From 5eb4c3a0be72aa8081819a3068d13db2d5fd31a8 Mon Sep 17 00:00:00 2001 From: Sugat <233906380+SugatD@users.noreply.github.com> Date: Fri, 21 Aug 2026 16:14:17 +0530 Subject: [PATCH] Refresh apt package index before installing additional_packages The runner image's baked-in apt package lists can lag behind the live Ubuntu archive. When a package gets a security update, the old .deb is removed from the mirror pool -- only the current version stays available. Installing straight from the stale cached index (without an apt-get update first) then 404s on the now-evicted old version, even though a perfectly good current build exists. Observed on puppetlabs-tomcat's Spec job: apt-get install -y libcurl4-openssl-dev failed fetching libcurl4-openssl-dev_8.5.0-2ubuntu10.11_amd64.deb (404), while libcurl4-openssl-dev_8.5.0-2ubuntu10.12_amd64.deb was live on the mirror at the same time. This affects any module using the additional_packages input, not just tomcat. Co-Authored-By: Claude Sonnet 5 --- .github/workflows/module_ci.yml | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/.github/workflows/module_ci.yml b/.github/workflows/module_ci.yml index 8408872..5e394e1 100644 --- a/.github/workflows/module_ci.yml +++ b/.github/workflows/module_ci.yml @@ -61,7 +61,12 @@ jobs: - name: "Install additional packages" if: ${{ inputs.additional_packages != '' }} - run: sudo apt-get install -y ${{ inputs.additional_packages }} + # Refresh the package index first: the runner image's baked-in apt lists can lag + # behind the live archive, so installing straight away can 404 on a package whose + # exact cached version has since been superseded and evicted from the mirror pool. + run: | + sudo apt-get update + sudo apt-get install -y ${{ inputs.additional_packages }} - name: "Configure forge authentication" env: @@ -116,7 +121,12 @@ jobs: - name: "Install additional packages" if: ${{ inputs.additional_packages != '' }} - run: sudo apt-get install -y ${{ inputs.additional_packages }} + # Refresh the package index first: the runner image's baked-in apt lists can lag + # behind the live archive, so installing straight away can 404 on a package whose + # exact cached version has since been superseded and evicted from the mirror pool. + run: | + sudo apt-get update + sudo apt-get install -y ${{ inputs.additional_packages }} - name: "Configure forge authentication" env: