Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Bug][CI] GitHub Actions startup failure: third-party actions not in ASF allow-list

Open
#5,485 0 comments 0 reactions 0 assignees View on GitHub

@aiceflower is already working on this.

Since Oct 8, 2026.

  • #5486 by @aiceflower — open

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Stale
Tech stack
github-actions, shell, yaml
Domain
ci-cd

Research direction

Inspect .github/workflows/integration-test.yml, .github/workflows/publish-docker.yaml, and .github/workflows/auto-comment.yml; compare each referenced action with apache/infrastructure-actions/approved_patterns.yml. Pin permitted actions to approved commit SHAs with version comments, and replace actions-cool/issues-helper because it is not allow-listed. Done when the affected workflows start successfully; PR #5486 is already open against this issue.

Written by the indexing model from the issue text.

Description

bug
Search before asking
  • I searched the issues and found no similar issues.
Linkis Component
  • linkis-dist (GitHub Actions CI workflows)
Description

All third-party GitHub Actions that are not covered by the ASF organization Actions allow-list are rejected by GitHub before any job starts, so affected workflows end with conclusion startup_failure (status: "Startup failure"). The jobs never actually run.

Affected references (5 in total):

Workflow Line Reference
.github/workflows/integration-test.yml 99 docker/setup-buildx-action@v1
.github/workflows/publish-docker.yaml 58 docker/setup-qemu-action@v1
.github/workflows/publish-docker.yaml 60 docker/setup-buildx-action@v1
.github/workflows/publish-docker.yaml 72 docker/[email protected]
.github/workflows/auto-comment.yml 28 actions-cool/issues-helper@v3

The reported annotation is:

The action docker/setup-buildx-action@v1 is not allowed in apache/linkis because all actions must be from a repository owned by your enterprise, created by GitHub, or match one of the patterns: ...

Steps to reproduce
  1. Open any pull request against master (for example #5484, a dependabot PR).
  2. Open the triggered Integration Test run: https://github.com/apache/linkis/actions/runs/37706014594
  3. Observe the run status startup_failure and the allow-list annotation above; no job step ever executes.
  4. Push to master and observe Publish Docker failing the same way: https://github.com/apache/linkis/actions/runs/32231573096 (and every run since 2025-11-24, last success was 2025-11-23).
  5. Open a new issue and observe Create Comment failing the same way: https://github.com/apache/linkis/actions/runs/35649775965
Expected behavior

All workflows start and execute their jobs. Third-party actions must be referenced by the exact commit SHA listed in apache/infrastructure-actions/approved_patterns.yml, with the version kept as an inline comment.

Your environment
  • GitHub-hosted runner: ubuntu-latest
  • Repository: apache/linkis, default branch master
  • Trigger: pull_request, push, issues
Anything else
  • This failure is invisible on the PR checks page: a workflow-level startup_failure does not create a check run, so PRs can look green while Integration Test is failing (PR #5483 has six startup_failure runs yet shows 11 green checks). Runs must be inspected on the Actions tab.
  • actions-cool/issues-helper has no entry in the ASF allow-list in any form, so it cannot be fixed by pinning a SHA; the step has to be replaced (for example with the runner-provided gh CLI).
  • The red checks currently shown on PRs (build-backend, spotless-check, sql-check, third-party-dependencies-check) are a separate, unrelated problem: master is broken (see #5482 / PR #5483).
  • Please also note that the ASF allow-list changes over time, so pinned SHAs may need to be re-synced occasionally.
Are you willing to submit a PR?
  • Yes I am willing to submit a PR!
Dominant language
Java
Stars
3.4k
Forks
1.2k
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/linkis

All issues in apache/linkis

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.