diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 30db1eed2..cecffbe05 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -120,8 +120,6 @@ jobs: id: setup_node with: node-version: '22' - cache: 'pnpm' - cache-dependency-path: site/pnpm-lock.yaml # Independent checks keep running after a red sibling; setup outcomes suppress cascaded noise. - name: Verify generated Pages output if: ${{ !cancelled() && steps.setup_pnpm.outcome == 'success' && steps.setup_node.outcome == 'success' }} @@ -253,7 +251,7 @@ jobs: install: rsync - name: Select Windows POSIX test utilities id: select_posix_tools - if: ${{ !cancelled() && runner.os == 'Windows' }} + if: ${{ !cancelled() && runner.os == 'Windows' && steps.posix_tools.outcome == 'success' }} shell: pwsh run: '"${{ steps.posix_tools.outputs.msys2-location }}\usr\bin" >> $env:GITHUB_PATH' # Independent checks keep running after a red sibling; setup outcomes suppress cascaded noise. @@ -818,6 +816,7 @@ jobs: uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 with: name: e2e-live-run + overwrite: true path: | ${{ runner.temp }}/e2e_live/run_manifest.json ${{ runner.temp }}/e2e_live/result_index.jsonl @@ -1068,6 +1067,7 @@ jobs: uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 with: name: android-native-ui-api-${{ matrix.api-level }} + overwrite: true path: | ${{ runner.temp }}/android-smoke/screenshots/ ${{ runner.temp }}/android-smoke/emulator.log diff --git a/docs/development/14-build-and-ci.md b/docs/development/14-build-and-ci.md index 319fee3af..a4510b93a 100644 --- a/docs/development/14-build-and-ci.md +++ b/docs/development/14-build-and-ci.md @@ -84,7 +84,7 @@ Prerelease artifacts may intentionally be unsigned and must report that state; s The artifact pipeline — per-platform archive smokes, native Linux packages, the AppImage custody chain, SBOM and attestation binding, and the seven-required-desktop plus optional-Android release job — lives in ARCHITECTURE §8 and `.github/workflows/ci.yml`. The honesty invariants a change must preserve: -- On a valid release tag, `release-preflight` records the tag/VERSION and prerelease state before checking its required job results. A failed test prerequisite makes the preflight red but permits the desktop build to run as a diagnostic rehearsal; this can consume configured signing/notarization and records attestations in the repository and public transparency log; artifacts remain downloadable from the run, but no GitHub Release is published; the release job still requires a successful preflight. Android publisher builds retain their Android proof dependencies because the signed source/APK pair is optional release content, so failed or skipped Android proofs exclude both optional assets; desktop diagnostics remain evidence only and cannot publish a Release. +- On a valid release tag, `release-preflight` records the tag/VERSION and prerelease state before checking its required job results. A failed test prerequisite makes the preflight red but permits the desktop build to run as a diagnostic rehearsal; this can consume configured signing/notarization and records attestations in the repository and public transparency log; artifacts remain downloadable from the run, but no GitHub Release is published; the release job still requires a successful preflight. Android publisher builds retain their Android proof dependencies because the signed source/APK pair is optional release content, so failed or skipped Android proofs exclude both optional assets; the diagnostic build itself never invokes the release job; if the required tests later pass on a rerun, that same-tag payload may be published with provenance bound to the same SHA. - Publication is draft-first with a per-tag concurrency group; the remote annotated tag is revalidated against the event SHA immediately before draft creation AND again before publication, and a published release is