This is an automated email from the ASF dual-hosted git repository.

rusackas pushed a commit to branch 
fix/security-zizmor-playwright-mobile-self-repository
in repository https://gitbox.apache.org/repos/asf/superset.git

commit c41984a31c31ed3bfc988a08bb63562720c14f2d
Author: rusackas <[email protected]>
AuthorDate: Tue Sep 8 22:19:39 2026 -0700

    fix(security): suppress zizmor self-repository false positive for 
playwright mobile step
    
    The Run Playwright (Mobile Tests) step in superset-playwright.yml
    references .github/actions/cached-dependencies via the workspace-relative
    uses: ./... syntax, which zizmor's self-repository audit flags in favor of
    the $/... syntax. The mechanical rewrite doesn't apply here:
    cached-dependencies is a git submodule (see .gitmodules), and $/...
    resolves action files directly from the repository tree without a real,
    submodule-aware checkout, so it can't see past the submodule's gitlink
    into the actual action.yml.
    
    This mirrors the same documented false-positive pattern already used for
    other cached-dependencies steps across the repo (e.g.
    superset-python-presto-hive.yml, superset-python-integrationtest.yml).
    
    Resolves code-scanning alert #2651
    
    Co-Authored-By: Claude Sonnet 5 <[email protected]>
---
 .github/workflows/superset-playwright.yml | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/.github/workflows/superset-playwright.yml 
b/.github/workflows/superset-playwright.yml
index 37675ca150d..6e1bd43c7c7 100644
--- a/.github/workflows/superset-playwright.yml
+++ b/.github/workflows/superset-playwright.yml
@@ -143,7 +143,13 @@ jobs:
         with:
           run: playwright-run "${{ matrix.app_root }}" experimental/
       - name: Run Playwright (Mobile Tests)
-        uses: ./.github/actions/cached-dependencies
+        # cached-dependencies is a submodule (not a plain directory), and
+        # the $/ self-repository syntax resolves action files directly from
+        # the repository without performing a real (submodule-aware)
+        # checkout, so it can't see into a submodule's link. Keep this one
+        # on the workspace-relative ./ form, consistent with every other
+        # workflow in the repo that references this action.
+        uses: ./.github/actions/cached-dependencies # zizmor: 
ignore[self-repository] - $/ cannot resolve an action that lives in a 
submodule; ./ is required here
         env:
           NODE_OPTIONS: "--max-old-space-size=4096"
           # Scoped to this step: setting feature flags at the job level would

Reply via email to