This is an automated email from the ASF dual-hosted git repository.

rusackas pushed a commit to branch 
fix/security-self-repository-integrationtest-mysql-celery
in repository https://gitbox.apache.org/repos/asf/superset.git

commit 3e5ab3db81b45c93563d302afc542649927e5a1f
Author: rusackas <[email protected]>
AuthorDate: Tue Sep 8 18:47:30 2026 -0700

    fix(security): suppress zizmor self-repository false positive for mysql 
celery worker step
    
    cached-dependencies is a git submodule, not a plain directory, so the
    $/ self-repository syntax can't resolve into it. Keep the
    workspace-relative ./ form with a scoped zizmor suppression, matching
    the pattern already used for the other cached-dependencies references
    in this workflow.
    
    Resolves code-scanning alert #2655
    
    Co-Authored-By: Claude Sonnet 5 <[email protected]>
---
 .github/workflows/superset-python-integrationtest.yml | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/.github/workflows/superset-python-integrationtest.yml 
b/.github/workflows/superset-python-integrationtest.yml
index 5a9cc6c3863..f549afe3ce5 100644
--- a/.github/workflows/superset-python-integrationtest.yml
+++ b/.github/workflows/superset-python-integrationtest.yml
@@ -81,7 +81,13 @@ jobs:
         with:
           run: setup-mysql
       - name: Start Celery worker
-        uses: ./.github/actions/cached-dependencies
+        # cached-dependencies is a git submodule (not a plain directory), and
+        # the $/ self-repository syntax resolves action files directly from
+        # the repository without performing a real (submodule-aware)
+        # checkout, so it can't see into a submodule's gitlink. Keep this one
+        # on the workspace-relative ./ form, consistent with every other
+        # workflow in the repo that references this action.
+        uses: ./.github/actions/cached-dependencies # zizmor: 
ignore[self-repository] - $/ cannot resolve an action that lives in a 
submodule; ./ is required here
         with:
           run: celery-worker
       - name: Python integration tests (MySQL)

Reply via email to