# Red-proof — the sync keeps a DEPLOYED app's running digest (v0.269.1; live finding night 2026-09-24 Part B)
# Mutation: the call site in internal/sync/sync.go rendered the ladder's newest digest for every app again
#   (`if false && s.renderPlanFn != nil && s.renderPlanFn(appName).Deployed {`)
--- FAIL: TestDigest_SyncerKeepsTheRunningDigest (0.00s)
    --- FAIL: TestDigest_SyncerKeepsTheRunningDigest/runs_an_older_digest (0.00s)
        digest_render_test.go:65: the sync MOVED the running digest (want "@sha256:bbbb…", never "sha256:aaaa…")
    --- FAIL: TestDigest_SyncerKeepsTheRunningDigest/runs_no_digest (0.00s)
        digest_render_test.go:65: the sync MOVED the running digest (want "image: nextcloud:31.0.14-apache\n", never "sha256:aaaa…")
FAIL
# Fix restored → ok  internal/sync; git diff of the mutation: none.
