This is an automated email from the ASF dual-hosted git repository. rusackas pushed a commit to branch fix/security-zizmor-self-repository-hive-setup-postgres in repository https://gitbox.apache.org/repos/asf/superset.git
commit 2157bde6a987e4c51cdfc27aa41ef4ed363c3a80 Author: rusackas <[email protected]> AuthorDate: Tue Sep 8 18:22:25 2026 -0700 fix(security): suppress zizmor self-repository false positive for hive setup-postgres step The Setup Postgres step in the test-postgres-hive job references .github/actions/cached-dependencies via the workspace-relative uses: ./... syntax, which zizmor's self-repository audit flags in favor of $/.... That mechanical rewrite doesn't work here: cached-dependencies is a git submodule, and $/... resolves action files directly from the repository tree without a real, submodule-aware checkout, so it can't see past the submodule's gitlink into the actual action.yml. This mirrors the identical, already-suppressed pattern used for the sibling cached-dependencies steps in this same file and elsewhere in the repo. Resolves code-scanning alert #2679. Co-Authored-By: Claude Sonnet 5 <[email protected]> --- .github/workflows/superset-python-presto-hive.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/superset-python-presto-hive.yml b/.github/workflows/superset-python-presto-hive.yml index b077664e3c6..f034cbbeece 100644 --- a/.github/workflows/superset-python-presto-hive.yml +++ b/.github/workflows/superset-python-presto-hive.yml @@ -149,7 +149,13 @@ jobs: - name: Setup Python uses: $/.github/actions/setup-backend/ - name: Setup Postgres - uses: ./.github/actions/cached-dependencies + # cached-dependencies is a submodule (not a plain directory), and + # the $/ self-repository syntax resolves action files directly from + # the repository without performing a real (submodule-aware) + # checkout, so it can't see into a submodule's link. Keep this one + # on the workspace-relative ./ form, consistent with every other + # workflow in the repo that references this action. + uses: ./.github/actions/cached-dependencies # zizmor: ignore[self-repository] - $/ cannot resolve an action that lives in a submodule; ./ is required here with: run: setup-postgres - name: Start Celery worker
