This is an automated email from the ASF dual-hosted git repository. rusackas pushed a commit to branch fix/security-playwright-self-repository-change-detector in repository https://gitbox.apache.org/repos/asf/superset.git
commit a10df9ad4827e05d19f6018c6cf9de08a5f03520 Author: rusackas <[email protected]> AuthorDate: Wed Sep 9 07:47:57 2026 -0700 fix(security): use self-repository syntax for change-detector in Playwright workflow Resolves code-scanning alert #2643 (zizmor/self-repository). The workspace-relative ./ form isn't a pinning mechanism and depends on runtime filesystem state; change-detector is a plain in-repo action (not a submodule), so it can safely switch to the $/ self-repository form, matching the same fix already applied to this action elsewhere (e.g. superset-python-integrationtest.yml). Co-Authored-By: Claude Sonnet 5 <[email protected]> --- .github/workflows/superset-playwright.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/superset-playwright.yml b/.github/workflows/superset-playwright.yml index 37675ca150d..29f4adb1fb3 100644 --- a/.github/workflows/superset-playwright.yml +++ b/.github/workflows/superset-playwright.yml @@ -42,7 +42,7 @@ jobs: persist-credentials: false - name: Check for file changes id: check - uses: ./.github/actions/change-detector/ + uses: $/.github/actions/change-detector/ with: token: ${{ secrets.GITHUB_TOKEN }}
