apache / apache/texera

release/v1.2 Required Checks fails at startup: sbt/setup-sbt pin not on ASF actions allowlist

Open Beginner friendly
#6,989 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Scala
Stars
314
Forks
187
Avg merge
1d 21h
Merged PRs (30d)
214

Description

### What happened?

All CI on `release/v1.2` is broken. The **Required Checks** workflow ends in `startup_failure` and never runs, so no build/test checks appear on v1.2 PRs and the label-based stack selection (`precheck`) never executes — which is why CI appears to "not trigger by label" on v1.2 PRs.

Root cause: `release/v1.2` pins `sbt/setup-sbt` at a SHA that is **not on the ASF GitHub Enterprise actions allowlist**:

```
sbt/setup-sbt@508b753e53cb6095967669e0911487d2b9bc9f41 # v1.1.22
```

GitHub rejects the run while building the workflow graph:

> The action `sbt/setup-sbt@508b753e53cb6095967669e0911487d2b9bc9f41` is not allowed in apache/texera because all actions must be from a repository owned by your enterprise, created by GitHub, or match one of the patterns: …

**Expected:** Required Checks starts and runs the label-gated build/test stacks on `release/v1.2`, same as on `main`.

`main` already uses the allowlisted version and its Required Checks is green:

```
sbt/setup-sbt@6444f4c8111de4b9059c3975def104b03cfaa5f0 # v1.5.2
```

(`main` reached v1.5.2 via #6710 / `d28b761ae`.)

**Fix:** bump the 6 `sbt/setup-sbt` pins on `release/v1.2` from `@508b753e… # v1.1.22` to `@6444f4c8111de4b9059c3975def104b03cfaa5f0 # v1.5.2`, in `.github/workflows/build.yml` (×3) and `.github/workflows/build-and-push-images.yml` (×3). This is a minimal targeted change rather than backporting the large github-actions group bump (#6187), which touches 15 actions across 17 files and conflicts heavily against v1.2.

**Impact:** all `release/v1.2` CI is blocked, including backport PRs #6982 and #6984.

**Follow-up:** worth auditing the remaining action pins on `release/v1.2` against the enterprise allowlist so the next run doesn't fail on a different disallowed action.

### How to reproduce?

1. Open or push to any PR targeting `release/v1.2` (e.g. #6982, #6984), or push to `release/v1.2`.
2. Observe the **Required Checks** workflow run ends in `startup_failure` with no jobs — e.g. https://github.com/apache/texera/actions/runs/30417060865
3. The run banner reports the disallowed `sbt/setup-sbt@508b753e…` action.

Started 2026-07-28; `release/v1.2` push CI was green through 2026-07-24.

### Version/Branch

1.2.0-incubating (release/v1.2)

### Commit Hash (Optional)

2bcb9aa7a (current `release/v1.2` tip at time of filing)

Contributor guide

Open the contributing guide

Research direction

Inspect the six sbt/setup-sbt references in .github/workflows/build.yml and .github/workflows/build-and-push-images.yml, comparing them with the allowlisted pin used on main. Update the six release/v1.2 pins, then verify that Required Checks starts successfully and the label-gated build/test stacks run for a release/v1.2 PR.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
85/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.