4b7ab46d5c
The OTA pipeline decided OTA-vs-native-rebuild by diffing the current fingerprint against a baseline commit stored in an actions/cache entry keyed most-recent-testflight-commit. That cache only saved on a miss but was restored on every run, so it only advanced when GitHub evicted it. Once eviction stopped (~June 12), the baseline froze, every fingerprint looked changed, and OTA deploys silently stopped - every push ran full native builds instead. Replace the cache baseline with a repo variable (MOST_RECENT_TESTFLIGHT_NATIVE_HASH) advanced by a dedicated recordBaseline job that runs only after both native builds succeed. The fingerprint action (bumped to the hash-aware v0.3.0) compares the current commit's native hash against the variable directly, skipping the baseline checkout+reinstall. recordBaseline is isolated so the PAT that can write repo variables (EAS_BASELINE_VARIABLE_TOKEN - the built-in GITHUB_TOKEN cannot manage variables) lives nowhere else in the pipeline, and refuses to write an empty value. The now-dead cache write steps are removed from the reusable build-submit-ios/android workflows. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>