aiceflower opened a new issue, #5485:
URL: https://github.com/apache/linkis/issues/5485

   ### Search before asking
   
   - [x] I searched the [issues](https://github.com/apache/linkis/issues) and 
found no similar issues.
   
   ### Linkis Component
   
   - [x] linkis-dist (GitHub Actions CI workflows)
   
   ### Description
   
   All third-party GitHub Actions that are not covered by the ASF organization 
Actions allow-list are rejected by GitHub before any job starts, so affected 
workflows end with conclusion `startup_failure` (status: "Startup failure"). 
The jobs never actually run.
   
   Affected references (5 in total):
   
   | Workflow | Line | Reference |
   | --- | --- | --- |
   | `.github/workflows/integration-test.yml` | 99 | 
`docker/setup-buildx-action@v1` |
   | `.github/workflows/publish-docker.yaml` | 58 | 
`docker/setup-qemu-action@v1` |
   | `.github/workflows/publish-docker.yaml` | 60 | 
`docker/setup-buildx-action@v1` |
   | `.github/workflows/publish-docker.yaml` | 72 | 
`docker/[email protected]` |
   | `.github/workflows/auto-comment.yml` | 28 | 
`actions-cool/issues-helper@v3` |
   
   The reported annotation is:
   
   > The action `docker/setup-buildx-action@v1` is not allowed in apache/linkis 
because all actions must be from a repository owned by your enterprise, created 
by GitHub, or match one of the patterns: ...
   
   ### Steps to reproduce
   
   1. Open any pull request against `master` (for example #5484, a dependabot 
PR).
   2. Open the triggered `Integration Test` run: 
https://github.com/apache/linkis/actions/runs/37706014594
   3. Observe the run status `startup_failure` and the allow-list annotation 
above; no job step ever executes.
   4. Push to `master` and observe `Publish Docker` failing the same way: 
https://github.com/apache/linkis/actions/runs/32231573096 (and every run since 
2025-11-24, last success was 2025-11-23).
   5. Open a new issue and observe `Create Comment` failing the same way: 
https://github.com/apache/linkis/actions/runs/35649775965
   
   ### Expected behavior
   
   All workflows start and execute their jobs. Third-party actions must be 
referenced by the exact commit SHA listed in 
[apache/infrastructure-actions/approved_patterns.yml](https://github.com/apache/infrastructure-actions/blob/main/approved_patterns.yml),
 with the version kept as an inline comment.
   
   ### Your environment
   
   - GitHub-hosted runner: `ubuntu-latest`
   - Repository: apache/linkis, default branch `master`
   - Trigger: `pull_request`, `push`, `issues`
   
   ### Anything else
   
   - This failure is invisible on the PR checks page: a workflow-level 
`startup_failure` does not create a check run, so PRs can look green while 
`Integration Test` is failing (PR #5483 has six `startup_failure` runs yet 
shows 11 green checks). Runs must be inspected on the Actions tab.
   - `actions-cool/issues-helper` has **no** entry in the ASF allow-list in any 
form, so it cannot be fixed by pinning a SHA; the step has to be replaced (for 
example with the runner-provided `gh` CLI).
   - The red checks currently shown on PRs (`build-backend`, `spotless-check`, 
`sql-check`, `third-party-dependencies-check`) are a separate, unrelated 
problem: master is broken (see #5482 / PR #5483).
   - Please also note that the ASF allow-list changes over time, so pinned SHAs 
may need to be re-synced occasionally.
   
   ### Are you willing to submit a PR?
   
   - [x] Yes I am willing to submit a PR!
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to