The GitHub Actions job "CI" on pekko-connectors.git/fix-1.4.x-ci-action-pins has failed. Run started by GitHub user pjfanning (triggered by pjfanning).
Head commit for run: 6ba0075dd641b6fd3d25402152624f2f1fe3c6dc / PJ Fanning <[email protected]> CI: update action SHA pins on 1.4.x to allowlisted versions Motivation: Every fresh CI and Headers run for 1.4.x-targeted PRs now fails with startup_failure and zero jobs. The run banner states the cause: the ASF org enforces an allowlist of actions by exact SHA, and the old pins used on this branch - sbt/setup-sbt@1cad58d5 (v1.1.18) and coursier/cache-action@e47d7d35 (v6.4.7) - are no longer on it. main's workflows pin newer SHAs of the same actions and run fine. Re-runs of runs created before the allowlist change still execute, which masked the breakage until a new PR (#1883) was opened against 1.4.x. Modification: Update the sbt/setup-sbt pin to c7d2d625 (v1.5.8) and the coursier/cache-action pin to 95e5b102 (v6.4.7), the allowlisted SHAs already used on main, in check-build-test.yml and headers.yml. No other workflow on this branch that triggers from 1.4.x uses a disallowed action (dependency-graph.yml also carries an old pin but only triggers on push to the default branch, so it never runs from 1.4.x). Result: CI and Headers workflows start again for 1.4.x-targeted PRs, including this one, whose own run exercises the updated files via the merge commit. Tests: - This PR's own CI run is the verification: pull_request runs take workflow definitions from the merge commit, so its jobs starting at all proves the fix. References: None - unblocks CI for 1.4.x PRs such as #1883 Report URL: https://github.com/apache/pekko-connectors/actions/runs/33450632405 With regards, GitHub Actions via GitBox --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
