)]}'
{
  "commit": "c6b91a0eaef16d427268e9806d5df65949e2a9bf",
  "tree": "fe524d66585ac305a27c421ed999cfa9226243a5",
  "parents": [
    "d49fd41d1d0c8856b7281974d626d93e9c2b1202"
  ],
  "author": {
    "name": "吴晟 Wu Sheng",
    "email": "wu.sheng@foxmail.com",
    "time": "Sat Aug 01 22:31:50 2026 +0800"
  },
  "committer": {
    "name": "GitHub",
    "email": "noreply@github.com",
    "time": "Sat Aug 01 22:31:50 2026 +0800"
  },
  "message": "fix(ci): pin docker/* actions to ASF-approved SHAs in publish-docker (#66)\n\nThe workflow referenced docker/login-action, docker/setup-qemu-action and\ndocker/setup-buildx-action by floating tag. The ASF GitHub Actions\nallow-list only approves specific commit SHAs for third-party actions, so\nthe workflow is rejected at startup: the run for #65 ended in\nstartup_failure and no image was published for that commit.\n\nSince publish-docker only runs on push-to-master, the rejection never\nsurfaces in PR CI — it is only visible after a merge.\n\nPin all three to the approved SHAs already used across the sibling ASF\nSkyWalking repositories (verified against apache/infrastructure-actions\napproved_patterns.yml):\n  - docker/login-action@650006c6...       # v4.2.0\n  - docker/setup-qemu-action@06116385...  # v4.1.0\n  - docker/setup-buildx-action@d7f5e7f5... # v4.1.0\n\nMerging this triggers a push-to-master build, which publishes an image\ncontaining the #65 concurrency fix.",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "54c2859c7c9f3029ff83a218f21ff1e6a1a11686",
      "old_mode": 33188,
      "old_path": ".github/workflows/publish-docker.yaml",
      "new_id": "82051596bc8ee12b1c86baeb03a2bbceca15b939",
      "new_mode": 33188,
      "new_path": ".github/workflows/publish-docker.yaml"
    }
  ]
}
