From 160a20125ec1105f5a995a5a43affc3c106d07e1 Mon Sep 17 00:00:00 2001 From: tiennm99 Date: Fri, 14 Aug 2026 14:25:40 +0700 Subject: [PATCH] fix(ci): give each ref its own concurrency lane MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The group was the literal string "pages", so every run of this workflow shared one lane regardless of branch, and cancel-in-progress meant the newest arrival won. A pull-request run therefore cancels an in-flight deploy of main. That is not theoretical: the deploy of #10 was killed 3m22s in by a pull-request run that started after it, and the site quietly stayed on the previous build. Nothing reported a failure — the PR checks were green and the deploy showed "cancelled", which reads like something someone chose. Keyed by ref, a push still cancels its own superseded run, which is the case worth cancelling, and a branch can no longer interrupt a deploy. Also drops "compress it" from the pipeline comment: the databases have shipped uncompressed since they started being read by range request. --- .github/workflows/deploy-pages.yml | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/.github/workflows/deploy-pages.yml b/.github/workflows/deploy-pages.yml index 56ed29b..4dc3f31 100644 --- a/.github/workflows/deploy-pages.yml +++ b/.github/workflows/deploy-pages.yml @@ -13,8 +13,14 @@ permissions: pages: write id-token: write +# Keyed by ref, not just "pages". With one shared group a pull-request run and +# a main deploy compete for the same lane, and cancel-in-progress means the +# newer one wins: the deploy of #10 was killed 3m22s in by a PR run that +# started after it, and the site silently stayed on the previous build while +# every check stayed green. Per ref, a push still cancels its own superseded +# run, which is the case where cancelling is worth having. concurrency: - group: pages + group: pages-${{ github.ref }} cancel-in-progress: true jobs: @@ -91,8 +97,8 @@ jobs: for m in parser crawler assembler; do (cd "$m" && "$GOVULNCHECK" ./...); done # One command runs the whole pipeline: compile the parser, build and - # verify each database against its registry row count, compress it, build - # the web app, and assemble _site — refusing to continue if a database is + # verify each database against its registry row count and size, build the + # web app, and assemble _site — refusing to continue if a database is # short, an artifact looks truncated, or one is missing entirely. - name: Build site run: go -C assembler run ./cmd/assemble