aiceflower opened a new issue, #5485: URL: https://github.com/apache/linkis/issues/5485
### Search before asking - [x] I searched the [issues](https://github.com/apache/linkis/issues) and found no similar issues. ### Linkis Component - [x] linkis-dist (GitHub Actions CI workflows) ### Description All third-party GitHub Actions that are not covered by the ASF organization Actions allow-list are rejected by GitHub before any job starts, so affected workflows end with conclusion `startup_failure` (status: "Startup failure"). The jobs never actually run. Affected references (5 in total): | Workflow | Line | Reference | | --- | --- | --- | | `.github/workflows/integration-test.yml` | 99 | `docker/setup-buildx-action@v1` | | `.github/workflows/publish-docker.yaml` | 58 | `docker/setup-qemu-action@v1` | | `.github/workflows/publish-docker.yaml` | 60 | `docker/setup-buildx-action@v1` | | `.github/workflows/publish-docker.yaml` | 72 | `docker/[email protected]` | | `.github/workflows/auto-comment.yml` | 28 | `actions-cool/issues-helper@v3` | The reported annotation is: > The action `docker/setup-buildx-action@v1` is not allowed in apache/linkis because all actions must be from a repository owned by your enterprise, created by GitHub, or match one of the patterns: ... ### Steps to reproduce 1. Open any pull request against `master` (for example #5484, a dependabot PR). 2. Open the triggered `Integration Test` run: https://github.com/apache/linkis/actions/runs/37706014594 3. Observe the run status `startup_failure` and the allow-list annotation above; no job step ever executes. 4. Push to `master` and observe `Publish Docker` failing the same way: https://github.com/apache/linkis/actions/runs/32231573096 (and every run since 2025-11-24, last success was 2025-11-23). 5. Open a new issue and observe `Create Comment` failing the same way: https://github.com/apache/linkis/actions/runs/35649775965 ### Expected behavior All workflows start and execute their jobs. Third-party actions must be referenced by the exact commit SHA listed in [apache/infrastructure-actions/approved_patterns.yml](https://github.com/apache/infrastructure-actions/blob/main/approved_patterns.yml), with the version kept as an inline comment. ### Your environment - GitHub-hosted runner: `ubuntu-latest` - Repository: apache/linkis, default branch `master` - Trigger: `pull_request`, `push`, `issues` ### Anything else - This failure is invisible on the PR checks page: a workflow-level `startup_failure` does not create a check run, so PRs can look green while `Integration Test` is failing (PR #5483 has six `startup_failure` runs yet shows 11 green checks). Runs must be inspected on the Actions tab. - `actions-cool/issues-helper` has **no** entry in the ASF allow-list in any form, so it cannot be fixed by pinning a SHA; the step has to be replaced (for example with the runner-provided `gh` CLI). - The red checks currently shown on PRs (`build-backend`, `spotless-check`, `sql-check`, `third-party-dependencies-check`) are a separate, unrelated problem: master is broken (see #5482 / PR #5483). - Please also note that the ASF allow-list changes over time, so pinned SHAs may need to be re-synced occasionally. ### Are you willing to submit a PR? - [x] Yes I am willing to submit a PR! -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
