The repo has two workflows publishing to the same gh-pages branch:
main-docs.yml JamesIves/github-pages-deploy-action + the automatic
GITHUB_TOKEN -> works
documentation.yml webfactory/ssh-agent + secrets.GH_PAGES_DEPLOY
-> fails
The second has been failing on every push to main with
git@github.com: Permission denied (publickey)
because the GH_PAGES_DEPLOY key is no longer valid. It has gone unnoticed
because the site does still deploy - the other workflow does it, and needs
no configured secret.
Rather than rotate the key and end up with two workflows racing to publish
the same content, this deletes the gh-release job. documentation.yml
becomes PR validation only; main-docs.yml remains the single deploy path.
GH_PAGES_DEPLOY is now referenced nowhere and the repo secret can be
deleted.
This also removes a hardcoded git identity pointing at a former
contributor's personal email address.
Other fixes while in these files:
- main-docs.yml triggered on "push" with no branch filter, and its Deploy
step had no condition, so a push of any branch to this repo would
publish that branch's docs over the live site. Now scoped to main.
- Dropped its unused "python-version: [3.6]" matrix. The job only runs
yarn and npm; the value did nothing but label the check "(3.6)".
- Pinned Node 20 explicitly in both workflows. Docusaurus 3 requires
>= 20 and main-docs.yml was relying on the runner default, which is the
same implicit dependency that left documentation.yml stuck on Node 14.
- Switched main-docs.yml to "yarn install --frozen-lockfile", matching
documentation.yml, so the deploy builds what the lockfile pins.
- Dropped "sudo apt-get install -y yarn"; yarn is preinstalled on
ubuntu-latest and the apt package is a different tool.
- checkout/setup-node v1 and v2 -> v4, clearing the deprecation warnings.
The deploy action itself is left at JamesIves v3 deliberately. v4 renames
its inputs, and this is the only working deploy path, so it is not
something to change in the same PR that touches everything around it.
Verified locally on Node 20: "yarn install --frozen-lockfile" succeeds
against the committed lockfile and the build produces 50 pages.
The repo has two workflows publishing to the same gh-pages branch:
The second fails on every push to main:
The GH_PAGES_DEPLOY key is no longer valid. This has gone unnoticed because the site does still deploy — the other workflow does it, and it needs no configured secret. gh-pages was last updated today, and mapillary.github.io currently serves the Docusaurus 3 build from #186.
Rotating the key would fix a job that is redundant, leaving two workflows racing to publish the same content. So this deletes the gh-release job instead. documentation.yml becomes PR validation only; main-docs.yml stays the single deploy path.
GH_PAGES_DEPLOY is now referenced nowhere and the repo secret can be deleted.
Also removes a hardcoded git identity pointing at a former contributor's personal email address.
Other fixes in the same files
Three of these are more than cosmetic:
Smaller:
Deliberately not changed
The deploy action stays at JamesIves/github-pages-deploy-action@releases/v3. v4 renames its inputs, and this is the only working deploy path — not something to change in the same PR that touches everything around it. Worth a follow-up on its own.
Test plan