This is an automated email from the ASF dual-hosted git repository.

tballison pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tika.git


The following commit(s) were added to refs/heads/main by this push:
     new 4de271f510 TIKA-4823: re-pin docker actions to approved SHAs; add ASF 
allow-list check (#3232)
4de271f510 is described below

commit 4de271f510cd7b1aa2f0304371ba17a6f3051080
Author: Tim Allison <[email protected]>
AuthorDate: Thu Sep 24 06:39:13 2026 -0400

    TIKA-4823: re-pin docker actions to approved SHAs; add ASF allow-list check 
(#3232)
---
 .github/dependabot.yml                    |  7 +++++
 .github/workflows/asf-allowlist-check.yml | 48 +++++++++++++++++++++++++++++++
 .github/workflows/docker-release.yml      | 14 ++++-----
 .github/workflows/docker-snapshot.yml     | 16 +++++------
 4 files changed, 70 insertions(+), 15 deletions(-)

diff --git a/.github/dependabot.yml b/.github/dependabot.yml
index 21a6f89f10..adf7706707 100644
--- a/.github/dependabot.yml
+++ b/.github/dependabot.yml
@@ -25,3 +25,10 @@ updates:
       # Allow up to 20 open pull requests
       open-pull-requests-limit: 20
 
+    # Actions pinned by SHA with a "# vX.Y.Z" comment get bumped too. The ASF
+    # allow-list expires a superseded version three months after approving the
+    # next one; asf-allowlist-check.yml fails a bump that is not yet approved.
+    - package-ecosystem: "github-actions"
+      directory: "/"
+      schedule:
+          interval: "weekly"
diff --git a/.github/workflows/asf-allowlist-check.yml 
b/.github/workflows/asf-allowlist-check.yml
new file mode 100644
index 0000000000..cd0cca2cfb
--- /dev/null
+++ b/.github/workflows/asf-allowlist-check.yml
@@ -0,0 +1,48 @@
+#
+# Licensed to the Apache Software Foundation (ASF) under one or more
+# contributor license agreements.  See the NOTICE file distributed with
+# this work for additional information regarding copyright ownership.
+# The ASF licenses this file to You under the Apache License, Version 2.0
+# (the "License"); you may not use this file except in compliance with
+# the License.  You may obtain a copy of the License at
+#
+#      http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+#
+
+# Every action a workflow uses must be on the ASF org allow-list, or the
+# workflow fails at startup with no logs (TIKA-4823, twice). This check fails
+# a PR that introduces an unapproved ref and warns 30 days before a pinned
+# version expires; the weekly run is what surfaces the expiry warning when
+# nothing under .github/ is changing.
+name: ASF allowlist check
+
+on:
+  workflow_dispatch:
+  pull_request:
+    paths:
+      - '.github/**'
+  push:
+    branches: [ main ]
+    paths:
+      - '.github/**'
+  schedule:
+    - cron: '17 6 * * 1'
+
+permissions:
+  contents: read
+
+jobs:
+  asf-allowlist-check:
+    runs-on: ubuntu-latest
+    timeout-minutes: 10
+    steps:
+      - uses: actions/checkout@v6
+        with:
+          persist-credentials: false
+      - uses: 
apache/infrastructure-actions/allowlist-check@47b297bbe90f580139129bee531bd84bd95b7f5d
 # allowlist-check/v1.0.4
diff --git a/.github/workflows/docker-release.yml 
b/.github/workflows/docker-release.yml
index 67b14b3c76..6d2df9db6b 100644
--- a/.github/workflows/docker-release.yml
+++ b/.github/workflows/docker-release.yml
@@ -137,19 +137,19 @@ jobs:
           echo "created=$(git show -s --format=%cI HEAD)" >> "$GITHUB_OUTPUT"
 
       - name: Set up Docker Buildx
-        uses: 
docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
+        uses: 
docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
 
       - name: Set up QEMU for multi-arch
         run: docker run --privileged --rm tonistiigi/binfmt --install all
 
       - name: Login to Docker Hub
-        uses: docker/login-action@c99871dec2022cc055c062a10cc1a1310835ceb4 # 
v4.3.0
+        uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # 
v4.6.0
         with:
           username: ${{ secrets.DOCKERHUB_USER }}
           password: ${{ secrets.DOCKERHUB_TOKEN }}
 
       - name: Build and push tika-server minimal
-        uses: 
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+        uses: 
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
         with:
           file: tika-server/docker-build/minimal/Dockerfile
           platforms: linux/amd64,linux/arm64,linux/s390x
@@ -161,7 +161,7 @@ jobs:
           tags: ${{ steps.tags.outputs.minimal }}
 
       - name: Build and push tika-server full
-        uses: 
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+        uses: 
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
         with:
           file: tika-server/docker-build/full/Dockerfile
           platforms: linux/amd64,linux/arm64,linux/s390x
@@ -221,13 +221,13 @@ jobs:
         run: mvn clean install -DskipTests -B 
"-Dorg.slf4j.simpleLogger.log.org.apache.maven.cli.transfer.Slf4jMavenTransferListener=warn"
 
       - name: Set up Docker Buildx
-        uses: 
docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
+        uses: 
docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
 
       - name: Set up QEMU for multi-arch
         run: docker run --privileged --rm tonistiigi/binfmt --install all
 
       - name: Login to Docker Hub
-        uses: docker/login-action@c99871dec2022cc055c062a10cc1a1310835ceb4 # 
v4.3.0
+        uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # 
v4.6.0
         with:
           username: ${{ secrets.DOCKERHUB_USER }}
           password: ${{ secrets.DOCKERHUB_TOKEN }}
@@ -283,7 +283,7 @@ jobs:
           cp "tika-grpc/docker-build/Dockerfile" "${OUT_DIR}/Dockerfile"
 
       - name: Build and push tika-grpc
-        uses: 
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+        uses: 
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
         with:
           context: target/tika-grpc-docker
           platforms: linux/amd64,linux/arm64
diff --git a/.github/workflows/docker-snapshot.yml 
b/.github/workflows/docker-snapshot.yml
index 36e1654038..4e5a1f0c7b 100644
--- a/.github/workflows/docker-snapshot.yml
+++ b/.github/workflows/docker-snapshot.yml
@@ -92,13 +92,13 @@ jobs:
         run: mvn clean install -DskipTests -B 
"-Dorg.slf4j.simpleLogger.log.org.apache.maven.cli.transfer.Slf4jMavenTransferListener=warn"
 
       - name: Set up Docker Buildx
-        uses: 
docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
+        uses: 
docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
 
       - name: Set up QEMU for multi-arch
         run: docker run --privileged --rm tonistiigi/binfmt --install all
 
       - name: Login to Docker Hub
-        uses: docker/login-action@c99871dec2022cc055c062a10cc1a1310835ceb4 # 
v4.3.0
+        uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # 
v4.6.0
         with:
           username: ${{ secrets.DOCKERHUB_USER }}
           password: ${{ secrets.DOCKERHUB_TOKEN }}
@@ -113,7 +113,7 @@ jobs:
           cp "tika-server/docker-build/minimal/Dockerfile.snapshot" 
"${OUT_DIR}/Dockerfile"
 
       - name: Build tika-server minimal image for smoke test
-        uses: 
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+        uses: 
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
         with:
           context: target/tika-server-minimal-docker
           platforms: linux/amd64
@@ -147,7 +147,7 @@ jobs:
           exit 1
 
       - name: Build and push tika-server minimal snapshot
-        uses: 
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+        uses: 
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
         with:
           context: target/tika-server-minimal-docker
           platforms: linux/amd64,linux/arm64,linux/s390x
@@ -169,7 +169,7 @@ jobs:
           cp "tika-server/docker-build/full/Dockerfile.snapshot" 
"${OUT_DIR}/Dockerfile"
 
       - name: Build tika-server full image for smoke test
-        uses: 
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+        uses: 
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
         with:
           context: target/tika-server-full-docker
           platforms: linux/amd64
@@ -203,7 +203,7 @@ jobs:
           exit 1
 
       - name: Build and push tika-server full snapshot
-        uses: 
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+        uses: 
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
         with:
           context: target/tika-server-full-docker
           platforms: linux/amd64,linux/arm64,linux/s390x
@@ -254,7 +254,7 @@ jobs:
           cp "tika-grpc/docker-build/Dockerfile" "${OUT_DIR}/Dockerfile"
 
       - name: Build tika-grpc image for smoke test
-        uses: 
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+        uses: 
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
         with:
           context: target/tika-grpc-docker
           platforms: linux/amd64
@@ -290,7 +290,7 @@ jobs:
           exit 1
 
       - name: Build and push tika-grpc snapshot
-        uses: 
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+        uses: 
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
         with:
           context: target/tika-grpc-docker
           platforms: linux/amd64,linux/arm64

Reply via email to