Skip to content

CI: all PRs targeting scylla-4.x fail due to unpinned actions/checkout@v4 in call_jira_sync.yml #911

Description

@nikagra

Symptom

Every PR targeting scylla-4.x produces the following CI failure:

Error: The action actions/checkout@v4 is not allowed in scylladb/java-driver
because all actions must be pinned to a full-length commit SHA.

Root cause

.github/workflows/call_jira_sync.yml delegates to a reusable workflow in an external repository:

uses: scylladb/github-automation/.github/workflows/main_pr_events_jira_sync.yml@7b9848eb304fd3af1e757fe3c3c1ed497515f0fc

Inside that reusable workflow, actions/checkout is referenced without a full commit SHA:

uses: actions/checkout@v4   # ← violates org allowed-actions policy

GitHub applies the scylladb org policy (all actions must be pinned to a full 40-character commit SHA) even to actions used inside externally-called reusable workflows. This causes every PR event that triggers call_jira_sync.yml to fail.

Scope

  • Affected: scylla-4.x (the only branch carrying call_jira_sync.yml)
  • Not affected: scylla-3.x (no call_jira_sync.yml there)

Fix

Two-part fix:

  1. scylladb/github-automation — pin actions/checkout@v4 to its full commit SHA (34e114876b0b11c390a56381ad16ebd13914f8d5, i.e. v4.3.1) in main_pr_events_jira_sync.yml
  2. scylladb/java-driver (scylla-4.x) — update the pinned commit reference in call_jira_sync.yml to the commit that contains the above fix

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions