This is an automated email from the ASF dual-hosted git repository.
tballison pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tika.git
The following commit(s) were added to refs/heads/main by this push:
new 4de271f510 TIKA-4823: re-pin docker actions to approved SHAs; add ASF
allow-list check (#3232)
4de271f510 is described below
commit 4de271f510cd7b1aa2f0304371ba17a6f3051080
Author: Tim Allison <[email protected]>
AuthorDate: Thu Sep 24 06:39:13 2026 -0400
TIKA-4823: re-pin docker actions to approved SHAs; add ASF allow-list check
(#3232)
---
.github/dependabot.yml | 7 +++++
.github/workflows/asf-allowlist-check.yml | 48 +++++++++++++++++++++++++++++++
.github/workflows/docker-release.yml | 14 ++++-----
.github/workflows/docker-snapshot.yml | 16 +++++------
4 files changed, 70 insertions(+), 15 deletions(-)
diff --git a/.github/dependabot.yml b/.github/dependabot.yml
index 21a6f89f10..adf7706707 100644
--- a/.github/dependabot.yml
+++ b/.github/dependabot.yml
@@ -25,3 +25,10 @@ updates:
# Allow up to 20 open pull requests
open-pull-requests-limit: 20
+ # Actions pinned by SHA with a "# vX.Y.Z" comment get bumped too. The ASF
+ # allow-list expires a superseded version three months after approving the
+ # next one; asf-allowlist-check.yml fails a bump that is not yet approved.
+ - package-ecosystem: "github-actions"
+ directory: "/"
+ schedule:
+ interval: "weekly"
diff --git a/.github/workflows/asf-allowlist-check.yml
b/.github/workflows/asf-allowlist-check.yml
new file mode 100644
index 0000000000..cd0cca2cfb
--- /dev/null
+++ b/.github/workflows/asf-allowlist-check.yml
@@ -0,0 +1,48 @@
+#
+# Licensed to the Apache Software Foundation (ASF) under one or more
+# contributor license agreements. See the NOTICE file distributed with
+# this work for additional information regarding copyright ownership.
+# The ASF licenses this file to You under the Apache License, Version 2.0
+# (the "License"); you may not use this file except in compliance with
+# the License. You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing, software
+# distributed under the License is distributed on an "AS IS" BASIS,
+# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+# See the License for the specific language governing permissions and
+# limitations under the License.
+#
+
+# Every action a workflow uses must be on the ASF org allow-list, or the
+# workflow fails at startup with no logs (TIKA-4823, twice). This check fails
+# a PR that introduces an unapproved ref and warns 30 days before a pinned
+# version expires; the weekly run is what surfaces the expiry warning when
+# nothing under .github/ is changing.
+name: ASF allowlist check
+
+on:
+ workflow_dispatch:
+ pull_request:
+ paths:
+ - '.github/**'
+ push:
+ branches: [ main ]
+ paths:
+ - '.github/**'
+ schedule:
+ - cron: '17 6 * * 1'
+
+permissions:
+ contents: read
+
+jobs:
+ asf-allowlist-check:
+ runs-on: ubuntu-latest
+ timeout-minutes: 10
+ steps:
+ - uses: actions/checkout@v6
+ with:
+ persist-credentials: false
+ - uses:
apache/infrastructure-actions/allowlist-check@47b297bbe90f580139129bee531bd84bd95b7f5d
# allowlist-check/v1.0.4
diff --git a/.github/workflows/docker-release.yml
b/.github/workflows/docker-release.yml
index 67b14b3c76..6d2df9db6b 100644
--- a/.github/workflows/docker-release.yml
+++ b/.github/workflows/docker-release.yml
@@ -137,19 +137,19 @@ jobs:
echo "created=$(git show -s --format=%cI HEAD)" >> "$GITHUB_OUTPUT"
- name: Set up Docker Buildx
- uses:
docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
+ uses:
docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
- name: Set up QEMU for multi-arch
run: docker run --privileged --rm tonistiigi/binfmt --install all
- name: Login to Docker Hub
- uses: docker/login-action@c99871dec2022cc055c062a10cc1a1310835ceb4 #
v4.3.0
+ uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f #
v4.6.0
with:
username: ${{ secrets.DOCKERHUB_USER }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Build and push tika-server minimal
- uses:
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+ uses:
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
file: tika-server/docker-build/minimal/Dockerfile
platforms: linux/amd64,linux/arm64,linux/s390x
@@ -161,7 +161,7 @@ jobs:
tags: ${{ steps.tags.outputs.minimal }}
- name: Build and push tika-server full
- uses:
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+ uses:
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
file: tika-server/docker-build/full/Dockerfile
platforms: linux/amd64,linux/arm64,linux/s390x
@@ -221,13 +221,13 @@ jobs:
run: mvn clean install -DskipTests -B
"-Dorg.slf4j.simpleLogger.log.org.apache.maven.cli.transfer.Slf4jMavenTransferListener=warn"
- name: Set up Docker Buildx
- uses:
docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
+ uses:
docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
- name: Set up QEMU for multi-arch
run: docker run --privileged --rm tonistiigi/binfmt --install all
- name: Login to Docker Hub
- uses: docker/login-action@c99871dec2022cc055c062a10cc1a1310835ceb4 #
v4.3.0
+ uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f #
v4.6.0
with:
username: ${{ secrets.DOCKERHUB_USER }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
@@ -283,7 +283,7 @@ jobs:
cp "tika-grpc/docker-build/Dockerfile" "${OUT_DIR}/Dockerfile"
- name: Build and push tika-grpc
- uses:
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+ uses:
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: target/tika-grpc-docker
platforms: linux/amd64,linux/arm64
diff --git a/.github/workflows/docker-snapshot.yml
b/.github/workflows/docker-snapshot.yml
index 36e1654038..4e5a1f0c7b 100644
--- a/.github/workflows/docker-snapshot.yml
+++ b/.github/workflows/docker-snapshot.yml
@@ -92,13 +92,13 @@ jobs:
run: mvn clean install -DskipTests -B
"-Dorg.slf4j.simpleLogger.log.org.apache.maven.cli.transfer.Slf4jMavenTransferListener=warn"
- name: Set up Docker Buildx
- uses:
docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
+ uses:
docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
- name: Set up QEMU for multi-arch
run: docker run --privileged --rm tonistiigi/binfmt --install all
- name: Login to Docker Hub
- uses: docker/login-action@c99871dec2022cc055c062a10cc1a1310835ceb4 #
v4.3.0
+ uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f #
v4.6.0
with:
username: ${{ secrets.DOCKERHUB_USER }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
@@ -113,7 +113,7 @@ jobs:
cp "tika-server/docker-build/minimal/Dockerfile.snapshot"
"${OUT_DIR}/Dockerfile"
- name: Build tika-server minimal image for smoke test
- uses:
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+ uses:
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: target/tika-server-minimal-docker
platforms: linux/amd64
@@ -147,7 +147,7 @@ jobs:
exit 1
- name: Build and push tika-server minimal snapshot
- uses:
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+ uses:
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: target/tika-server-minimal-docker
platforms: linux/amd64,linux/arm64,linux/s390x
@@ -169,7 +169,7 @@ jobs:
cp "tika-server/docker-build/full/Dockerfile.snapshot"
"${OUT_DIR}/Dockerfile"
- name: Build tika-server full image for smoke test
- uses:
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+ uses:
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: target/tika-server-full-docker
platforms: linux/amd64
@@ -203,7 +203,7 @@ jobs:
exit 1
- name: Build and push tika-server full snapshot
- uses:
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+ uses:
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: target/tika-server-full-docker
platforms: linux/amd64,linux/arm64,linux/s390x
@@ -254,7 +254,7 @@ jobs:
cp "tika-grpc/docker-build/Dockerfile" "${OUT_DIR}/Dockerfile"
- name: Build tika-grpc image for smoke test
- uses:
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+ uses:
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: target/tika-grpc-docker
platforms: linux/amd64
@@ -290,7 +290,7 @@ jobs:
exit 1
- name: Build and push tika-grpc snapshot
- uses:
docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
+ uses:
docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: target/tika-grpc-docker
platforms: linux/amd64,linux/arm64