This is an automated email from the ASF dual-hosted git repository.

rusackas pushed a commit to branch 
fix/security/self-repository-mysql-setup-backend
in repository https://gitbox.apache.org/repos/asf/superset.git

commit b59242172dd4cc658e1aa67cb7f9367e678b2366
Author: rusackas <[email protected]>
AuthorDate: Wed Sep 9 01:39:00 2026 -0700

    fix(security): use self-repository syntax for setup-backend in mysql job
    
    Resolves code-scanning alert #2653. The mysql job's "Setup Python" step
    referenced the setup-backend action via the workspace-relative ./ form,
    which zizmor flags because it isn't eligible for GitHub's "fully pinned"
    policy enforcement and can be influenced by files checked out earlier in
    the run. setup-backend is a plain directory (not a submodule), so it can
    safely use the $/ self-repository form, matching the fix already applied
    to the equivalent step in the postgres and sqlite jobs.
    
    Co-Authored-By: Claude Sonnet 5 <[email protected]>
---
 .github/workflows/superset-python-integrationtest.yml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/.github/workflows/superset-python-integrationtest.yml 
b/.github/workflows/superset-python-integrationtest.yml
index 5f8a5488a23..e07046006c1 100644
--- a/.github/workflows/superset-python-integrationtest.yml
+++ b/.github/workflows/superset-python-integrationtest.yml
@@ -75,7 +75,7 @@ jobs:
           persist-credentials: false
           submodules: recursive
       - name: Setup Python
-        uses: ./.github/actions/setup-backend/
+        uses: $/.github/actions/setup-backend/
       - name: Setup MySQL
         uses: ./.github/actions/cached-dependencies
         with:

Reply via email to