fix(ci): give each ref its own concurrency lane

The group was the literal string "pages", so every run of this workflow
shared one lane regardless of branch, and cancel-in-progress meant the
newest arrival won. A pull-request run therefore cancels an in-flight
deploy of main.

That is not theoretical: the deploy of #10 was killed 3m22s in by a
pull-request run that started after it, and the site quietly stayed on
the previous build. Nothing reported a failure — the PR checks were
green and the deploy showed "cancelled", which reads like something
someone chose.

Keyed by ref, a push still cancels its own superseded run, which is the
case worth cancelling, and a branch can no longer interrupt a deploy.

Also drops "compress it" from the pipeline comment: the databases have
shipped uncompressed since they started being read by range request.
This commit is contained in:
tiennm99 committed 2026-08-14 14:25:40 +07:00
1 parent 9c8e3461a7
commit 160a20125e
1 file changed
+9 -3
+9 -3
View File
@@ -13,8 +13,14 @@ permissions:
pages: write
id-token: write
# Keyed by ref, not just "pages". With one shared group a pull-request run and
# a main deploy compete for the same lane, and cancel-in-progress means the
# newer one wins: the deploy of #10 was killed 3m22s in by a PR run that
# started after it, and the site silently stayed on the previous build while
# every check stayed green. Per ref, a push still cancels its own superseded
# run, which is the case where cancelling is worth having.
concurrency:
group: pages
group: pages-${{ github.ref }}
cancel-in-progress: true
jobs:
@@ -91,8 +97,8 @@ jobs:
for m in parser crawler assembler; do (cd "$m" && "$GOVULNCHECK" ./...); done
# One command runs the whole pipeline: compile the parser, build and
# verify each database against its registry row count, compress it, build
# the web app, and assemble _site — refusing to continue if a database is
# verify each database against its registry row count and size, build the
# web app, and assemble _site — refusing to continue if a database is
# short, an artifact looks truncated, or one is missing entirely.
- name: Build site
run: go -C assembler run ./cmd/assemble