From 233bcb6423b2726dea5c3246fffa627d6c46ea66 Mon Sep 17 00:00:00 2001 From: Caglar Pir Date: Tue, 8 Sep 2026 11:06:35 +0200 Subject: [PATCH] Remove the redundant broken gh-pages deploy job The repo has two workflows publishing to the same gh-pages branch: main-docs.yml JamesIves/github-pages-deploy-action + the automatic GITHUB_TOKEN -> works documentation.yml webfactory/ssh-agent + secrets.GH_PAGES_DEPLOY -> fails The second has been failing on every push to main with git@github.com: Permission denied (publickey) because the GH_PAGES_DEPLOY key is no longer valid. It has gone unnoticed because the site does still deploy - the other workflow does it, and needs no configured secret. Rather than rotate the key and end up with two workflows racing to publish the same content, this deletes the gh-release job. documentation.yml becomes PR validation only; main-docs.yml remains the single deploy path. GH_PAGES_DEPLOY is now referenced nowhere and the repo secret can be deleted. This also removes a hardcoded git identity pointing at a former contributor's personal email address. Other fixes while in these files: - main-docs.yml triggered on "push" with no branch filter, and its Deploy step had no condition, so a push of any branch to this repo would publish that branch's docs over the live site. Now scoped to main. - Dropped its unused "python-version: [3.6]" matrix. The job only runs yarn and npm; the value did nothing but label the check "(3.6)". - Pinned Node 20 explicitly in both workflows. Docusaurus 3 requires >= 20 and main-docs.yml was relying on the runner default, which is the same implicit dependency that left documentation.yml stuck on Node 14. - Switched main-docs.yml to "yarn install --frozen-lockfile", matching documentation.yml, so the deploy builds what the lockfile pins. - Dropped "sudo apt-get install -y yarn"; yarn is preinstalled on ubuntu-latest and the apt package is a different tool. - checkout/setup-node v1 and v2 -> v4, clearing the deprecation warnings. The deploy action itself is left at JamesIves v3 deliberately. v4 renames its inputs, and this is the only working deploy path, so it is not something to change in the same PR that touches everything around it. Verified locally on Node 20: "yarn install --frozen-lockfile" succeeds against the committed lockfile and the build produces 50 pages. --- .github/workflows/documentation.yml | 38 +++++------------------------ .github/workflows/main-docs.yml | 28 ++++++++++++--------- 2 files changed, 23 insertions(+), 43 deletions(-) diff --git a/.github/workflows/documentation.yml b/.github/workflows/documentation.yml index b389d6d..e9088e2 100644 --- a/.github/workflows/documentation.yml +++ b/.github/workflows/documentation.yml @@ -1,19 +1,20 @@ name: documentation +# Validates that the docs site still builds. Deployment lives in +# main-docs.yml, which publishes to gh-pages using the automatic +# GITHUB_TOKEN and needs no configured secret. on: pull_request: branches: [main] - push: - branches: [main] jobs: checks: - if: github.event_name != 'push' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v1 - - uses: actions/setup-node@v1 + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 with: + # Docusaurus 3 requires Node >= 20 node-version: '20.x' - name: Test Build run: | @@ -26,30 +27,3 @@ jobs: npm i fi npm run build - gh-release: - if: github.event_name != 'pull_request' - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v1 - - uses: actions/setup-node@v1 - with: - node-version: '20.x' - - uses: webfactory/ssh-agent@v0.5.0 - with: - ssh-private-key: ${{ secrets.GH_PAGES_DEPLOY }} - - name: Release to GitHub Pages - env: - USE_SSH: true - GIT_USER: git - run: | - cd docs - git config --global user.email "saifulislam84210@gmail.com" - git config --global user.name "Saif Ul Islam" - if [ -e yarn.lock ]; then - yarn install --frozen-lockfile - elif [ -e package-lock.json ]; then - npm ci - else - npm i - fi - npm run deploy diff --git a/.github/workflows/main-docs.yml b/.github/workflows/main-docs.yml index ab6b464..0e5c28a 100644 --- a/.github/workflows/main-docs.yml +++ b/.github/workflows/main-docs.yml @@ -1,23 +1,29 @@ -on: [push] +name: deploy documentation + +# Builds the docs site and publishes it to the gh-pages branch, which is what +# GitHub Pages serves. Authenticates with the automatic GITHUB_TOKEN, so there +# is no deploy key or secret to maintain. +on: + push: + branches: [main] jobs: build_docs_job: runs-on: ubuntu-latest - strategy: - matrix: - python-version: [3.6] steps: - name: Checkout - uses: actions/checkout@v2 - - name: Dependencies - run: | - sudo apt-get install -y yarn - id: build + uses: actions/checkout@v4 + - name: Set up Node + uses: actions/setup-node@v4 + with: + # Docusaurus 3 requires Node >= 20. This was previously left to the + # runner default, which happened to be new enough but was not pinned. + node-version: '20.x' - name: Build the Website run: | cd docs - yarn - npm run build + yarn install --frozen-lockfile + npm run build - name: Deploy uses: JamesIves/github-pages-deploy-action@releases/v3 with: