You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Bug][CI] GitHub Actions startup failure: third-party actions not in ASF allow-list #5485
I searched the issues and found no similar issues.
Linkis Component
linkis-dist (GitHub Actions CI workflows)
Description
All third-party GitHub Actions that are not covered by the ASF organization Actions allow-list are rejected by GitHub before any job starts, so affected workflows end with conclusion startup_failure (status: "Startup failure"). The jobs never actually run.
Affected references (5 in total):
Workflow
Line
Reference
.github/workflows/integration-test.yml
99
docker/setup-buildx-action@v1
.github/workflows/publish-docker.yaml
58
docker/setup-qemu-action@v1
.github/workflows/publish-docker.yaml
60
docker/setup-buildx-action@v1
.github/workflows/publish-docker.yaml
72
docker/login-action@v1.10.0
.github/workflows/auto-comment.yml
28
actions-cool/issues-helper@v3
The reported annotation is:
The action docker/setup-buildx-action@v1 is not allowed in apache/linkis because all actions must be from a repository owned by your enterprise, created by GitHub, or match one of the patterns: ...
All workflows start and execute their jobs. Third-party actions must be referenced by the exact commit SHA listed in apache/infrastructure-actions/approved_patterns.yml, with the version kept as an inline comment.
Your environment
GitHub-hosted runner: ubuntu-latest
Repository: apache/linkis, default branch master
Trigger: pull_request, push, issues
Anything else
This failure is invisible on the PR checks page: a workflow-level startup_failure does not create a check run, so PRs can look green while Integration Test is failing (PR Fix Scala compilation of linkis-module #5483 has six startup_failure runs yet shows 11 green checks). Runs must be inspected on the Actions tab.
actions-cool/issues-helper has no entry in the ASF allow-list in any form, so it cannot be fixed by pinning a SHA; the step has to be replaced (for example with the runner-provided gh CLI).
Search before asking
Linkis Component
Description
All third-party GitHub Actions that are not covered by the ASF organization Actions allow-list are rejected by GitHub before any job starts, so affected workflows end with conclusion
startup_failure(status: "Startup failure"). The jobs never actually run.Affected references (5 in total):
.github/workflows/integration-test.ymldocker/setup-buildx-action@v1.github/workflows/publish-docker.yamldocker/setup-qemu-action@v1.github/workflows/publish-docker.yamldocker/setup-buildx-action@v1.github/workflows/publish-docker.yamldocker/login-action@v1.10.0.github/workflows/auto-comment.ymlactions-cool/issues-helper@v3The reported annotation is:
Steps to reproduce
master(for example Bump moment from 2.29.4 to 2.31.0 in /linkis-web #5484, a dependabot PR).Integration Testrun: https://github.com/apache/linkis/actions/runs/37706014594startup_failureand the allow-list annotation above; no job step ever executes.masterand observePublish Dockerfailing the same way: https://github.com/apache/linkis/actions/runs/32231573096 (and every run since 2025-11-24, last success was 2025-11-23).Create Commentfailing the same way: https://github.com/apache/linkis/actions/runs/35649775965Expected behavior
All workflows start and execute their jobs. Third-party actions must be referenced by the exact commit SHA listed in apache/infrastructure-actions/approved_patterns.yml, with the version kept as an inline comment.
Your environment
ubuntu-latestmasterpull_request,push,issuesAnything else
startup_failuredoes not create a check run, so PRs can look green whileIntegration Testis failing (PR Fix Scala compilation of linkis-module #5483 has sixstartup_failureruns yet shows 11 green checks). Runs must be inspected on the Actions tab.actions-cool/issues-helperhas no entry in the ASF allow-list in any form, so it cannot be fixed by pinning a SHA; the step has to be replaced (for example with the runner-providedghCLI).build-backend,spotless-check,sql-check,third-party-dependencies-check) are a separate, unrelated problem: master is broken (see Scala Compilation is broken on master branch and recent PRs #5482 / PR Fix Scala compilation of linkis-module #5483).Are you willing to submit a PR?