From a55caaf8c672c7898ccf02daa236f5c1365eba4b Mon Sep 17 00:00:00 2001 From: Kevin Adams Date: Sun, 30 Aug 2026 08:10:36 -0400 Subject: [PATCH] fix: stop development-channel builds from overwriting the testing apt dist MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The "Publish to GitHub Pages testing dist" step ran for both 'testing' and 'development' channel builds and does rm -rf pool/testing before copying in the new .deb — so any push to a release/* branch other than release/3.x silently overwrote the real testing dist with its own alpha build. Confirmed happening 2026-08-30 when release/4.x was created and its 3.2.5~alpha+d0ea761 build replaced release/3.x's legitimate beta build there. Restricted the step to channel == 'testing' only. Co-Authored-By: Claude Sonnet 5 --- .github/workflows/build.yml | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 03b9c5e..736d267 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -474,9 +474,15 @@ jobs: git push - name: Publish to GitHub Pages testing dist - if: >- - needs.build.outputs.channel == 'testing' || - needs.build.outputs.channel == 'development' + # Only real release/3.x / master beta builds go here. "development" + # channel (other release/* branches, e.g. release/4.x) must NOT land + # in this dist — it's shared/public, and this step does `rm -rf + # pool/testing` before copying in the new build, which would silently + # overwrite the real testing dist with an unrelated branch's alpha + # build (confirmed happening 2026-08-30 when release/4.x was created). + # No GitHub Pages publish target exists yet for "development" — it + # just builds/scans/uploads as a workflow artifact until one is added. + if: needs.build.outputs.channel == 'testing' env: APT_SIGNING_KEY: ${{ secrets.APT_SIGNING_KEY }} APT_SIGNING_KEY_PASSPHRASE: ${{ secrets.APT_SIGNING_KEY_PASSPHRASE }}