aiceflower opened a new pull request, #5486:
URL: https://github.com/apache/linkis/pull/5486

   ### What is the purpose of the change
   
   Third-party GitHub Actions that are not covered by the ASF organization 
Actions allow-list are rejected by GitHub **before any job starts**, so three 
workflows end with the conclusion `startup_failure` and never execute a single 
step:
   
   - `Integration Test` – fails on every pull request 
(https://github.com/apache/linkis/actions/runs/37706014594)
   - `Publish Docker` – fails on every push to `master` since 2025-11-24 (last 
success: 2025-11-23, https://github.com/apache/linkis/actions/runs/32231573096)
   - `Create Comment` – fails on every new issue 
(https://github.com/apache/linkis/actions/runs/35649775965)
   
   Reported annotation:
   
   > The action `docker/setup-buildx-action@v1` is not allowed in apache/linkis 
because all actions must be from a repository owned by your enterprise, created 
by GitHub, or match one of the patterns: ...
   
   ASF requires third-party actions to be referenced by the exact commit SHA 
listed in 
[apache/infrastructure-actions/approved_patterns.yml](https://github.com/apache/infrastructure-actions/blob/main/approved_patterns.yml).
 This PR pins the five offending references to allow-listed SHAs (version kept 
as an inline comment) and replaces the one action that has no allow-list entry 
at all.
   
   ### Related issues/PRs
   
   Related issues: close #5485
   
   ### Brief change log
   
   - `.github/workflows/integration-test.yml`: `docker/setup-buildx-action@v1` 
→ `@f87e5991a6d7451dcb8d9637bfbc97413f497069` (v4.4.1)
   - `.github/workflows/publish-docker.yaml`: `docker/setup-qemu-action@v1` → 
`@99012661954931238ded8c8b007157a8430204e1` (v4.4.0)
   - `.github/workflows/publish-docker.yaml`: `docker/setup-buildx-action@v1` → 
`@f87e5991a6d7451dcb8d9637bfbc97413f497069` (v4.4.1)
   - `.github/workflows/publish-docker.yaml`: `docker/[email protected]` → 
`@dbcb813823bdd20940b903addbd779551569679f` (v4.6.0)
   - `.github/workflows/auto-comment.yml`: `actions-cool/issues-helper@v3` is 
**not** listed in the ASF allow-list in any form, so it cannot be pinned; the 
step is replaced by the runner-provided `gh issue comment --body-file -` (no 
third-party action, cannot be blocked by the allow-list again). The welcome 
message text is preserved verbatim.
   
   All SHAs were verified against `approved_patterns.yml` and mapped to their 
release tags with `git ls-remote`.
   
   ### Notes for reviewers
   
   - Red checks on this PR (`build-backend`, `spotless-check`, `sql-check`, 
`third-party-dependencies-check`) are **not caused by this change**: `master` 
is currently broken (see #5482 / PR #5483, which fixes the Scala compilation, 
the `TicketCipher.java` spotless violation and the `linkis_dml.sql` script). 
They will turn green once #5483 is merged.
   - `Integration Test` does not appear in the PR checks at all: a 
workflow-level `startup_failure` does not create a check run. Its recovery must 
be verified on the Actions tab – as soon as the run gets past "Startup failure" 
and starts executing jobs, the allow-list issue is resolved.
   - `Publish Docker` only runs on push to `master`, and `Create Comment` only 
on new issues, so both can only be fully verified after merge.
   
   ### Checklist
   
   - [x] I have read the [Contributing Guidelines on pull 
requests](https://github.com/apache/linkis/blob/master/.github/CONTRIBUTING.md).
   - [x] I have explained the need for this PR and the problem it solves
   - [x] I have explained the changes or the new features added to this PR
   - [ ] I have added tests corresponding to this change (N/A: GitHub Actions 
workflow configuration only, validated by YAML parsing)
   - [ ] I have updated the documentation to reflect this change (N/A: CI 
infrastructure only)
   - [x] I have verified that this change is backward compatible 
(docker/login-action v4 and setup-buildx/setup-qemu v4 keep the same inputs 
used here: `registry`/`username`/`password` and default platform setup)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to