This is an automated email from the ASF dual-hosted git repository. rusackas pushed a commit to branch fix/security/self-repository-mysql-setup-backend in repository https://gitbox.apache.org/repos/asf/superset.git
commit b59242172dd4cc658e1aa67cb7f9367e678b2366 Author: rusackas <[email protected]> AuthorDate: Wed Sep 9 01:39:00 2026 -0700 fix(security): use self-repository syntax for setup-backend in mysql job Resolves code-scanning alert #2653. The mysql job's "Setup Python" step referenced the setup-backend action via the workspace-relative ./ form, which zizmor flags because it isn't eligible for GitHub's "fully pinned" policy enforcement and can be influenced by files checked out earlier in the run. setup-backend is a plain directory (not a submodule), so it can safely use the $/ self-repository form, matching the fix already applied to the equivalent step in the postgres and sqlite jobs. Co-Authored-By: Claude Sonnet 5 <[email protected]> --- .github/workflows/superset-python-integrationtest.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/superset-python-integrationtest.yml b/.github/workflows/superset-python-integrationtest.yml index 5f8a5488a23..e07046006c1 100644 --- a/.github/workflows/superset-python-integrationtest.yml +++ b/.github/workflows/superset-python-integrationtest.yml @@ -75,7 +75,7 @@ jobs: persist-credentials: false submodules: recursive - name: Setup Python - uses: ./.github/actions/setup-backend/ + uses: $/.github/actions/setup-backend/ - name: Setup MySQL uses: ./.github/actions/cached-dependencies with:
