This is an automated email from the ASF dual-hosted git repository.
hainenber pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/superset.git
The following commit(s) were added to refs/heads/master by this push:
new ce700f389c7 fix(security): suppress zizmor self-repository false
positive for postgres setup step (#44084)
ce700f389c7 is described below
commit ce700f389c7f605819ffc2a2fdbc373219afa634
Author: Evan Rusackas <[email protected]>
AuthorDate: Wed Sep 9 08:31:57 2026 -0700
fix(security): suppress zizmor self-repository false positive for postgres
setup step (#44084)
Co-authored-by: Claude Sonnet 5 <[email protected]>
---
.github/workflows/superset-playwright.yml | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/.github/workflows/superset-playwright.yml
b/.github/workflows/superset-playwright.yml
index 3d9626ef7b0..c34e809a5b2 100644
--- a/.github/workflows/superset-playwright.yml
+++ b/.github/workflows/superset-playwright.yml
@@ -111,7 +111,13 @@ jobs:
- name: Setup Python
uses: $/.github/actions/setup-backend/
- name: Setup postgres
- uses: ./.github/actions/cached-dependencies
+ # cached-dependencies is a submodule (not a plain directory), and
+ # the $/ self-repository syntax resolves action files directly from
+ # the repository without performing a real (submodule-aware)
+ # checkout, so it can't see into a submodule's link. Keep this one
+ # on the workspace-relative ./ form, consistent with every other
+ # workflow in the repo that references this action.
+ uses: ./.github/actions/cached-dependencies # zizmor:
ignore[self-repository] - $/ cannot resolve an action that lives in a
submodule; ./ is required here
with:
run: setup-postgres
- name: Import test data