pjfanning opened a new pull request, #1884:
URL: https://github.com/apache/pekko-connectors/pull/1884

   ### Motivation
   Every fresh `CI` and `Headers` run for 1.4.x-targeted PRs currently fails 
with `startup_failure` and zero jobs (e.g. both runs for #1883). The run page 
banner states the cause:
   
   > The actions `sbt/setup-sbt@1cad58d595b729a71ca2254cdf5b43dd6f42d4bb` and 
`coursier/cache-action@e47d7d35a0d3a2c7f649ca5c63dfc2bbfaa002e7` are not 
allowed in apache/pekko-connectors because all actions must be from a 
repository owned by your enterprise, created by GitHub, or match one of the 
patterns: …
   
   The ASF org allowlists third-party actions by exact SHA, and the old pins on 
this branch have dropped off the list. `main`'s workflows pin newer SHAs of the 
same actions and run fine (GitHub-owned actions like `actions/checkout` / 
`actions/setup-java` are always allowed, and `format.yml` passes because its 
`jrouly/scalafmt-native-action` SHA matches `main`'s). Re-runs of runs created 
before the allowlist change still execute — policy is applied when a run is 
created — which masked the breakage until a new PR was opened against 1.4.x.
   
   ### Modification
   Update `check-build-test.yml` and `headers.yml` on 1.4.x to the allowlisted 
SHAs already used on `main`:
   - `sbt/setup-sbt` `1cad58d5` (v1.1.18) → `c7d2d625` (v1.5.8)
   - `coursier/cache-action` `e47d7d35` → `95e5b102` (both v6.4.7)
   
   No functional change to what the jobs do (JDK versions, sbt commands and 
matrix untouched). `dependency-graph.yml` also carries an old pin but only 
triggers on push to the default branch, so it never runs from 1.4.x and is left 
alone.
   
   ### Result
   CI and Headers workflows start again for 1.4.x-targeted PRs. After this 
merges, existing 1.4.x PRs (#1883, and #1872 for its separate ftp-timeout 
failure) need a fresh merge commit — close/reopen or rebase — since re-running 
an existing run reuses its frozen merge snapshot and old workflow files.
   
   ### Tests
   - This PR's own CI run is the verification: `pull_request` runs take 
workflow definitions from the merge commit, so its jobs starting (rather than 
`startup_failure`) proves the fix.
   
   ### References
   None - unblocks CI for 1.4.x PRs such as #1883


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to