This is an automated email from the ASF dual-hosted git repository.

rusackas pushed a commit to branch 
fix/security-self-repository-integrationtest-setup-postgres
in repository https://gitbox.apache.org/repos/asf/superset.git

commit 3c3c92e96b3c0292ae7d5492ad26f83f14074bc5
Author: rusackas <[email protected]>
AuthorDate: Tue Sep 8 18:25:50 2026 -0700

    fix(security): use self-repository syntax for setup-backend in postgres job
    
    zizmor's self-repository audit flags uses: ./.github/actions/setup-backend/
    in the test-postgres job in favor of GitHub's dedicated uses: $/... syntax.
    This mirrors the mechanical fix already applied to the analogous
    setup-backend references in this same workflow (test-sqlite, #44018) and in
    superset-python-presto-hive.yml (#43975), now that the ASF allowlist check
    has been bumped to recognize $/ refs (#44014).
    
    Resolves code-scanning alert #2656.
    
    Co-Authored-By: Claude Sonnet 5 <[email protected]>
---
 .github/workflows/superset-python-integrationtest.yml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/.github/workflows/superset-python-integrationtest.yml 
b/.github/workflows/superset-python-integrationtest.yml
index 5a9cc6c3863..9f06dc08c63 100644
--- a/.github/workflows/superset-python-integrationtest.yml
+++ b/.github/workflows/superset-python-integrationtest.yml
@@ -160,7 +160,7 @@ jobs:
           persist-credentials: false
           submodules: recursive
       - name: Setup Python
-        uses: ./.github/actions/setup-backend/
+        uses: $/.github/actions/setup-backend/
         with:
           python-version: ${{ matrix.python-version }}
       - name: Setup Postgres

Reply via email to