sadpandajoe opened a new pull request, #45035: URL: https://github.com/apache/superset/pull/45035
### SUMMARY A fork or mirror that pushes to `master` runs every workflow in this repository, including jobs that depend on something only `apache/superset` has. Those jobs run to the end and then fail, or produce nothing, on every push. This PR makes each of them either skip cleanly or work, without changing what runs in `apache/superset`. All test jobs (Python unit and integration, frontend, E2E, pre-commit) are untouched and keep running everywhere. | Workflow | Problem outside `apache/superset` | Change | |---|---|---| | CodeQL | The full analysis runs, then the SARIF upload is rejected when code scanning is not enabled (private repositories without GitHub Code Security). | Probe the code scanning API once in the existing `changes` job and skip `analyze` when it is unavailable. | | Validate All GitHub Actions (zizmor) | Same SARIF upload rejection. | Reuse the probe to set zizmor's `advanced-security` input, so the audit still runs and fails on findings but does not attempt the upload. | | Docker | Push builds log in to Docker Hub and push images, which fails without `DOCKERHUB_USER` / `DOCKERHUB_TOKEN`. | Skip `docker-build` on `push` when the credentials are absent, using the same `has-secrets` pattern as `tech-debt.yml` and `release.yml`. Pull request builds are unchanged. | | Translations | The base-ref fetch is unauthenticated (the checkout uses `persist-credentials: false`), so it fails when the repository is not public. | Authenticate the two fetches with the workflow token for that step only. | | Docs Testing | `build-after-tests` has no `permissions` block and cannot read the triggering workflow run in a non-public repository. | Grant `contents: read` and `actions: read`. | | Frontend | `report-coverage` declares only `id-token: write`, which drops the default `contents: read`. | Add `contents: read`. | | Python nightly canary, Testcontainers, bundle-size baseline, Showtime cleanup | Scheduled runs are only meaningful upstream. | Run on `schedule` only in `apache/superset`, matching the existing `github.repository == 'apache/superset'` guards. `workflow_dispatch` still works everywhere. | Design notes: - The code scanning probe **fails open**. Only an HTTP 403 whose body is GitHub's explicit "Code Security / Advanced Security must be enabled" rejection counts as unavailable. Any other outcome (success, an empty alert list, a token without access to alerts, a network error) reports available, so `apache/superset` and forks that do have code scanning are never skipped by mistake. - The probe lives in `.github/workflows/scripts/check-code-scanning-available.sh` with a companion test script that stubs `curl`. The validator workflow runs that test. - `changes` in the CodeQL workflow gains `security-events: read` for the probe. ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF N/A ### TESTING INSTRUCTIONS 1. Run the probe tests: `bash .github/workflows/scripts/check-code-scanning-available.test.sh` (8 cases, including the fail-open branches). 2. On this PR, confirm that CodeQL `analyze`, `docker-build`, zizmor and the translations check all still run in `apache/superset`. That is the behaviour that must not change. 3. Optionally, in a private fork without code scanning or Docker Hub secrets, push to `master` and confirm that CodeQL `analyze` and `docker-build` are skipped, and that the zizmor and translations jobs pass. Verified locally: `action-validator` and `zizmor` pass on the changed workflows, and the probe returns `available=true` against `apache/superset` and `available=false` against a private repository without code scanning. One thing not verified ahead of a real run: the live probe was exercised with a user token, not with the workflow `GITHUB_TOKEN`. If the workflow token gets a different response in a repository without code scanning, the probe reports available and behaviour is the same as before this PR. ### ADDITIONAL INFORMATION - [ ] Has associated issue: - [ ] Required feature flags: - [ ] Changes UI - [ ] Includes DB Migration (follow approval process in [SIP-59](https://github.com/apache/superset/issues/13351)) - [ ] Migration is atomic, supports rollback & is backwards-compatible - [ ] Confirm DB migration upgrade and downgrade tested - [ ] Runtime estimates and downtime expectations provided - [ ] Introduces new feature or API - [ ] Removes existing feature or API 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
