What: no job in .github/workflows/ci.yml sets timeout-minutes, so each runs at GitHub's 6-hour default. The hang-prone surfaces are verify-unit/verify-integration (network tofu init) and build/showcase-gif (headless Chromium). A wedged registry download or browser export can hold the PR queue for hours. release.yml already sets timeouts — ci.yml should too.
Fix: add a conservative timeout-minutes (20–30, generous vs. observed run times) to every job in ci.yml. Look at recent green runs to pick values with headroom (typical runs finish well under 15 minutes).
Verify: CI stays green; each job shows the timeout in the run UI.
Found by the 2026-08-30 project audit (finding REL-8).
What: no job in
.github/workflows/ci.ymlsetstimeout-minutes, so each runs at GitHub's 6-hour default. The hang-prone surfaces areverify-unit/verify-integration(networktofu init) andbuild/showcase-gif(headless Chromium). A wedged registry download or browser export can hold the PR queue for hours.release.ymlalready sets timeouts —ci.ymlshould too.Fix: add a conservative
timeout-minutes(20–30, generous vs. observed run times) to every job inci.yml. Look at recent green runs to pick values with headroom (typical runs finish well under 15 minutes).Verify: CI stays green; each job shows the timeout in the run UI.
Found by the 2026-08-30 project audit (finding REL-8).