Cache scope from the branch
On Actions, main writes trusted cache entries and a pull request writes only its own.

A shared cache needs a rule for who may write. On GitHub Actions, @vzn/vx-ci sets it from the ref: the default branch is trusted, a pull request gets a scope of its own.
No config needed; set cacheScope yourself to override it.
// config
// vx.workspace.ts
import { defineWorkspace } from '@vzn/vx/config'
import { github } from '@vzn/vx-ci'
export default defineWorkspace({
plugins: [github({ cacheScope: true })],
})More in CI

Run only what a change reaches
--affected follows task edges from the change, and nothing else runs.

vx lock
CI runs exactly the config you reviewed.

Flaky task detection
Local and free: the same key failing after it passed is called flaky.

Results on GitHub
Every run on GitHub Actions writes a job summary and a check.

Results on the pull request
A check run on the commit carries the run summary, failures first.