github-actions[bot] closed pull request #15315: updatted github action by
change version tag to sha hashes
URL: https://github.com/apache/datafusion/pull/15315
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above
github-actions[bot] commented on PR #15315:
URL: https://github.com/apache/datafusion/pull/15315#issuecomment-2978700211
Thank you for your contribution. Unfortunately, this pull request is stale
because it has been open 60 days with no activity. Please remove the stale
label or comment or
geoffreyclaude commented on code in PR #15315:
URL: https://github.com/apache/datafusion/pull/15315#discussion_r2049224450
##
.github/actions/setup-rust-runtime/action.yaml:
##
@@ -16,23 +16,22 @@
# under the License.
name: Setup Rust Runtime
-description: 'Setup Rust Runtim
Jiashu-Hu commented on PR #15315:
URL: https://github.com/apache/datafusion/pull/15315#issuecomment-2741526839
> Well that is unfortunate. I wonder if the apache regex is correct - the
one in the error message is not, should be
`.*\/.*@[a-f0-9][a-f0-9][a-f0-9][a-f0-9][a-f0-9][a-f0-9][a-f0-9
Jiashu-Hu opened a new pull request, #15315:
URL: https://github.com/apache/datafusion/pull/15315
## Which issue does this PR close?
- Closes #[15298](https://github.com/apache/datafusion/issues/15298).
## Rationale for this change
This update strengthens the security
Omega359 commented on PR #15315:
URL: https://github.com/apache/datafusion/pull/15315#issuecomment-2743064531
I think a committer should bring this up with apache infra structure folks
as I cannot see a way to follow the directions in the apache github actions
policy here without just yanki
Omega359 commented on PR #15315:
URL: https://github.com/apache/datafusion/pull/15315#issuecomment-2741203586
Well that is unfortunate. I wonder if the apache regex is correct - the one
in the error message is not, should be
'.*\/.*@[a-f0-9][a-f0-9][a-f0-9][a-f0-9][a-f0-9][a-f0-9][a-f0-9]+'
Jiashu-Hu commented on PR #15315:
URL: https://github.com/apache/datafusion/pull/15315#issuecomment-2738308374
hi @alamb, seems there's some regulation to block SHA HASHE value as version
tag in apache community
https://github.com/user-attachments/assets/ec3357ac-750c-4010-ae11-6455c54294