From 429bd3dc88d3dfccc44f611badc10559c3974c87 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 26 Aug 2026 21:15:08 +0000 Subject: [PATCH 1/2] ci: bump the actions group across 1 directory with 8 updates Bumps the actions group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4` | `7` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4` | `7` | | [actions/setup-node](https://github.com/actions/setup-node) | `4` | `7` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4` | `8` | | [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2` | `3` | | [actions/setup-python](https://github.com/actions/setup-python) | `5` | `7` | | [actions/github-script](https://github.com/actions/github-script) | `7` | `9` | | [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) | `7.0.6` | `8.1.1` | Updates `actions/checkout` from 4 to 7 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v4...v7) Updates `actions/upload-artifact` from 4 to 7 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](https://github.com/actions/upload-artifact/compare/v4...v7) Updates `actions/setup-node` from 4 to 7 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/v4...v7) Updates `actions/download-artifact` from 4 to 8 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](https://github.com/actions/download-artifact/compare/v4...v8) Updates `softprops/action-gh-release` from 2 to 3 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](https://github.com/softprops/action-gh-release/compare/v2...v3) Updates `actions/setup-python` from 5 to 7 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](https://github.com/actions/setup-python/compare/v5...v7) Updates `actions/github-script` from 7 to 9 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](https://github.com/actions/github-script/compare/v7...v9) Updates `peter-evans/create-pull-request` from 7.0.6 to 8.1.1 - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](https://github.com/peter-evans/create-pull-request/compare/v7.0.6...v8.1.1) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/github-script dependency-version: '9' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-python dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: peter-evans/create-pull-request dependency-version: 8.1.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: softprops/action-gh-release dependency-version: '3' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] --- .github/workflows/ci-linux.yml | 20 +++++++++---------- .github/workflows/ci.yml | 12 +++++------ .../workflows/close-single-word-issues.yml | 2 +- .github/workflows/codeql.yml | 2 +- .github/workflows/create-draft-release.yml | 2 +- .github/workflows/publish-apt.yml | 2 +- .github/workflows/release-pr.yml | 4 ++-- .github/workflows/sync-with-upstream.yml | 2 +- 8 files changed, 23 insertions(+), 23 deletions(-) diff --git a/.github/workflows/ci-linux.yml b/.github/workflows/ci-linux.yml index d2fb70d4e0..68853ca122 100644 --- a/.github/workflows/ci-linux.yml +++ b/.github/workflows/ci-linux.yml @@ -24,7 +24,7 @@ jobs: name: Ubuntu arm64 runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: repository: ${{ inputs.repository || github.repository }} ref: ${{ inputs.ref }} @@ -36,7 +36,7 @@ jobs: - name: Check build artifacts for leaked secrets run: ./script/check-build-secrets.sh - name: Upload output artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: ubuntu-arm64-artifacts path: | @@ -50,7 +50,7 @@ jobs: name: Ubuntu arm runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: repository: ${{ inputs.repository || github.repository }} ref: ${{ inputs.ref }} @@ -62,7 +62,7 @@ jobs: - name: Check build artifacts for leaked secrets run: ./script/check-build-secrets.sh - name: Upload output artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: ubuntu-arm-artifacts path: | @@ -76,7 +76,7 @@ jobs: name: Ubuntu x64 runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: repository: ${{ inputs.repository || github.repository }} ref: ${{ inputs.ref }} @@ -88,7 +88,7 @@ jobs: - name: Check build artifacts for leaked secrets run: ./script/check-build-secrets.sh - name: Upload output artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: ubuntu-amd64-artifacts path: | @@ -109,16 +109,16 @@ jobs: id-token: write # mint the short-lived Sigstore identity attestations: write # record the provenance attestation steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Use Node.js 20.17.0 - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: 20.17.0 cache: yarn - name: Download all artifacts - uses: actions/download-artifact@v4 + uses: actions/download-artifact@v8 with: path: './artifacts' @@ -165,7 +165,7 @@ jobs: echo "---" - name: Create Release - uses: softprops/action-gh-release@v2 + uses: softprops/action-gh-release@v3 with: name: GitHub Desktop for Linux ${{ env.RELEASE_TAG_WITHOUT_PREFIX }} body_path: script/release_notes.txt diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8614f4486b..f1c9e92ee1 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -56,12 +56,12 @@ jobs: env: RELEASE_CHANNEL: ${{ inputs.environment }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: repository: ${{ inputs.repository || github.repository }} ref: ${{ inputs.ref }} submodules: recursive - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version: ${{ env.NODE_VERSION }} cache: yarn @@ -91,16 +91,16 @@ jobs: env: RELEASE_CHANNEL: ${{ inputs.environment }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: repository: ${{ inputs.repository || github.repository }} ref: ${{ inputs.ref }} submodules: recursive - - uses: actions/setup-python@v5 + - uses: actions/setup-python@v7 with: python-version: '3.11' - name: Use Node.js ${{ env.NODE_VERSION }} - uses: actions/setup-node@v4 + uses: actions/setup-node@v7 with: node-version: ${{ env.NODE_VERSION }} cache: yarn @@ -148,7 +148,7 @@ jobs: AZURE_CLIENT_ID: ${{ secrets.AZURE_CODE_SIGNING_CLIENT_ID }} AZURE_CLIENT_SECRET: ${{ secrets.AZURE_CODE_SIGNING_CLIENT_SECRET }} - name: Upload artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 if: ${{ inputs.upload-artifacts }} with: name: ${{matrix.friendlyName}}-${{matrix.arch}} diff --git a/.github/workflows/close-single-word-issues.yml b/.github/workflows/close-single-word-issues.yml index f2ef0dae8e..82eedb6a8e 100644 --- a/.github/workflows/close-single-word-issues.yml +++ b/.github/workflows/close-single-word-issues.yml @@ -14,7 +14,7 @@ jobs: steps: - name: Close Single-Word Issue - uses: actions/github-script@v7 + uses: actions/github-script@v9 with: github-token: ${{ secrets.GITHUB_TOKEN }} script: | diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 0df88e9c02..d9e71e4dd9 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -18,7 +18,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@v4 + uses: actions/checkout@v7 # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL diff --git a/.github/workflows/create-draft-release.yml b/.github/workflows/create-draft-release.yml index 94c08b1a1f..a4cee2c5a1 100644 --- a/.github/workflows/create-draft-release.yml +++ b/.github/workflows/create-draft-release.yml @@ -22,7 +22,7 @@ jobs: name: Publish draft release steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: token: ${{ secrets.CREATE_RELEASE_AUTOMATION_TOKEN }} - name: Configure git diff --git a/.github/workflows/publish-apt.yml b/.github/workflows/publish-apt.yml index 60535629b4..269c6d8486 100644 --- a/.github/workflows/publish-apt.yml +++ b/.github/workflows/publish-apt.yml @@ -26,7 +26,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout (reprepro conf + public key) - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Install tooling run: | diff --git a/.github/workflows/release-pr.yml b/.github/workflows/release-pr.yml index 8780960952..cb7d5d2fc5 100644 --- a/.github/workflows/release-pr.yml +++ b/.github/workflows/release-pr.yml @@ -9,7 +9,7 @@ jobs: permissions: pull-requests: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 if: | startsWith(github.ref, 'refs/heads/releases/') && !contains(github.ref, 'test') @@ -37,7 +37,7 @@ jobs: private_key: ${{ secrets.DESKTOP_RELEASES_APP_PRIVATE_KEY }} - name: Create Release Pull Request - uses: peter-evans/create-pull-request@v7.0.6 + uses: peter-evans/create-pull-request@v8.1.1 if: | startsWith(github.ref, 'refs/heads/releases/') && !contains(github.ref, 'test') with: diff --git a/.github/workflows/sync-with-upstream.yml b/.github/workflows/sync-with-upstream.yml index 36df18944a..2c3ddc26a7 100644 --- a/.github/workflows/sync-with-upstream.yml +++ b/.github/workflows/sync-with-upstream.yml @@ -11,7 +11,7 @@ jobs: name: Sync main branch with upstream steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: token: ${{ secrets.CREATE_RELEASE_AUTOMATION_TOKEN }} - name: Configure git From 7ac9b7e6024c7e1fdcca0bc5f402a0290cd45930 Mon Sep 17 00:00:00 2001 From: "guys-inc-ops[bot]" <321481384+guys-inc-ops[bot]@users.noreply.github.com> Date: Thu, 27 Aug 2026 00:07:37 -0400 Subject: [PATCH 2/2] Stop the state pull from swallowing its own failure (#33) The step ended in '|| true', so a failed pull was indistinguishable from an empty repository: reprepro would add the single incoming package, export, and the sync would overwrite dists/ with a one-package index. Every previously published version stops being listed, the pool objects survive unreferenced, and the run stays green. This is the failure mode recorded in archivist's ADR 0001 as the reason that tool regenerates from scratch rather than pulling mutable state. It was still live here. Two changes. A genuine failure now fails the job, since there is no longer a reason to suppress it - 'aws s3 sync' from an absent prefix already exits 0, so the first publish into a new prefix was never the problem '|| true' solved. And because a zero exit code alone cannot prove the pull was complete, the step now compares the remote object count against what actually landed, and refuses to continue if the remote has content and nothing arrived. Claude-Session: https://claude.ai/code/session_015AH1v3tR8Xw2DmKqJSipPd Co-authored-by: guys-inc-ops[bot] <321481384+guys-inc-ops[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) --- .github/workflows/publish-apt.yml | 25 +++++++++++++++++++++++-- 1 file changed, 23 insertions(+), 2 deletions(-) diff --git a/.github/workflows/publish-apt.yml b/.github/workflows/publish-apt.yml index 99ce2f62d3..445bf1460e 100644 --- a/.github/workflows/publish-apt.yml +++ b/.github/workflows/publish-apt.yml @@ -103,10 +103,31 @@ jobs: AWS_ACCESS_KEY_ID: ${{ secrets.R2_ACCESS_KEY_ID }} AWS_SECRET_ACCESS_KEY: ${{ secrets.R2_SECRET_ACCESS_KEY }} AWS_DEFAULT_REGION: auto + R2_ACCOUNT_ID: ${{ secrets.R2_ACCOUNT_ID }} run: | + set -euo pipefail mkdir -p repo - aws s3 sync "s3://$BUCKET/$PREFIX" repo \ - --endpoint-url "https://${{ secrets.R2_ACCOUNT_ID }}.r2.cloudflarestorage.com" || true + endpoint="https://${R2_ACCOUNT_ID}.r2.cloudflarestorage.com" + + # This step used to end in `|| true`. A failed pull therefore looked + # exactly like an empty repository: reprepro would add the one incoming + # package, export, and the sync would overwrite dists/ with a + # single-package index. Every previously published version silently + # stops being listed, and the run stays green. + # + # So: let a genuine failure fail, and separately catch the case where + # the remote has content but nothing arrived - which a zero exit code + # alone would not reveal. + remote=$(aws s3 ls "s3://$BUCKET/$PREFIX/" --recursive --endpoint-url "$endpoint" | wc -l) + aws s3 sync "s3://$BUCKET/$PREFIX" repo --endpoint-url "$endpoint" --no-progress + pulled=$(find repo -type f | wc -l) + echo "remote objects: $remote, pulled: $pulled" + + if [ "$remote" -gt 0 ] && [ "$pulled" -eq 0 ]; then + echo "::error::Remote holds $remote objects but none were pulled. Refusing to" + echo "::error::republish, which would drop every existing package from the index." + exit 1 + fi - name: Prepare reprepro config run: |