This is an automated email from the ASF dual-hosted git repository.

rusackas pushed a commit to branch 
fix/security-zizmor-self-repository-integrationtest-celery
in repository https://gitbox.apache.org/repos/asf/superset.git

commit 67ab35ce200b2cb0cb30a691dc3c90cb01d7c2f9
Author: rusackas <[email protected]>
AuthorDate: Tue Sep 8 05:07:46 2026 -0700

    fix(security): suppress zizmor self-repository false positive for sqlite 
celery worker step
    
    The `Start Celery worker` step in the `test-sqlite` job of
    superset-python-integrationtest.yml references 
.github/actions/cached-dependencies
    via the workspace-relative `uses: ./...` syntax, which zizmor's
    self-repository audit flags in favor of `uses: $/...`. That mechanical fix
    doesn't apply here: cached-dependencies is a git submodule, and $/...
    resolves action files directly from the repository tree without a real,
    submodule-aware checkout, so it can't see past the submodule's gitlink into
    the actual action.yml. This adds the same documented suppression comment
    already used for this action elsewhere in the repo (e.g.
    superset-translations.yml, superset-python-presto-hive.yml).
    
    Resolves code-scanning alert #2661.
    
    Co-Authored-By: Claude Sonnet 5 <[email protected]>
---
 .github/workflows/superset-python-integrationtest.yml | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/.github/workflows/superset-python-integrationtest.yml 
b/.github/workflows/superset-python-integrationtest.yml
index 28e5c34567a..ca40f634c65 100644
--- a/.github/workflows/superset-python-integrationtest.yml
+++ b/.github/workflows/superset-python-integrationtest.yml
@@ -218,7 +218,13 @@ jobs:
             # sqlite needs this working directory
             mkdir ${{ github.workspace }}/.temp
       - name: Start Celery worker
-        uses: ./.github/actions/cached-dependencies
+        # cached-dependencies is a git submodule (not a plain directory), and
+        # the $/ self-repository syntax resolves action files directly from
+        # the repository without performing a real (submodule-aware)
+        # checkout, so it can't see into a submodule's gitlink. Keep this one
+        # on the workspace-relative ./ form, consistent with every other
+        # workflow in the repo that references this action.
+        uses: ./.github/actions/cached-dependencies # zizmor: 
ignore[self-repository] - $/ cannot resolve an action that lives in a 
submodule; ./ is required here
         with:
           run: celery-worker
       - name: Python integration tests (SQLite)

Reply via email to