sadpandajoe opened a new pull request, #45035:
URL: https://github.com/apache/superset/pull/45035

   ### SUMMARY
   
   A fork or mirror that pushes to `master` runs every workflow in this 
repository, including jobs that depend on something only `apache/superset` has. 
Those jobs run to the end and then fail, or produce nothing, on every push. 
This PR makes each of them either skip cleanly or work, without changing what 
runs in `apache/superset`.
   
   All test jobs (Python unit and integration, frontend, E2E, pre-commit) are 
untouched and keep running everywhere.
   
   | Workflow | Problem outside `apache/superset` | Change |
   |---|---|---|
   | CodeQL | The full analysis runs, then the SARIF upload is rejected when 
code scanning is not enabled (private repositories without GitHub Code 
Security). | Probe the code scanning API once in the existing `changes` job and 
skip `analyze` when it is unavailable. |
   | Validate All GitHub Actions (zizmor) | Same SARIF upload rejection. | 
Reuse the probe to set zizmor's `advanced-security` input, so the audit still 
runs and fails on findings but does not attempt the upload. |
   | Docker | Push builds log in to Docker Hub and push images, which fails 
without `DOCKERHUB_USER` / `DOCKERHUB_TOKEN`. | Skip `docker-build` on `push` 
when the credentials are absent, using the same `has-secrets` pattern as 
`tech-debt.yml` and `release.yml`. Pull request builds are unchanged. |
   | Translations | The base-ref fetch is unauthenticated (the checkout uses 
`persist-credentials: false`), so it fails when the repository is not public. | 
Authenticate the two fetches with the workflow token for that step only. |
   | Docs Testing | `build-after-tests` has no `permissions` block and cannot 
read the triggering workflow run in a non-public repository. | Grant `contents: 
read` and `actions: read`. |
   | Frontend | `report-coverage` declares only `id-token: write`, which drops 
the default `contents: read`. | Add `contents: read`. |
   | Python nightly canary, Testcontainers, bundle-size baseline, Showtime 
cleanup | Scheduled runs are only meaningful upstream. | Run on `schedule` only 
in `apache/superset`, matching the existing `github.repository == 
'apache/superset'` guards. `workflow_dispatch` still works everywhere. |
   
   Design notes:
   
   - The code scanning probe **fails open**. Only an HTTP 403 whose body is 
GitHub's explicit "Code Security / Advanced Security must be enabled" rejection 
counts as unavailable. Any other outcome (success, an empty alert list, a token 
without access to alerts, a network error) reports available, so 
`apache/superset` and forks that do have code scanning are never skipped by 
mistake.
   - The probe lives in 
`.github/workflows/scripts/check-code-scanning-available.sh` with a companion 
test script that stubs `curl`. The validator workflow runs that test.
   - `changes` in the CodeQL workflow gains `security-events: read` for the 
probe.
   
   ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
   
   N/A
   
   ### TESTING INSTRUCTIONS
   
   1. Run the probe tests: `bash 
.github/workflows/scripts/check-code-scanning-available.test.sh` (8 cases, 
including the fail-open branches).
   2. On this PR, confirm that CodeQL `analyze`, `docker-build`, zizmor and the 
translations check all still run in `apache/superset`. That is the behaviour 
that must not change.
   3. Optionally, in a private fork without code scanning or Docker Hub 
secrets, push to `master` and confirm that CodeQL `analyze` and `docker-build` 
are skipped, and that the zizmor and translations jobs pass.
   
   Verified locally: `action-validator` and `zizmor` pass on the changed 
workflows, and the probe returns `available=true` against `apache/superset` and 
`available=false` against a private repository without code scanning.
   
   One thing not verified ahead of a real run: the live probe was exercised 
with a user token, not with the workflow `GITHUB_TOKEN`. If the workflow token 
gets a different response in a repository without code scanning, the probe 
reports available and behaviour is the same as before this PR.
   
   ### ADDITIONAL INFORMATION
   
   - [ ] Has associated issue:
   - [ ] Required feature flags:
   - [ ] Changes UI
   - [ ] Includes DB Migration (follow approval process in 
[SIP-59](https://github.com/apache/superset/issues/13351))
     - [ ] Migration is atomic, supports rollback & is backwards-compatible
     - [ ] Confirm DB migration upgrade and downgrade tested
     - [ ] Runtime estimates and downtime expectations provided
   - [ ] Introduces new feature or API
   - [ ] Removes existing feature or API
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to