This is an automated email from the ASF dual-hosted git repository.

rusackas pushed a commit to branch 
fix/security-playwright-self-repository-change-detector
in repository https://gitbox.apache.org/repos/asf/superset.git

commit a10df9ad4827e05d19f6018c6cf9de08a5f03520
Author: rusackas <[email protected]>
AuthorDate: Wed Sep 9 07:47:57 2026 -0700

    fix(security): use self-repository syntax for change-detector in Playwright 
workflow
    
    Resolves code-scanning alert #2643 (zizmor/self-repository). The
    workspace-relative ./ form isn't a pinning mechanism and depends on
    runtime filesystem state; change-detector is a plain in-repo action
    (not a submodule), so it can safely switch to the $/ self-repository
    form, matching the same fix already applied to this action elsewhere
    (e.g. superset-python-integrationtest.yml).
    
    Co-Authored-By: Claude Sonnet 5 <[email protected]>
---
 .github/workflows/superset-playwright.yml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/.github/workflows/superset-playwright.yml 
b/.github/workflows/superset-playwright.yml
index 37675ca150d..29f4adb1fb3 100644
--- a/.github/workflows/superset-playwright.yml
+++ b/.github/workflows/superset-playwright.yml
@@ -42,7 +42,7 @@ jobs:
           persist-credentials: false
       - name: Check for file changes
         id: check
-        uses: ./.github/actions/change-detector/
+        uses: $/.github/actions/change-detector/
         with:
           token: ${{ secrets.GITHUB_TOKEN }}
 

Reply via email to