This is an automated email from the ASF dual-hosted git repository.

rusackas pushed a commit to branch 
fix/security-zizmor-playwright-npm-deps-self-repository
in repository https://gitbox.apache.org/repos/asf/superset.git

commit ef4b63e3ec34335b0faf53ed292b390aa819a47e
Author: rusackas <[email protected]>
AuthorDate: Wed Sep 9 04:42:31 2026 -0700

    fix(security): suppress zizmor self-repository false positive for npm 
install step
    
    The `Install npm dependencies` step in superset-playwright.yml references
    `.github/actions/cached-dependencies` via the workspace-relative `uses: 
./...`
    syntax, which zizmor's self-repository audit flags in favor of `uses: 
$/...`.
    
    The mechanical rewrite doesn't apply here: cached-dependencies is a git
    submodule (see .gitmodules), and $/... resolves action files directly from
    the repository tree without a real, submodule-aware checkout, so it can't
    see past the submodule's gitlink into the actual action.yml. This mirrors
    the same documented false-positive pattern already used for sibling
    cached-dependencies steps in this file (e.g. #44045, #44064).
    
    Resolves code-scanning alert #2647
    
    Co-Authored-By: Claude Sonnet 5 <[email protected]>
---
 .github/workflows/superset-playwright.yml | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/.github/workflows/superset-playwright.yml 
b/.github/workflows/superset-playwright.yml
index 37675ca150d..1046cf48ba0 100644
--- a/.github/workflows/superset-playwright.yml
+++ b/.github/workflows/superset-playwright.yml
@@ -125,7 +125,13 @@ jobs:
           cache: "npm"
           cache-dependency-path: "superset-frontend/package-lock.json"
       - name: Install npm dependencies
-        uses: ./.github/actions/cached-dependencies
+        # cached-dependencies is a submodule (not a plain directory), and
+        # the $/ self-repository syntax resolves action files directly from
+        # the repository without performing a real (submodule-aware)
+        # checkout, so it can't see into a submodule's link. Keep this one
+        # on the workspace-relative ./ form, consistent with every other
+        # workflow in the repo that references this action.
+        uses: ./.github/actions/cached-dependencies # zizmor: 
ignore[self-repository] - $/ cannot resolve an action that lives in a 
submodule; ./ is required here
         with:
           run: npm-install
       - name: Build javascript packages

Reply via email to