release/v1.2 Required Checks fails at startup: sbt/setup-sbt pin not on ASF actions allowlist

Open Beginner friendly
#6,989 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
85/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Quiet
Tech stack
github-actions
Domain
ci-cd

Research direction

Inspect the six sbt/setup-sbt references in .github/workflows/build.yml and .github/workflows/build-and-push-images.yml, comparing them with the allowlisted pin used on main. Update the six release/v1.2 pins, then verify that Required Checks starts successfully and the label-gated build/test stacks run for a release/v1.2 PR.

Written by the indexing model from the issue text.

Description

What happened?

All CI on release/v1.2 is broken. The Required Checks workflow ends in startup_failure and never runs, so no build/test checks appear on v1.2 PRs and the label-based stack selection (precheck) never executes — which is why CI appears to "not trigger by label" on v1.2 PRs.

Root cause: release/v1.2 pins sbt/setup-sbt at a SHA that is not on the ASF GitHub Enterprise actions allowlist:

sbt/setup-sbt@508b753e53cb6095967669e0911487d2b9bc9f41  # v1.1.22

GitHub rejects the run while building the workflow graph:

The action sbt/setup-sbt@508b753e53cb6095967669e0911487d2b9bc9f41 is not allowed in apache/texera because all actions must be from a repository owned by your enterprise, created by GitHub, or match one of the patterns: …

Expected: Required Checks starts and runs the label-gated build/test stacks on release/v1.2, same as on main.

main already uses the allowlisted version and its Required Checks is green:

sbt/setup-sbt@6444f4c8111de4b9059c3975def104b03cfaa5f0  # v1.5.2

(main reached v1.5.2 via #6710 / d28b761ae.)

Fix: bump the 6 sbt/setup-sbt pins on release/v1.2 from @508b753e… # v1.1.22 to @6444f4c8111de4b9059c3975def104b03cfaa5f0 # v1.5.2, in .github/workflows/build.yml (×3) and .github/workflows/build-and-push-images.yml (×3). This is a minimal targeted change rather than backporting the large github-actions group bump (#6187), which touches 15 actions across 17 files and conflicts heavily against v1.2.

Impact: all release/v1.2 CI is blocked, including backport PRs #6982 and #6984.

Follow-up: worth auditing the remaining action pins on release/v1.2 against the enterprise allowlist so the next run doesn't fail on a different disallowed action.

How to reproduce?
  1. Open or push to any PR targeting release/v1.2 (e.g. #6982, #6984), or push to release/v1.2.
  2. Observe the Required Checks workflow run ends in startup_failure with no jobs — e.g. https://github.com/apache/texera/actions/runs/30417060865
  3. The run banner reports the disallowed sbt/setup-sbt@508b753e… action.

Started 2026-07-28; release/v1.2 push CI was green through 2026-07-24.

Version/Branch

1.2.0-incubating (release/v1.2)

Commit Hash (Optional)

2bcb9aa7a (current release/v1.2 tip at time of filing)

Dominant language
Scala
Stars
316
Forks
189
Avg merge
2d 20h
Merged PRs (30d)
198

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/texera

All issues in apache/texera

Similar issues

More Scala issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.