Skip to content

[fix][COM][ci] pin third-party GitHub Actions to ASF allowlisted SHAs - #5486

Open
aiceflower wants to merge 1 commit into
masterfrom
fix/ci-actions-allowlist
Open

aiceflower wants to merge 1 commit into
masterfrom
fix/ci-actions-allowlist

Conversation

@aiceflower

Copy link
Copy Markdown
Member

What is the purpose of the change

Third-party GitHub Actions that are not covered by the ASF organization Actions allow-list are rejected by GitHub before any job starts, so three workflows end with the conclusion startup_failure and never execute a single step:

Reported annotation:

The action docker/setup-buildx-action@v1 is not allowed in apache/linkis because all actions must be from a repository owned by your enterprise, created by GitHub, or match one of the patterns: ...

ASF requires third-party actions to be referenced by the exact commit SHA listed in apache/infrastructure-actions/approved_patterns.yml. This PR pins the five offending references to allow-listed SHAs (version kept as an inline comment) and replaces the one action that has no allow-list entry at all.

Related issues/PRs

Related issues: close #5485

Brief change log

  • .github/workflows/integration-test.yml: docker/setup-buildx-action@v1 → @f87e5991a6d7451dcb8d9637bfbc97413f497069 (v4.4.1)
  • .github/workflows/publish-docker.yaml: docker/setup-qemu-action@v1 → @99012661954931238ded8c8b007157a8430204e1 (v4.4.0)
  • .github/workflows/publish-docker.yaml: docker/setup-buildx-action@v1 → @f87e5991a6d7451dcb8d9637bfbc97413f497069 (v4.4.1)
  • .github/workflows/publish-docker.yaml: docker/login-action@v1.10.0 → @dbcb813823bdd20940b903addbd779551569679f (v4.6.0)
  • .github/workflows/auto-comment.yml: actions-cool/issues-helper@v3 is not listed in the ASF allow-list in any form, so it cannot be pinned; the step is replaced by the runner-provided gh issue comment --body-file - (no third-party action, cannot be blocked by the allow-list again). The welcome message text is preserved verbatim.

All SHAs were verified against approved_patterns.yml and mapped to their release tags with git ls-remote.

Notes for reviewers

  • Red checks on this PR (build-backend, spotless-check, sql-check, third-party-dependencies-check) are not caused by this change: master is currently broken (see Scala Compilation is broken on master branch and recent PRs #5482 / PR Fix Scala compilation of linkis-module #5483, which fixes the Scala compilation, the TicketCipher.java spotless violation and the linkis_dml.sql script). They will turn green once Fix Scala compilation of linkis-module #5483 is merged.
  • Integration Test does not appear in the PR checks at all: a workflow-level startup_failure does not create a check run. Its recovery must be verified on the Actions tab – as soon as the run gets past "Startup failure" and starts executing jobs, the allow-list issue is resolved.
  • Publish Docker only runs on push to master, and Create Comment only on new issues, so both can only be fully verified after merge.

Checklist

  • I have read the Contributing Guidelines on pull requests.
  • I have explained the need for this PR and the problem it solves
  • I have explained the changes or the new features added to this PR
  • I have added tests corresponding to this change (N/A: GitHub Actions workflow configuration only, validated by YAML parsing)
  • I have updated the documentation to reflect this change (N/A: CI infrastructure only)
  • I have verified that this change is backward compatible (docker/login-action v4 and setup-buildx/setup-qemu v4 keep the same inputs used here: registry/username/password and default platform setup)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug][CI] GitHub Actions startup failure: third-party actions not in ASF allow-list

1 participant