Skip to content

Action takes 5-6 seconds to download #2542

Description

@jsoref

It takes 5-6 seconds for workflows to download this repository as an action. I believe it's because the node modules directory is 300+mb. It includes at least two copies of typescript.

@aibaars suggests:

I think they could remove node-modules and compile the typescript code to a few minified scripts

Activity

  1. rvermeulen commented on Oct 16, 2024

    @rvermeulen
    Contributor

    Hi @jsoref,

    Thanks for your suggestion. I will forward it to the team responsible for the Action and provide an update when I receive more information.

  2. aeisenberg commented on Aug 29, 2025

    @aeisenberg
    Contributor

    Now that #3054 is merged, download times should be significantly improved. Thanks for the effort you've put into this already. We'll close this issue and please let us know if download times continue to be a problem.

  3. jsoref commented on Aug 29, 2025

    @jsoref
    ContributorAuthor

    Confirmed. 14s->1s

    before (14s)

    Fri, 29 Aug 2025 17:35:24 GMT
    Download action repository 'github/codeql-action@48dd624a81acd5d5f2e94c2b1e54102c6b5bd642' (SHA:48dd624a81acd5d5f2e94c2b1e54102c6b5bd642)
    Fri, 29 Aug 2025 17:35:38 GMT
    Complete job name: time
    

    after (1s)

    Fri, 29 Aug 2025 17:35:49 GMT
    Download action repository 'github/codeql-action@02ab253bd299d261d00cdf8a9bca38fea2697d50' (SHA:02ab253bd299d261d00cdf8a9bca38fea2697d50)
    Fri, 29 Aug 2025 17:35:50 GMT
    Complete job name: time
    
  4. aeisenberg commented on Aug 29, 2025

    @aeisenberg
    Contributor

    Nice!

  5. jsoref commented on Aug 31, 2025

    @jsoref
    ContributorAuthor

    Fwiw, it looks like you now have 45mb of content (42mb is the bundled actions, and 3mb is everything else) which is a huge improvement over what it was before.

    Personally, I'd kinda want repositories or tags that had only a single action since that's the difference between 2-5M and 45M -- and I'm pretty sure it'd be doable if you were willing to create things where you basically deleted everything except the top level readmes, the relevant js file and the relevant action, committed, and tagged that as a single tag (either ${sha}-${action} or ${action}-${sha}).

    But that's just a bit of cream and I can understand not wanting to do it...

  6. aeisenberg commented on Sep 2, 2025

    @aeisenberg
    Contributor

    I can see how that would be useful for upload-sarif users. It would be less useful for codeql code scanning users since they are the vast majority of codeql action users. I suspect they would see much less of an improvement if we split things up as you suggest.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions