fix: stop development-channel builds from overwriting the testing apt dist

The "Publish to GitHub Pages testing dist" step ran for both 'testing'
and 'development' channel builds and does rm -rf pool/testing before
copying in the new .deb — so any push to a release/* branch other than
release/3.x silently overwrote the real testing dist with its own alpha
build. Confirmed happening 2026-08-30 when release/4.x was created and
its 3.2.5~alpha+d0ea761 build replaced release/3.x's legitimate beta
build there. Restricted the step to channel == 'testing' only.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Kevin Adams
2026-08-30 08:10:36 -04:00
co-authored by Claude Sonnet 5
parent 10286da622
commit a55caaf8c6
+9 -3
View File
@@ -474,9 +474,15 @@ jobs:
git push
- name: Publish to GitHub Pages testing dist
if: >-
needs.build.outputs.channel == 'testing' ||
needs.build.outputs.channel == 'development'
# Only real release/3.x / master beta builds go here. "development"
# channel (other release/* branches, e.g. release/4.x) must NOT land
# in this dist — it's shared/public, and this step does `rm -rf
# pool/testing` before copying in the new build, which would silently
# overwrite the real testing dist with an unrelated branch's alpha
# build (confirmed happening 2026-08-30 when release/4.x was created).
# No GitHub Pages publish target exists yet for "development" — it
# just builds/scans/uploads as a workflow artifact until one is added.
if: needs.build.outputs.channel == 'testing'
env:
APT_SIGNING_KEY: ${{ secrets.APT_SIGNING_KEY }}
APT_SIGNING_KEY_PASSPHRASE: ${{ secrets.APT_SIGNING_KEY_PASSPHRASE }}