This is an automated email from the ASF dual-hosted git repository. rusackas pushed a commit to branch fix/security-zizmor-self-repository-playwright-postgres in repository https://gitbox.apache.org/repos/asf/superset.git
commit ab5e2fc6d76d18835bc2d56c944c42c09e2f5d53 Author: rusackas <[email protected]> AuthorDate: Wed Sep 9 07:46:32 2026 -0700 fix(security): suppress zizmor self-repository false positive for setup-postgres step zizmor's self-repository audit flags `uses: ./.github/actions/cached-dependencies` in the "Setup postgres" step of superset-playwright.yml, suggesting the $/... self-repository syntax instead of ./... cached-dependencies is a git submodule (not a plain directory), and $/ resolves action files directly from the repository without a real, submodule-aware checkout, so it can't see into the submodule's gitlink. Converting this reference to $/ breaks the step at runtime (previously discovered and reverted for the same action elsewhere, see #43972). This keeps the ./ form and adds a scoped zizmor: ignore[self-repository] suppression with a comment, matching the pattern already used for other cached-dependencies occurrences in this workflow. Resolves code-scanning alert #2645. Co-Authored-By: Claude Sonnet 5 <[email protected]> --- .github/workflows/superset-playwright.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/superset-playwright.yml b/.github/workflows/superset-playwright.yml index 37675ca150d..e83812e30ef 100644 --- a/.github/workflows/superset-playwright.yml +++ b/.github/workflows/superset-playwright.yml @@ -111,7 +111,13 @@ jobs: - name: Setup Python uses: ./.github/actions/setup-backend/ - name: Setup postgres - uses: ./.github/actions/cached-dependencies + # cached-dependencies is a submodule (not a plain directory), and + # the $/ self-repository syntax resolves action files directly from + # the repository without performing a real (submodule-aware) + # checkout, so it can't see into a submodule's link. Keep this one + # on the workspace-relative ./ form, consistent with every other + # workflow in the repo that references this action. + uses: ./.github/actions/cached-dependencies # zizmor: ignore[self-repository] - $/ cannot resolve an action that lives in a submodule; ./ is required here with: run: setup-postgres - name: Import test data
