Hi,As mentioned in https://groups.google.com/g/quarkus-dev/c/FBplXH85mM8, we are going to restrict the GitHub Actions that can be used in the quarkusio organization.We will have a manually maintained list of vetted GitHub Actions that are authorized in the org, anything else won't work.Any addition to this list will have to be analyzed thoroughly and, in particular, we won't allow actions developed by random individuals. This is unfortunate as it's really nice to be able to consume actions but it has been used as a supply chain attack vector so we need to be extremely careful.A lot of work has been done to improve our situation compared to when I first sent the initial email, thanks a lot to everyone involved in this effort.There are still a couple of problematic repositories though:--- quarkusio/quarkus-devtools-compat ---
dcarbone/install-yq-action -> this is not needed anymore, you can just drop it
dorny/test-reporter -> not sure what it is used for and we need to discuss what to do about it, please ping me--- quarkusio/quarkus-workshop-agentic ---
peaceiris/actions-gh-pages -> we should use the standard GH stuff for publishing pages
--- quarkusio/quarkus-workshop-langchain4j ---
peaceiris/actions-gh-pages -> we should use the standard GH stuff for publishing pages
--- quarkusio/quarkus-workshops ---
actions-cool/maintain-one-comment -> see https://github.com/quarkusio/quarkusio.github.io/blob/19e855efbb6f58760fbe14326611becaecbea736/.github/workflows/preview.yml#L60-L70 or https://github.com/quarkusio/quarkusio.github.io/blob/19e855efbb6f58760fbe14326611becaecbea736/.github/workflows/preview-teardown.yml#L18-L27
dawidd6/action-download-artifact -> the standard action from GitHub should handle everything properly now, please switch to it
peaceiris/actions-gh-pages -> we should use the standard GH stuff for publishing pagesThe initial deadline was at the end of April and we are already mid-May so I will put the restrictions in place, please have a look at these projects if you're involved in them or want to help and ping me if you need help with this.Thanks.--Guillaume
--
You received this message because you are subscribed to the Google Groups "Quarkus Development mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to quarkus-dev...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/quarkus-dev/CALt0%2Bo_uNp%2BTtY90iWic8Mzxu8n6RLBcP1iYKw7aRyVtk6xNAA%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/quarkus-dev/CALeTM-%3D5nPiwJVr3w2B%2BjoFR8v%2B%2BrYtsmsLPExRKBexRTVoCmA%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/quarkus-dev/CALt0%2Bo8JmNpyUbviK1WHJkQt3cXCm_OcuAVbyOwPW7vLPH7rAw%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/quarkus-dev/CAJ7JGjY_NcEHkfkpeNC%2BUrDdhZaE%3D3_EAor%3Dp%3DTxp2ajw1cqew%40mail.gmail.com.
Hi,
Yesterday it was found “radcortez/milestone-release-action@main” and “radcortez/project-metadata-action@main”
Was missing and made quarkus-agent-mcp build fail (see https://quarkusio.zulipchat.com/#narrow/channel/187038-dev/topic/Quarkiverse.20Prepare.20Release.20fails/with/595067663)
Those two actions now got moved to smallrye org.
I added radcortez actions to the list temporarily to unblock the builds but this morning they are not there.
Two questions:
smallrye/* or we add the explicit listed ones to the list?/max
To view this discussion visit https://groups.google.com/d/msgid/quarkus-dev/CALt0%2Bo8oOV%2ByhnmWbu3_RCH6eDnuAOonyg%3D4Sw-b9DehVnCqaQ%40mail.gmail.com.