Repository navigation
[fix][COM][ci] pin third-party GitHub Actions to ASF allowlisted SHAs - #5486
Open
aiceflower wants to merge 1 commit into
Open
aiceflower wants to merge 1 commit into
aiceflower wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What is the purpose of the change
Third-party GitHub Actions that are not covered by the ASF organization Actions allow-list are rejected by GitHub before any job starts, so three workflows end with the conclusion
startup_failureand never execute a single step:Integration Test– fails on every pull request (https://github.com/apache/linkis/actions/runs/37706014594)Publish Docker– fails on every push tomastersince 2025-11-24 (last success: 2025-11-23, https://github.com/apache/linkis/actions/runs/32231573096)Create Comment– fails on every new issue (https://github.com/apache/linkis/actions/runs/35649775965)Reported annotation:
ASF requires third-party actions to be referenced by the exact commit SHA listed in apache/infrastructure-actions/approved_patterns.yml. This PR pins the five offending references to allow-listed SHAs (version kept as an inline comment) and replaces the one action that has no allow-list entry at all.
Related issues/PRs
Related issues: close #5485
Brief change log
.github/workflows/integration-test.yml:docker/setup-buildx-action@v1→@f87e5991a6d7451dcb8d9637bfbc97413f497069(v4.4.1).github/workflows/publish-docker.yaml:docker/setup-qemu-action@v1→@99012661954931238ded8c8b007157a8430204e1(v4.4.0).github/workflows/publish-docker.yaml:docker/setup-buildx-action@v1→@f87e5991a6d7451dcb8d9637bfbc97413f497069(v4.4.1).github/workflows/publish-docker.yaml:docker/login-action@v1.10.0→@dbcb813823bdd20940b903addbd779551569679f(v4.6.0).github/workflows/auto-comment.yml:actions-cool/issues-helper@v3is not listed in the ASF allow-list in any form, so it cannot be pinned; the step is replaced by the runner-providedgh issue comment --body-file -(no third-party action, cannot be blocked by the allow-list again). The welcome message text is preserved verbatim.All SHAs were verified against
approved_patterns.ymland mapped to their release tags withgit ls-remote.Notes for reviewers
build-backend,spotless-check,sql-check,third-party-dependencies-check) are not caused by this change:masteris currently broken (see Scala Compilation is broken on master branch and recent PRs #5482 / PR Fix Scala compilation of linkis-module #5483, which fixes the Scala compilation, theTicketCipher.javaspotless violation and thelinkis_dml.sqlscript). They will turn green once Fix Scala compilation of linkis-module #5483 is merged.Integration Testdoes not appear in the PR checks at all: a workflow-levelstartup_failuredoes not create a check run. Its recovery must be verified on the Actions tab – as soon as the run gets past "Startup failure" and starts executing jobs, the allow-list issue is resolved.Publish Dockeronly runs on push tomaster, andCreate Commentonly on new issues, so both can only be fully verified after merge.Checklist
registry/username/passwordand default platform setup)