This is an automated email from the ASF dual-hosted git repository. rusackas pushed a commit to branch fix/security-zizmor-playwright-mobile-self-repository in repository https://gitbox.apache.org/repos/asf/superset.git
commit c41984a31c31ed3bfc988a08bb63562720c14f2d Author: rusackas <[email protected]> AuthorDate: Tue Sep 8 22:19:39 2026 -0700 fix(security): suppress zizmor self-repository false positive for playwright mobile step The Run Playwright (Mobile Tests) step in superset-playwright.yml references .github/actions/cached-dependencies via the workspace-relative uses: ./... syntax, which zizmor's self-repository audit flags in favor of the $/... syntax. The mechanical rewrite doesn't apply here: cached-dependencies is a git submodule (see .gitmodules), and $/... resolves action files directly from the repository tree without a real, submodule-aware checkout, so it can't see past the submodule's gitlink into the actual action.yml. This mirrors the same documented false-positive pattern already used for other cached-dependencies steps across the repo (e.g. superset-python-presto-hive.yml, superset-python-integrationtest.yml). Resolves code-scanning alert #2651 Co-Authored-By: Claude Sonnet 5 <[email protected]> --- .github/workflows/superset-playwright.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/superset-playwright.yml b/.github/workflows/superset-playwright.yml index 37675ca150d..6e1bd43c7c7 100644 --- a/.github/workflows/superset-playwright.yml +++ b/.github/workflows/superset-playwright.yml @@ -143,7 +143,13 @@ jobs: with: run: playwright-run "${{ matrix.app_root }}" experimental/ - name: Run Playwright (Mobile Tests) - uses: ./.github/actions/cached-dependencies + # cached-dependencies is a submodule (not a plain directory), and + # the $/ self-repository syntax resolves action files directly from + # the repository without performing a real (submodule-aware) + # checkout, so it can't see into a submodule's link. Keep this one + # on the workspace-relative ./ form, consistent with every other + # workflow in the repo that references this action. + uses: ./.github/actions/cached-dependencies # zizmor: ignore[self-repository] - $/ cannot resolve an action that lives in a submodule; ./ is required here env: NODE_OPTIONS: "--max-old-space-size=4096" # Scoped to this step: setting feature flags at the job level would
