diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index 616a88f..4f38e41 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -390,7 +390,11 @@ jobs: echo "services=$(paste -sd, /tmp/services.txt)" >> "$GITHUB_OUTPUT" - name: Log in to registry - if: steps.services.outputs.services != '' + # The pin step below also writes (manifest PUTs), and it runs on every + # main push — including manifest-only ones where services is empty. A + # stale persistent login on the old runner used to mask this; a clean + # runner pushes anonymously and gets 401. + if: steps.services.outputs.services != '' || github.ref_name == 'main' shell: bash # Through env, not by substitution into the script. A secret written # into a run: block is pasted into the shell source before bash parses