Skip to content

fix(ci): pin docker/* actions in build.yml to ASF-approved SHAs#8852

Merged
klesh merged 1 commit intoapache:mainfrom
yamoyamoto:fix/workflow-allowlist-violation
Apr 26, 2026
Merged

fix(ci): pin docker/* actions in build.yml to ASF-approved SHAs#8852
klesh merged 1 commit intoapache:mainfrom
yamoyamoto:fix/workflow-allowlist-violation

Conversation

@yamoyamoto
Copy link
Copy Markdown
Contributor

⚠️ Pre Checklist

Please complete ALL items in this checklist, and remove before submitting

  • I have read through the Contributing Documentation.
  • I have added relevant tests.
  • I have added relevant documentation.
  • I will add labels to the PR, such as pr-type/bug-fix, pr-type/feature-development, etc.

Summary

Pin the four docker/* actions in .github/workflows/build.yml to commit SHAs from apache/infrastructure-actions/approved_patterns.yml.

Does this close any open issues?

Closes #8851

Screenshots

N/A

Other Information

N/A

Signed-off-by: yamoyamoto <yamo7yamoto@gmail.com>
@dosubot dosubot Bot added size:XS This PR changes 0-9 lines, ignoring generated files. devops Something about CI/CD (devops) pr-type/bug-fix This PR fixes a bug labels Apr 26, 2026
Copy link
Copy Markdown
Contributor

@klesh klesh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@klesh klesh merged commit 1d21f19 into apache:main Apr 26, 2026
13 checks passed
@klesh
Copy link
Copy Markdown
Contributor

klesh commented Apr 26, 2026

@yamoyamoto, would you like to become an Apache Committer for the project? I would like to nominate you if you are interested. Here is an explanation of Apache Committers: https://community.apache.org/contributors/becomingacommitter.html

Feel free to reach out to me at klesh@apache.org.

@yamoyamoto
Copy link
Copy Markdown
Contributor Author

Hi @klesh,
Thank you so much for the nomination! I am highly honored to be considered for an Apache Committer role for the DevLake project.
I will send you an email shortly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

devops Something about CI/CD (devops) pr-type/bug-fix This PR fixes a bug size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug][CI] build.yml fails with startup_failure due to non-allowlisted GitHub Actions

2 participants