This is an automated email from the ASF dual-hosted git repository. rusackas pushed a commit to branch fix/security-zizmor-self-repository-mysql-setup in repository https://gitbox.apache.org/repos/asf/superset.git
commit 98136bc0cc134e81c0a783ecfb265c8e5d8ae93e Author: rusackas <[email protected]> AuthorDate: Wed Sep 9 01:40:46 2026 -0700 fix(security): suppress zizmor self-repository false positive for mysql setup step cached-dependencies is a git submodule, so GitHub's $/ self-repository uses: syntax can't resolve it (no submodule-aware checkout). Keep the workspace-relative ./ form here with a scoped zizmor suppression, matching the pattern already used for this action elsewhere in the workflow. Resolves code-scanning alert #2654 Co-Authored-By: Claude Sonnet 5 <[email protected]> --- .github/workflows/superset-python-integrationtest.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/superset-python-integrationtest.yml b/.github/workflows/superset-python-integrationtest.yml index 5f8a5488a23..a85df757fa1 100644 --- a/.github/workflows/superset-python-integrationtest.yml +++ b/.github/workflows/superset-python-integrationtest.yml @@ -77,7 +77,13 @@ jobs: - name: Setup Python uses: ./.github/actions/setup-backend/ - name: Setup MySQL - uses: ./.github/actions/cached-dependencies + # cached-dependencies is a git submodule (not a plain directory), and + # the $/ self-repository syntax resolves action files directly from + # the repository without performing a real (submodule-aware) + # checkout, so it can't see into a submodule's gitlink. Keep this one + # on the workspace-relative ./ form, consistent with every other + # workflow in the repo that references this action. + uses: ./.github/actions/cached-dependencies # zizmor: ignore[self-repository] - $/ cannot resolve an action that lives in a submodule; ./ is required here with: run: setup-mysql - name: Start Celery worker
