hainenber commented on code in PR #44722:
URL: https://github.com/apache/superset/pull/44722#discussion_r4113741680


##########
.github/workflows/superset-helm-lint-test.yml:
##########
@@ -43,19 +43,8 @@ jobs:
         with:
           install-superset: "false"
 
-      # Still vendored (not de-vendored like chart-releaser-action below): the
-      # allowlisted helm/[email protected] depends internally on
-      # astral-sh/[email protected], which isn't itself on the ASF Actions
-      # allowlist (only v8.1.0+ are, at apache/infrastructure-actions'
-      # actions.yml). Needs an INFRA request before this can de-vendor too.
-      # chart-testing-action is a submodule (not a plain directory), and the
-      # $/ self-repository syntax resolves action files directly from the
-      # repository without performing a real (submodule-aware) checkout, so
-      # it can't see into a submodule's link. Keep this one on the
-      # workspace-relative ./ form, consistent with every other workflow in
-      # the repo that references a submodule action.
       - name: Set up chart-testing
-        uses: ./.github/actions/chart-testing-action # zizmor: 
ignore[self-repository] - $/ cannot resolve an action that lives in a 
submodule; ./ is required here
+        uses: 
helm/chart-testing-action@6ec842c01de15ebb84c8627d2744a0c2f2755c9f # v2.8.0

Review Comment:
   This contradicts with what considered as best practices in handling GHA 
version: pinning to exact SHA to avoid version yank



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to