Gitea stays the source of truth and push-mirrors this repository to GitHub. The org variable BUILD_ON, set on both forges, picks where the heavy work runs: - unset: nothing changes. Gitea's jobs run as before and every job in the GitHub workflow is skipped. - github: Gitea skips its test, build and publish jobs. GitHub Actions runs them on hosted runners, arm64 natively rather than under QEMU, publishes to the same Gitea registry, and posts a commit status back to Gitea. A new `github` job in Gitea's ci.yml waits for that status and passes or fails with it, so the Gitea run still decides a PR. Announcing and releasing stay on Gitea whatever BUILD_ON says. The GitHub-era workflows go: cleanup.yml pruned GHCR, release.yml was a second weekly scheduler, and publish.yml pushed to GHCR. Their work is in the new .github/workflows/ci.yml or stays on Gitea. dependabot.yml goes too: its pull request branches would exist only on GitHub, and every mirror sync would delete them.