This is an automated email from the ASF dual-hosted git repository.

rusackas pushed a commit to branch 
fix/security-zizmor-self-repository-playwright-postgres
in repository https://gitbox.apache.org/repos/asf/superset.git

commit ab5e2fc6d76d18835bc2d56c944c42c09e2f5d53
Author: rusackas <[email protected]>
AuthorDate: Wed Sep 9 07:46:32 2026 -0700

    fix(security): suppress zizmor self-repository false positive for 
setup-postgres step
    
    zizmor's self-repository audit flags `uses: 
./.github/actions/cached-dependencies`
    in the "Setup postgres" step of superset-playwright.yml, suggesting the
    $/... self-repository syntax instead of ./...
    
    cached-dependencies is a git submodule (not a plain directory), and $/
    resolves action files directly from the repository without a real,
    submodule-aware checkout, so it can't see into the submodule's gitlink.
    Converting this reference to $/ breaks the step at runtime (previously
    discovered and reverted for the same action elsewhere, see #43972). This
    keeps the ./ form and adds a scoped zizmor: ignore[self-repository]
    suppression with a comment, matching the pattern already used for other
    cached-dependencies occurrences in this workflow.
    
    Resolves code-scanning alert #2645.
    
    Co-Authored-By: Claude Sonnet 5 <[email protected]>
---
 .github/workflows/superset-playwright.yml | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/.github/workflows/superset-playwright.yml 
b/.github/workflows/superset-playwright.yml
index 37675ca150d..e83812e30ef 100644
--- a/.github/workflows/superset-playwright.yml
+++ b/.github/workflows/superset-playwright.yml
@@ -111,7 +111,13 @@ jobs:
       - name: Setup Python
         uses: ./.github/actions/setup-backend/
       - name: Setup postgres
-        uses: ./.github/actions/cached-dependencies
+        # cached-dependencies is a submodule (not a plain directory), and
+        # the $/ self-repository syntax resolves action files directly from
+        # the repository without performing a real (submodule-aware)
+        # checkout, so it can't see into a submodule's link. Keep this one
+        # on the workspace-relative ./ form, consistent with every other
+        # workflow in the repo that references this action.
+        uses: ./.github/actions/cached-dependencies # zizmor: 
ignore[self-repository] - $/ cannot resolve an action that lives in a 
submodule; ./ is required here
         with:
           run: setup-postgres
       - name: Import test data

Reply via email to