This is an automated email from the ASF dual-hosted git repository.

rusackas pushed a commit to branch 
fix/security-self-repository-integrationtest-change-detector
in repository https://gitbox.apache.org/repos/asf/superset.git

commit e80f693ff6b079c626cb37e7c76bcfa095bd6fe2
Author: rusackas <[email protected]>
AuthorDate: Wed Sep 9 01:37:47 2026 -0700

    fix(security): use self-repository syntax for change-detector in 
integration tests
    
    The `changes` job in superset-python-integrationtest.yml referenced the
    local `change-detector` composite action with the workspace-relative
    `uses: ./...` form, which zizmor's self-repository audit flags because
    it resolves against runtime filesystem state rather than a pinned ref.
    Switch to GitHub's dedicated `$/` self-repository syntax, matching the
    fix already applied to the equivalent job in other workflows.
    
    Resolves code-scanning alert #2652.
    
    Co-Authored-By: Claude Sonnet 5 <[email protected]>
---
 .github/workflows/superset-python-integrationtest.yml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/.github/workflows/superset-python-integrationtest.yml 
b/.github/workflows/superset-python-integrationtest.yml
index 5f8a5488a23..f686f92f06f 100644
--- a/.github/workflows/superset-python-integrationtest.yml
+++ b/.github/workflows/superset-python-integrationtest.yml
@@ -34,7 +34,7 @@ jobs:
           persist-credentials: false
       - name: Check for file changes
         id: check
-        uses: ./.github/actions/change-detector/
+        uses: $/.github/actions/change-detector/
         with:
           token: ${{ secrets.GITHUB_TOKEN }}
 

Reply via email to