jdaugherty opened a new pull request, #38: URL: https://github.com/apache/grails-gradle-publish/pull/38
CI and the RAT audit are not failing tests on PRs — they never start. Every run on #37 and on pushes to this branch line comes back `startup_failure` with "This run likely failed because of a workflow file issue", and the last green CI on `1.0.x` was 2026-05-03 while its head is from July. ### Cause ASF infra only permits third-party actions whose exact SHA is listed in [`apache/infrastructure-actions/actions.yml`](https://github.com/apache/infrastructure-actions/blob/main/actions.yml), and entries there carry an `expires_at` that ages them out as new versions are approved. Our pinned `gradle/actions/setup-gradle@50e97c2c # v6.1.0` is no longer listed at all. The file now has: ```yaml gradle/actions/setup-gradle: 0723195856401067f7a2779048b490ace7a47d7c: tag: v5.0.2 # Projects have deliberately chosen to not use v6 of the setup-gradle action due to licensing model changes. # See https://github.com/apache/infrastructure-actions/pull/953 keep: true 3f131e8634966bd73d06cc69884922b02e6faf92: tag: v6.2.0 expires_at: 2026-10-30 9c971963bec38e04b3d30dcc455b5382be2fdbfb: tag: v6.3.0 ``` Every workflow that sets up Gradle — `ci`, `rat`, `release` — is blocked by that one reference. It also explains the one workflow that still runs: "Release - Drafter" only uses `release-drafter`, which is allowlisted as `'*': keep: true`, so any version of it is permitted. Nothing else in the repo is at fault — all the pinned SHAs still resolve as commits, they are simply not approved any more. ### Changes | action | before | after | |---|---|---| | `gradle/actions/setup-gradle` | `50e97c2c` v6.1.0 | `9c971963` **v6.3.0** — the current allowlist entry, no expiry | | `softprops/action-gh-release` | `3bb12739` v2.6.2 | `efb35369` v3.0.3 | | `release-drafter/release-drafter` | `6a93d829` v6.4.0 | `34d80673` v7.7.0 | | `actions/checkout` | SHA v4.3.1 / v5.0.1 | `@v7` | | `actions/setup-java` | SHA v4.8.0 / v5.2.0 | `@v6` | | `actions/upload-artifact` | SHA v4.6.2 | `@v7` | | `apache/grails-github-actions/*` | `@asf` | `@v1.0.3` | The two remaining third-party actions stay pinned by SHA, since that is what the allowlist governs. GitHub's own actions and our own `apache/grails-github-actions` move to version references: neither is subject to the allowlist, which covers third-party actions only, and a version reference does not age out the way a pinned SHA does. `apache/grails-github-actions` was tracking the `asf` branch rather than a release; it is now on its latest tag. This PR validates itself — `pull_request` workflows run from the head branch, so if CI and RAT start and go green here, the fix is confirmed. ### Two things worth a decision - **setup-gradle v6 licensing.** The allowlist keeps v5.0.2 pinned with `keep: true` and a note that some projects deliberately stayed off v6 over Gradle's licensing model change. This repo is already on v6, so this keeps it there — but if we want to follow those projects, the alternative is v5.0.2. - **SHA pinning for GitHub's own actions.** `apache/grails-core` pins `actions/*` by SHA with a version comment (`actions/checkout@de0fac2e # v6.0.2`, `actions/setup-java@be666c2f # v5.2.0`, `actions/upload-artifact@043fb46d # v7.0.1`). This PR uses version tags instead, so the two repos will differ. Happy to switch to SHAs to match if that is the org convention we want. Once this merges, #37 can rebase and finally get a CI run. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
