This is an automated email from the ASF dual-hosted git repository. rusackas pushed a commit to branch fix/security-zizmor-self-repository-integrationtest-celery in repository https://gitbox.apache.org/repos/asf/superset.git
commit 67ab35ce200b2cb0cb30a691dc3c90cb01d7c2f9 Author: rusackas <[email protected]> AuthorDate: Tue Sep 8 05:07:46 2026 -0700 fix(security): suppress zizmor self-repository false positive for sqlite celery worker step The `Start Celery worker` step in the `test-sqlite` job of superset-python-integrationtest.yml references .github/actions/cached-dependencies via the workspace-relative `uses: ./...` syntax, which zizmor's self-repository audit flags in favor of `uses: $/...`. That mechanical fix doesn't apply here: cached-dependencies is a git submodule, and $/... resolves action files directly from the repository tree without a real, submodule-aware checkout, so it can't see past the submodule's gitlink into the actual action.yml. This adds the same documented suppression comment already used for this action elsewhere in the repo (e.g. superset-translations.yml, superset-python-presto-hive.yml). Resolves code-scanning alert #2661. Co-Authored-By: Claude Sonnet 5 <[email protected]> --- .github/workflows/superset-python-integrationtest.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/superset-python-integrationtest.yml b/.github/workflows/superset-python-integrationtest.yml index 28e5c34567a..ca40f634c65 100644 --- a/.github/workflows/superset-python-integrationtest.yml +++ b/.github/workflows/superset-python-integrationtest.yml @@ -218,7 +218,13 @@ jobs: # sqlite needs this working directory mkdir ${{ github.workspace }}/.temp - name: Start Celery worker - uses: ./.github/actions/cached-dependencies + # cached-dependencies is a git submodule (not a plain directory), and + # the $/ self-repository syntax resolves action files directly from + # the repository without performing a real (submodule-aware) + # checkout, so it can't see into a submodule's gitlink. Keep this one + # on the workspace-relative ./ form, consistent with every other + # workflow in the repo that references this action. + uses: ./.github/actions/cached-dependencies # zizmor: ignore[self-repository] - $/ cannot resolve an action that lives in a submodule; ./ is required here with: run: celery-worker - name: Python integration tests (SQLite)
