[Bug][CI] GitHub Actions startup failure: third-party actions not in ASF allow-list
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 35/100
Research direction
Inspect .github/workflows/integration-test.yml, .github/workflows/publish-docker.yaml, and .github/workflows/auto-comment.yml; compare each referenced action with apache/infrastructure-actions/approved_patterns.yml. Pin permitted actions to approved commit SHAs with version comments, and replace actions-cool/issues-helper because it is not allow-listed. Done when the affected workflows start successfully; PR #5486 is already open against this issue.
Written by the indexing model from the issue text.
Description
Search before asking
- I searched the issues and found no similar issues.
Linkis Component
- linkis-dist (GitHub Actions CI workflows)
Description
All third-party GitHub Actions that are not covered by the ASF organization Actions allow-list are rejected by GitHub before any job starts, so affected workflows end with conclusion startup_failure (status: "Startup failure"). The jobs never actually run.
Affected references (5 in total):
| Workflow | Line | Reference |
|---|---|---|
.github/workflows/integration-test.yml |
99 | docker/setup-buildx-action@v1 |
.github/workflows/publish-docker.yaml |
58 | docker/setup-qemu-action@v1 |
.github/workflows/publish-docker.yaml |
60 | docker/setup-buildx-action@v1 |
.github/workflows/publish-docker.yaml |
72 | docker/[email protected] |
.github/workflows/auto-comment.yml |
28 | actions-cool/issues-helper@v3 |
The reported annotation is:
The action
docker/setup-buildx-action@v1is not allowed in apache/linkis because all actions must be from a repository owned by your enterprise, created by GitHub, or match one of the patterns: ...
Steps to reproduce
- Open any pull request against
master(for example #5484, a dependabot PR). - Open the triggered
Integration Testrun: https://github.com/apache/linkis/actions/runs/37706014594 - Observe the run status
startup_failureand the allow-list annotation above; no job step ever executes. - Push to
masterand observePublish Dockerfailing the same way: https://github.com/apache/linkis/actions/runs/32231573096 (and every run since 2025-11-24, last success was 2025-11-23). - Open a new issue and observe
Create Commentfailing the same way: https://github.com/apache/linkis/actions/runs/35649775965
Expected behavior
All workflows start and execute their jobs. Third-party actions must be referenced by the exact commit SHA listed in apache/infrastructure-actions/approved_patterns.yml, with the version kept as an inline comment.
Your environment
- GitHub-hosted runner:
ubuntu-latest - Repository: apache/linkis, default branch
master - Trigger:
pull_request,push,issues
Anything else
- This failure is invisible on the PR checks page: a workflow-level
startup_failuredoes not create a check run, so PRs can look green whileIntegration Testis failing (PR #5483 has sixstartup_failureruns yet shows 11 green checks). Runs must be inspected on the Actions tab. actions-cool/issues-helperhas no entry in the ASF allow-list in any form, so it cannot be fixed by pinning a SHA; the step has to be replaced (for example with the runner-providedghCLI).- The red checks currently shown on PRs (
build-backend,spotless-check,sql-check,third-party-dependencies-check) are a separate, unrelated problem: master is broken (see #5482 / PR #5483). - Please also note that the ASF allow-list changes over time, so pinned SHAs may need to be re-synced occasionally.
Are you willing to submit a PR?
- Yes I am willing to submit a PR!
- Dominant language
- Java
- Stars
- 3.4k
- Forks
- 1.2k
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/linkis
-
[Bug] linkis-application-manager's RMUtils class has a logic bugMay be free again @zhang-arvin claimed this 39 days ago, and no pull request is open. Openbug
Difficulty 1/5 Under an hour Newbie friendliness 86/100
-
Scala Compilation is broken on master branch and recent PRsPossibly taken @pjfanning claimed this 17 days ago. Open
Difficulty 4/5 3-5 days Newbie friendliness 38/100
-
[bug][CGS][entrance] parallelgroup cache not updated when entrance instance goes offlinePossibly taken @zhang-arvin claimed this 30 days ago. Open
Difficulty 4/5 3-5 days Newbie friendliness 55/100
-
Difficulty 4/5 3-5 days Newbie friendliness 28/100
-
Difficulty 3/5 1-2 days Newbie friendliness 55/100
Similar issues
-
backend
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
bcgov/nr-forest-client#2524 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 67/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 74/100
Maintainers usually reply within 1 day
-
team:Lumberjack
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
OpenLiberty/open-liberty#35998 ·
Maintainers usually reply within 1 day
-
[BUG] SQS SendMessageBatch accepts more than 10 entries instead of TooManyEntriesInBatchRequestPossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 67/100
floci-io/floci#5319 · 1 comment ·
Maintainers usually reply within 1 day