pjfanning opened a new pull request, #1884: URL: https://github.com/apache/pekko-connectors/pull/1884
### Motivation Every fresh `CI` and `Headers` run for 1.4.x-targeted PRs currently fails with `startup_failure` and zero jobs (e.g. both runs for #1883). The run page banner states the cause: > The actions `sbt/setup-sbt@1cad58d595b729a71ca2254cdf5b43dd6f42d4bb` and `coursier/cache-action@e47d7d35a0d3a2c7f649ca5c63dfc2bbfaa002e7` are not allowed in apache/pekko-connectors because all actions must be from a repository owned by your enterprise, created by GitHub, or match one of the patterns: … The ASF org allowlists third-party actions by exact SHA, and the old pins on this branch have dropped off the list. `main`'s workflows pin newer SHAs of the same actions and run fine (GitHub-owned actions like `actions/checkout` / `actions/setup-java` are always allowed, and `format.yml` passes because its `jrouly/scalafmt-native-action` SHA matches `main`'s). Re-runs of runs created before the allowlist change still execute — policy is applied when a run is created — which masked the breakage until a new PR was opened against 1.4.x. ### Modification Update `check-build-test.yml` and `headers.yml` on 1.4.x to the allowlisted SHAs already used on `main`: - `sbt/setup-sbt` `1cad58d5` (v1.1.18) → `c7d2d625` (v1.5.8) - `coursier/cache-action` `e47d7d35` → `95e5b102` (both v6.4.7) No functional change to what the jobs do (JDK versions, sbt commands and matrix untouched). `dependency-graph.yml` also carries an old pin but only triggers on push to the default branch, so it never runs from 1.4.x and is left alone. ### Result CI and Headers workflows start again for 1.4.x-targeted PRs. After this merges, existing 1.4.x PRs (#1883, and #1872 for its separate ftp-timeout failure) need a fresh merge commit — close/reopen or rebase — since re-running an existing run reuses its frozen merge snapshot and old workflow files. ### Tests - This PR's own CI run is the verification: `pull_request` runs take workflow definitions from the merge commit, so its jobs starting (rather than `startup_failure`) proves the fix. ### References None - unblocks CI for 1.4.x PRs such as #1883 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
