Skip to content

[Bug][CI] GitHub Actions startup failure: third-party actions not in ASF allow-list #5485

Description

@aiceflower

Search before asking

  • I searched the issues and found no similar issues.

Linkis Component

  • linkis-dist (GitHub Actions CI workflows)

Description

All third-party GitHub Actions that are not covered by the ASF organization Actions allow-list are rejected by GitHub before any job starts, so affected workflows end with conclusion startup_failure (status: "Startup failure"). The jobs never actually run.

Affected references (5 in total):

Workflow Line Reference
.github/workflows/integration-test.yml 99 docker/setup-buildx-action@v1
.github/workflows/publish-docker.yaml 58 docker/setup-qemu-action@v1
.github/workflows/publish-docker.yaml 60 docker/setup-buildx-action@v1
.github/workflows/publish-docker.yaml 72 docker/login-action@v1.10.0
.github/workflows/auto-comment.yml 28 actions-cool/issues-helper@v3

The reported annotation is:

The action docker/setup-buildx-action@v1 is not allowed in apache/linkis because all actions must be from a repository owned by your enterprise, created by GitHub, or match one of the patterns: ...

Steps to reproduce

  1. Open any pull request against master (for example Bump moment from 2.29.4 to 2.31.0 in /linkis-web #5484, a dependabot PR).
  2. Open the triggered Integration Test run: https://github.com/apache/linkis/actions/runs/37706014594
  3. Observe the run status startup_failure and the allow-list annotation above; no job step ever executes.
  4. Push to master and observe Publish Docker failing the same way: https://github.com/apache/linkis/actions/runs/32231573096 (and every run since 2025-11-24, last success was 2025-11-23).
  5. Open a new issue and observe Create Comment failing the same way: https://github.com/apache/linkis/actions/runs/35649775965

Expected behavior

All workflows start and execute their jobs. Third-party actions must be referenced by the exact commit SHA listed in apache/infrastructure-actions/approved_patterns.yml, with the version kept as an inline comment.

Your environment

  • GitHub-hosted runner: ubuntu-latest
  • Repository: apache/linkis, default branch master
  • Trigger: pull_request, push, issues

Anything else

  • This failure is invisible on the PR checks page: a workflow-level startup_failure does not create a check run, so PRs can look green while Integration Test is failing (PR Fix Scala compilation of linkis-module #5483 has six startup_failure runs yet shows 11 green checks). Runs must be inspected on the Actions tab.
  • actions-cool/issues-helper has no entry in the ASF allow-list in any form, so it cannot be fixed by pinning a SHA; the step has to be replaced (for example with the runner-provided gh CLI).
  • The red checks currently shown on PRs (build-backend, spotless-check, sql-check, third-party-dependencies-check) are a separate, unrelated problem: master is broken (see Scala Compilation is broken on master branch and recent PRs #5482 / PR Fix Scala compilation of linkis-module #5483).
  • Please also note that the ASF allow-list changes over time, so pinned SHAs may need to be re-synced occasionally.

Are you willing to submit a PR?

  • Yes I am willing to submit a PR!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions