-07-21 [email protected] Fix null-deref/double-dispose in StretchingOverscrollIndicator (#189589) (flutter/flutter#189667) 2026-07-21 [email protected] Roll Packages from 611899b to 8260a1e (10 revisions) (flutter/flutter#189782) 2026-07-21 [email protected] [iOS] Inject DisplayLinkManager into FlutterMetalLayer (flutter/flutter#189752) 2026-07-21 [email protected] Derive the SkImage size used by ImageEncodingImpeller::ConvertDlImageToSkImage from the size of the underlying texture, not the size of the DlImage (flutter/flutter#189739) If this roll has caused a breakage, revert this CL and stop the roller using the controls here: https://autoroll.skia.org/r/flutter-packages Please CC [email protected],[email protected] on the revert to ensure that a human is aware of the problem. To file a bug in Packages: https://github.com/flutter/flutter/issues/new/choose To report a problem with the AutoRoller itself, please file a bug: https://issues.skia.org/issues/new?component=1389291&template=1850622 Documentation for the AutoRoller is here: https://skia.googlesource.com/buildbot/+doc/main/autoroll/README.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The
pub package cachestep in composite-flutter-setup keys its cache on a hash of the pubspec.yaml files found under dev/, examples/, and packages/, but omits the root workspace pubspec.yaml. The root pubspec pins the versions of all transitive dependencies, so a pub roll that only touches the root, leaves the hash, and therefore the hash key, unchanged. This is exactly what happens on pub package rolls like #189760.When that happens the cache still hits and restores a stale pubspec.lock over the freshly checked-out one. At that point, the following
flutter update-packagesthen fails when run with--enforce-lockfile, since the lock file we just restored from cache no longer matches the pinned versions in the checked-out root pubspec.yaml, which breaks the Tree Analyze step tree-wide until the cache is manually invalidated.We now include the root pubspec.yaml in the hash so that a packages only roll changes the cache key, forcing a fresh package resolve rather than restoring a stale lock.
Fixes: #189825
Pre-launch Checklist
///).If you need help, consider asking for advice on the #hackers-new channel on Discord.
If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance.
Note: The Flutter team is currently trialing the use of Gemini Code Assist for GitHub. Comments from the
gemini-code-assistbot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed.