[
https://issues.apache.org/jira/browse/FLINK-39573?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
ASF GitHub Bot updated FLINK-39573:
-----------------------------------
Labels: pull-request-available (was: )
> Build documentation CI workflow fails with startup_failure due to
> burnett01/rsync-deployments action not allowed
> ----------------------------------------------------------------------------------------------------------------
>
> Key: FLINK-39573
> URL: https://issues.apache.org/jira/browse/FLINK-39573
> Project: Flink
> Issue Type: Bug
> Components: Flink CDC
> Reporter: yuan
> Priority: Major
> Labels: pull-request-available
>
> h3.
> h3. Problem
> The "Build documentation" GitHub Actions workflow in apache/flink-cdc has
> been failing with *startup_failure* since April 18, 2026. This means the
> documentation is not being built and published to the Apache Nightlies
> website.
> The error message from GitHub Actions:
> {code:java}
> The action
> burnett01/rsync-deployments@0dc935cdecc5f5e571865e60d2a6cdc673704823 is not
> allowed in apache/flink-cdc because all actions must be from a repository
> owned by your enterprise, created by GitHub, or match one of the patterns in
> the allowed list.
> {code}
> h3. Root Cause
> The workflow file
> [.github/workflows/build_docs.yml|https://github.com/apache/flink-cdc/blob/master/.github/workflows/build_docs.yml]
> uses
> {{{}burnett01/rsync-deployments@0dc935cdecc5f5e571865e60d2a6cdc673704823{}}},
> which is pinned to *v5.2* (from 2022). This version is *not* in the Apache
> Infra approved actions list
> ([actions.yml|https://github.com/apache/infrastructure-actions/blob/main/actions.yml]).
> The Apache approved list only includes these versions of
> burnett01/rsync-deployments:
> * {{7659d600d8bdd035bb5cdfba1d4bd0dd4a307ca6}} (v8.0.3)
> * {{dc0d5d44c4728aad3f02154a87309809e62a960f}} (v8.0.4)
> h3. Proposed Fix
> *Option 1 (Simple):* Upgrade the action to the approved v8.0.4 SHA:
> {code:yaml}
> # Before
> uses: burnett01/rsync-deployments@0dc935cdecc5f5e571865e60d2a6cdc673704823
> # After
> uses: burnett01/rsync-deployments@dc0d5d44c4728aad3f02154a87309809e62a960f
> {code}
> *Option 2 (Robust):* Create a local composite action to replace the
> third-party action entirely, as was done in FLINK-38448 for
> flink-kubernetes-operator. See [the fix
> PR|https://github.com/apache/flink-kubernetes-operator/commit/3e3cb584] for
> reference.
> h3. References
> * CI failure history: [Build documentation workflow
> runs|https://github.com/apache/flink-cdc/actions/workflows/build_docs.yml] -
> all runs since April 18 show startup_failure
> * Similar issue: FLINK-38448 - Same problem fixed in
> flink-kubernetes-operator
> * Apache Actions policy:
> [https://infra.apache.org/github-actions-policy.html]
> * Apache approved actions list:
> [https://github.com/apache/infrastructure-actions/blob/main/actions.yml]
--
This message was sent by Atlassian Jira
(v8.20.10#820010)