release/v1.2 Required Checks fails at startup: sbt/setup-sbt pin not on ASF actions allowlist
- Dominant language
- Scala
- Stars
- 314
- Forks
- 187
- Avg merge
- 1d 21h
- Merged PRs (30d)
- 214
Description
### What happened?
All CI on `release/v1.2` is broken. The **Required Checks** workflow ends in `startup_failure` and never runs, so no build/test checks appear on v1.2 PRs and the label-based stack selection (`precheck`) never executes — which is why CI appears to "not trigger by label" on v1.2 PRs.
Root cause: `release/v1.2` pins `sbt/setup-sbt` at a SHA that is **not on the ASF GitHub Enterprise actions allowlist**:
```
sbt/setup-sbt@508b753e53cb6095967669e0911487d2b9bc9f41 # v1.1.22
```
GitHub rejects the run while building the workflow graph:
> The action `sbt/setup-sbt@508b753e53cb6095967669e0911487d2b9bc9f41` is not allowed in apache/texera because all actions must be from a repository owned by your enterprise, created by GitHub, or match one of the patterns: …
**Expected:** Required Checks starts and runs the label-gated build/test stacks on `release/v1.2`, same as on `main`.
`main` already uses the allowlisted version and its Required Checks is green:
```
sbt/setup-sbt@6444f4c8111de4b9059c3975def104b03cfaa5f0 # v1.5.2
```
(`main` reached v1.5.2 via #6710 / `d28b761ae`.)
**Fix:** bump the 6 `sbt/setup-sbt` pins on `release/v1.2` from `@508b753e… # v1.1.22` to `@6444f4c8111de4b9059c3975def104b03cfaa5f0 # v1.5.2`, in `.github/workflows/build.yml` (×3) and `.github/workflows/build-and-push-images.yml` (×3). This is a minimal targeted change rather than backporting the large github-actions group bump (#6187), which touches 15 actions across 17 files and conflicts heavily against v1.2.
**Impact:** all `release/v1.2` CI is blocked, including backport PRs #6982 and #6984.
**Follow-up:** worth auditing the remaining action pins on `release/v1.2` against the enterprise allowlist so the next run doesn't fail on a different disallowed action.
### How to reproduce?
1. Open or push to any PR targeting `release/v1.2` (e.g. #6982, #6984), or push to `release/v1.2`.
2. Observe the **Required Checks** workflow run ends in `startup_failure` with no jobs — e.g. https://github.com/apache/texera/actions/runs/30417060865
3. The run banner reports the disallowed `sbt/setup-sbt@508b753e…` action.
Started 2026-07-28; `release/v1.2` push CI was green through 2026-07-24.
### Version/Branch
1.2.0-incubating (release/v1.2)
### Commit Hash (Optional)
2bcb9aa7a (current `release/v1.2` tip at time of filing)
Contributor guide
Research direction
Inspect the six sbt/setup-sbt references in .github/workflows/build.yml and .github/workflows/build-and-push-images.yml, comparing them with the allowlisted pin used on main. Update the six release/v1.2 pins, then verify that Required Checks starts successfully and the label-gated build/test stacks run for a release/v1.2 PR.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 85/100