A dependency cache stores files that are expensive to fetch again. It is a performance aid, not a release artifact and not a source of truth for versions. A build must be able to succeed from a clean runner using its lockfile and trusted registries when the cache is absent. Cache access and writes also form a security boundary because one workflow may restore files saved by another.
CI dependency caches: speed without hidden build inputs
Operational decision
For a Node-based audit portal, cache package download data keyed to the lockfile and toolchain, then run npm ci so the dependency tree is still checked against the committed lock. Do not cache node_modules across untrusted branches as though it were reviewed source. Keep tokens, generated credentials, and private configuration out of cache paths. The shell block demonstrates the clean install and test steps after a cache restore; the hosting workflow still needs an explicit cache rule and a read-only trust posture for outside pull requests. Measure cold and warm builds separately. If a cache hit saves only a few seconds but expands attack surface or invalidation work, remove it. A cache miss should slow the job, not change the package set or produce a different image digest without explanation.
node --version
npm ci --prefer-offline
npm run lint
npm test
npm run buildCost and verification
Caches consume storage and can increase debugging time when keys are too broad. A lockfile-keyed cache narrows stale reuse but still must be treated as untrusted input; package-manager integrity checks and a clean install help. npm ci removes an existing node_modules directory before installation and fails when the lockfile disagrees with package metadata. That behavior is useful for repeatability, but installation scripts can still execute, so review dependency trust and runner permissions. Do not compare a warm-cache build with a cold build as if their timing had the same conditions.
Common Mistakes
- Do not cache secrets or credentials.
- Do not promote a cache as if it were a verified artifact.
- Do not let an untrusted workflow overwrite a trusted release cache.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Continuous integration: test the merge candidate
- CI runner isolation: treat repository code as untrusted
- Immutable artifacts and release provenance
