jdaugherty opened a new pull request, #38:
URL: https://github.com/apache/grails-gradle-publish/pull/38

   CI and the RAT audit are not failing tests on PRs — they never start. Every 
run on #37 and on pushes to this branch line comes back `startup_failure` with 
"This run likely failed because of a workflow file issue", and the last green 
CI on `1.0.x` was 2026-05-03 while its head is from July.
   
   ### Cause
   
   ASF infra only permits third-party actions whose exact SHA is listed in 
[`apache/infrastructure-actions/actions.yml`](https://github.com/apache/infrastructure-actions/blob/main/actions.yml),
 and entries there carry an `expires_at` that ages them out as new versions are 
approved.
   
   Our pinned `gradle/actions/setup-gradle@50e97c2c # v6.1.0` is no longer 
listed at all. The file now has:
   
   ```yaml
   gradle/actions/setup-gradle:
     0723195856401067f7a2779048b490ace7a47d7c:
       tag: v5.0.2
       # Projects have deliberately chosen to not use v6 of the setup-gradle 
action due to licensing model changes.
       # See https://github.com/apache/infrastructure-actions/pull/953
       keep: true
     3f131e8634966bd73d06cc69884922b02e6faf92:
       tag: v6.2.0
       expires_at: 2026-10-30
     9c971963bec38e04b3d30dcc455b5382be2fdbfb:
       tag: v6.3.0
   ```
   
   Every workflow that sets up Gradle — `ci`, `rat`, `release` — is blocked by 
that one reference. It also explains the one workflow that still runs: "Release 
- Drafter" only uses `release-drafter`, which is allowlisted as `'*': keep: 
true`, so any version of it is permitted.
   
   Nothing else in the repo is at fault — all the pinned SHAs still resolve as 
commits, they are simply not approved any more.
   
   ### Changes
   
   | action | before | after |
   |---|---|---|
   | `gradle/actions/setup-gradle` | `50e97c2c` v6.1.0 | `9c971963` **v6.3.0** 
— the current allowlist entry, no expiry |
   | `softprops/action-gh-release` | `3bb12739` v2.6.2 | `efb35369` v3.0.3 |
   | `release-drafter/release-drafter` | `6a93d829` v6.4.0 | `34d80673` v7.7.0 |
   | `actions/checkout` | SHA v4.3.1 / v5.0.1 | `@v7` |
   | `actions/setup-java` | SHA v4.8.0 / v5.2.0 | `@v6` |
   | `actions/upload-artifact` | SHA v4.6.2 | `@v7` |
   | `apache/grails-github-actions/*` | `@asf` | `@v1.0.3` |
   
   The two remaining third-party actions stay pinned by SHA, since that is what 
the allowlist governs. GitHub's own actions and our own 
`apache/grails-github-actions` move to version references: neither is subject 
to the allowlist, which covers third-party actions only, and a version 
reference does not age out the way a pinned SHA does. 
`apache/grails-github-actions` was tracking the `asf` branch rather than a 
release; it is now on its latest tag.
   
   This PR validates itself — `pull_request` workflows run from the head 
branch, so if CI and RAT start and go green here, the fix is confirmed.
   
   ### Two things worth a decision
   
   - **setup-gradle v6 licensing.** The allowlist keeps v5.0.2 pinned with 
`keep: true` and a note that some projects deliberately stayed off v6 over 
Gradle's licensing model change. This repo is already on v6, so this keeps it 
there — but if we want to follow those projects, the alternative is v5.0.2.
   - **SHA pinning for GitHub's own actions.** `apache/grails-core` pins 
`actions/*` by SHA with a version comment (`actions/checkout@de0fac2e # 
v6.0.2`, `actions/setup-java@be666c2f # v5.2.0`, 
`actions/upload-artifact@043fb46d # v7.0.1`). This PR uses version tags 
instead, so the two repos will differ. Happy to switch to SHAs to match if that 
is the org convention we want.
   
   Once this merges, #37 can rebase and finally get a CI run.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to