Avoid third-party actions in fork go-tests workflow#265
Merged
Conversation
GitHub selected-actions blocks workflows at startup when a referenced action is not allowlisted, even if the step would be skipped at runtime. Replace changed-files and golangci-lint action usage with shell/go install steps, and remove Enterprise/Slack-only action references from the fork test path.
The fork go-tests workflow now runs far enough to surface an existing gofmt drift in api/acl.go. Apply gofmt so the CI check can pass without mixing this formatting fix into the workflow commit.
mbrulatout
approved these changes
Jul 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Why
criteo-forks/consul allows only selected GitHub Actions. GitHub validates referenced actions before job conditions are evaluated, so unused Vault/Slack references and third-party helper actions can make go-tests fail at workflow startup before any test job is created.
After the workflow started creating jobs, CI also reported api/acl.go as not gofmt-formatted. That formatting issue is unrelated to the workflow commit, so it is kept as a separate commit in this PR.