Skip to content

[automation] Auto-update linters version, help and documentation - #8726

Merged
nvuillam merged 5 commits into
mainfrom
create-pull-request/patch
Aug 22, 2026
Merged

[automation] Auto-update linters version, help and documentation#8726
nvuillam merged 5 commits into
mainfrom
create-pull-request/patch

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

[automation] Auto-update linters version, help and documentation

@github-actions

github-actions Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor Author

⚠️MegaLinter analysis: Success with warnings

⚠️ PYTHON / bandit - 177 errors
---------------------
>> Issue: [B311:blacklist] Standard pseudo-random generators are not suitable for security/cryptographic purposes.
   Severity: Low   Confidence: High
   CWE: CWE-330 (https://cwe.mitre.org/data/definitions/330.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/blacklists/blacklist_calls.html#b311-random
   Location: ./megalinter/utils_sarif.py:156:61
155	                        rule["id"] = (
156	                            rule["id"] + "_DUPLICATE_" + str(random.randint(1, 99999))
157	                        )

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:122:4
121	    )
122	    assert os.path.isdir(config.get(request_id, "DEFAULT_WORKSPACE")), (
123	        "DEFAULT_WORKSPACE "
124	        + config.get(request_id, "DEFAULT_WORKSPACE")
125	        + " is not a valid folder"
126	    )
127	

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:167:4
166	    tmp_report_folder = tempfile.gettempdir() + os.path.sep + str(uuid.uuid4())
167	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
168	    linter_name = linter.linter_name

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:241:4
240	    tmp_report_folder = tempfile.gettempdir() + os.path.sep + str(uuid.uuid4())
241	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
242	    if os.path.isfile(workspace + os.path.sep + "no_test_failure"):

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:490:4
489	    )
490	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
491	    expected_file_name = ""

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:590:4
589	        workspace += os.path.sep + "bad"
590	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
591	    # Call linter

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:690:4
689	        workspace = workspace + os.path.sep + "fix"
690	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
691	

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:796:12
795	            ]
796	            assert (len(list(diffs))) > 0, f"No changes in the {file} file"
797	

--------------------------------------------------
>> Issue: [B108:hardcoded_tmp_directory] Probable insecure usage of temp file/directory.
   Severity: Medium   Confidence: Medium
   CWE: CWE-377 (https://cwe.mitre.org/data/definitions/377.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b108_hardcoded_tmp_directory.html
   Location: ./server/server.py:81:42
80	    if item.fileUploadId:
81	        uploaded_file_path = os.path.join("/tmp/server-files", item.fileUploadId)
82	        if not os.path.isdir(uploaded_file_path):

--------------------------------------------------
>> Issue: [B108:hardcoded_tmp_directory] Probable insecure usage of temp file/directory.
   Severity: Medium   Confidence: Medium
   CWE: CWE-377 (https://cwe.mitre.org/data/definitions/377.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b108_hardcoded_tmp_directory.html
   Location: ./server/server.py:103:38
102	    file_upload_id = "FILE_" + str(uuid1())
103	    uploaded_file_path = os.path.join("/tmp/server-files", file_upload_id)
104	    os.makedirs(uploaded_file_path)

--------------------------------------------------
>> Issue: [B108:hardcoded_tmp_directory] Probable insecure usage of temp file/directory.
   Severity: Medium   Confidence: Medium
   CWE: CWE-377 (https://cwe.mitre.org/data/definitions/377.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b108_hardcoded_tmp_directory.html
   Location: ./server/server_worker.py:98:34
97	        temp_dir = self.create_temp_dir()
98	        upload_dir = os.path.join("/tmp/server-files", file_upload_id)
99	        if os.path.exists(upload_dir):

--------------------------------------------------

Code scanned:
	Total lines of code: 28307
	Total lines skipped (#nosec): 0
	Total potential issues skipped due to specifically being disabled (e.g., #nosec BXXX): 0

Run metrics:
	Total issues (by severity):
		Undefined: 0
		Low: 115
		Medium: 54
		High: 8
	Total issues (by confidence):
		Undefined: 0
		Low: 44
		Medium: 24
		High: 109
Files skipped (0):

(Truncated to last 6666 characters out of 125127)
⚠️ BASH / bash-exec - 1 error
Results of bash-exec linter (version 5.3.9)
See documentation on https://megalinter.io/beta/descriptors/bash_bash_exec/
-----------------------------------------------

✅ [SUCCESS] .automation/build_schemas_doc.sh
✅ [SUCCESS] .automation/format-tables.sh
✅ [SUCCESS] .vscode/testlinter.sh
✅ [SUCCESS] build.sh
✅ [SUCCESS] entrypoint.sh
❌ [ERROR] sh/megalinter_exec.sh
    Error: File:[sh/megalinter_exec.sh] is not executable

✅ [SUCCESS] sh/setup-runtime-user.sh
⚠️ SPELL / lychee - 56 errors
3 Forbidden

Errors in megalinter/descriptors/repository.megalinter-descriptor.yml
[404] https://raw.githubusercontent.com/oxsecurity/megalinter/main/docs/assets/icons/linters/betterleaks.png (at 297:26) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/rst.megalinter-descriptor.yml
[403] https://docutils.sourceforge.io/docs/ref/rst/directives.html#raw-data-pass-through (at 34:38) | Rejected status code: 403 Forbidden

Errors in megalinter/descriptors/salesforce.megalinter-descriptor.yml
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/config.html (at 374:37) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/engine-flow.html (at 371:17) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 176:17) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 276:17) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 74:17) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/rules-flow.html (at 373:23) | Rejected status code: 403 Forbidden

Errors in megalinter/descriptors/shared/biome.megalinter-linter.yml
[TIMEOUT] https://biomejs.dev/linter/rules/ (at 21:19) | Request timed out
[TIMEOUT] https://biomejs.dev/reference/configuration/ (at 22:33) | Request timed out

Errors in megalinter/descriptors/shared/cppcheck.megalinter-linter.yml
[403] https://cppcheck.sourceforge.io/ (at 3:13) | Rejected status code: 403 Forbidden
[403] https://cppcheck.sourceforge.io/ (at 4:14) | Rejected status code: 403 Forbidden
[403] https://cppcheck.sourceforge.io/manual.html#configuration (at 8:33) | Rejected status code: 403 Forbidden

Errors in megalinter/descriptors/spell.megalinter-descriptor.yml
[404] https://vale.sh/docs/topics/vocab/ (at 190:38) | Rejected status code: 404 Not Found | Followed 2 redirects. Redirects: https://vale.sh/docs/topics/vocab/ --[301]--> https://docs.vale.sh/topics/vocab/ --[302]--> https://docs.vale.sh/topics/vocab
[404] https://vale.sh/docs/vale-cli/structure/ (at 183:95) | Rejected status code: 404 Not Found | Followed 2 redirects. Redirects: https://vale.sh/docs/vale-cli/structure/ --[301]--> https://docs.vale.sh/vale-cli/structure/ --[302]--> https://docs.vale.sh/vale-cli/structure

Errors in megalinter/descriptors/tsx.megalinter-descriptor.yml
[404] https://eslint-react.xyz/docs/getting-started/installation (at 81:37) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/xml.megalinter-descriptor.yml
[406] https://gitlab.gnome.org/GNOME/libxml2/-/wikis/home (at 38:17) | Rejected status code: 406 Not Acceptable

Errors in README.md
[ERROR] https://ampcode.com/ (at 247:1) | HTTP/2 protocol error. Server may not support HTTP/2 properly
[301] https://future-architect.github.io/authors/%E5%AE%AE%E6%B0%B8%E5%B4%87%E5%8F%B2 (at 1974:104) | Rejected status code: 301 Moved Permanently
[TIMEOUT] https://generated.at/ (at 1315:301) | Request timed out
[404] https://github.com/oxsecurity/megalinter/stargazers (at 2120:3) | Rejected status code: 404 Not Found
[404] https://github.com/oxsecurity/megalinter/stargazers/ (at 23:1) | Rejected status code: 404 Not Found
[403] https://javascript.plainenglish.io/node-js-coding-standard-tools-with-megalinter-on-gitlab-ci-a43b55915811 (at 1957:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/@caodanju/30-seconds-to-setup-megalinter-your-go-to-tool-for-automated-code-quality-and-iac-security-969d90a5a99c (at 1942:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/@RunningMattress (at 1951:255) | Rejected status code: 403 Forbidden
[403] https://medium.com/@RunningMattress/level-up-your-unity-packages-with-ci-cd-9498d2791211 (at 1951:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/@SeasonedDeveloper (at 1938:255) | Rejected status code: 403 Forbidden
[403] https://medium.com/@SeasonedDeveloper/looking-for-the-best-ci-cd-pipeline-linting-tool-try-megalinter-d89c9eba850d (at 1938:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/datamindedbe/integrating-megalinter-to-automate-linting-across-multiple-codebases-a-technical-description-a200bb235b71 (at 1939:3) | Rejected status code: 403 Forbidden
[403] https://nicolas.vuillamy.fr/improve-uniformize-and-secure-your-code-base-with-megalinter-62ebab422c1 (at 1960:3) | Rejected status code: 403 Forbidden
[403] https://nicolas.vuillamy.fr/megalinter-sells-his-soul-and-joins-ox-security-2a91a0027628 (at 1959:3) | Rejected status code: 403 Forbidden
[403] https://nklya.medium.com/ (at 1956:255) | Rejected status code: 403 Forbidden
[403] https://nklya.medium.com/hot-to-linter-basic-things-like-trailing-whitespaces-and-newlines-7b40da8f688d (at 1956:3) | Rejected status code: 403 Forbidden
[403] https://npmjs.org/package/mega-linter-runner (at 1230:1) | Error (cached)
[403] https://npmjs.org/package/mega-linter-runner (at 1231:1) | Error (cached)
[403] https://npmjs.org/package/mega-linter-runner (at 1232:1) | Error (cached)
[403] https://npmjs.org/package/mega-linter-runner (at 21:1) | Rejected status code: 403 Forbidden | Followed 1 redirect. Redirects: https://npmjs.org/package/mega-linter-runner --[301]--> https://www.npmjs.com/package/mega-linter-runner
[403] https://openai.com/codex/ (at 239:1) | Rejected status code: 403 Forbidden
[403] https://pmd.sourceforge.io/pmd-6.55.0/pmd_userdocs_tools_ci.html (at 2041:3) | Rejected status code: 403 Forbidden
[403] https://techcommunity.microsoft.com/ (at 1946:371) | Rejected status code: 403 Forbidden
[403] https://techcommunity.microsoft.com/t5/azure-devops-blog/achieve-code-consistency-megalinter-integration-in-azure-devops/ba-p/3939448 (at 1946:3) | Rejected status code: 403 Forbidden
[403] https://techcommunity.microsoft.com/t5/user/viewprofilepage/user-id/2039143#profile (at 1946:255) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@downatthebottomofthemolehole/megalinter-mcp-server (at 1916:354) | Rejected status code: 403 Forbidden

Hint: Followed 769 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: Rejected redirectional status codes. This means some redirects were not followed. You might want to increase the limit for `-m`/`--max-redirects`.

(Truncated to last 6666 characters out of 32111)
⚠️ MARKDOWN / markdownlint - 343 errors
-Linter"]
docs/plugins.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Plugins"]
docs/quick-start.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Quick Start"]
docs/removed-linters.md:9 error MD024/no-duplicate-heading Multiple headings with the same content [Context: "Removed linters"]
docs/reporters.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Reporters"]
docs/reporters/AzureCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Azure Comment Reporter"]
docs/reporters/BitbucketCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Bitbucket Comment Reporter"]
docs/reporters/ConfigReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "IDE Configuration Reporter"]
docs/reporters/ConsoleReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Console Reporter"]
docs/reporters/EmailReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "E-mail Reporter"]
docs/reporters/FileIoReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "File.io Reporter"]
docs/reporters/GitHubCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "GitHub Comment Reporter"]
docs/reporters/GitHubCommentReporter.md:27:196 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:27:46 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:27:174 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:27:196 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:28:179 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:28:46 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:28:160 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:28:179 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:29:159 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:29:48 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:29:143 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:29:159 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:30:171 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:30:46 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:30:152 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:30:171 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubStatusReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "GitHub Status Reporter"]
docs/reporters/GitlabCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Gitlab Comment Reporter"]
docs/reporters/JsonReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "JSON Reporter"]
docs/reporters/MarkdownSummaryReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Markdown Summary Reporter"]
docs/reporters/SarifReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "SARIF Reporter (beta)"]
docs/reporters/TapReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "TAP Reporter"]
docs/reporters/TextReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Text Reporter"]
docs/reporters/UpdatedSourcesReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Updated Sources Reporter"]
docs/special-thanks.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Special thanks"]
docs/special-thanks.md:23:3 error MD045/no-alt-text Images should have alternate text (alt text)
docs/sponsor.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Sponsoring"]
docs/supported-linters.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Supported Linters"]
mega-linter-runner/README.md:27:274 error MD051/link-fragments Link fragments should be valid [Context: "[**apply formatting and auto-fixes**](#apply-fixes)"]
mega-linter-runner/README.md:27:217 error MD051/link-fragments Link fragments should be valid [Context: "[**reports in several formats**](#reports)"]
README.md:219:127 error MD051/link-fragments Link fragments should be valid [Context: "[many additional features](#mega-linter-vs-super-linter)"]
README.md:2147:3 error MD045/no-alt-text Images should have alternate text (alt text)
skills/megalinter-check/performance.md:27:601 error MD013/line-length Line length [Expected: 600; Actual: 713]
skills/megalinter-setup/agents/megalinter-runner.md:33:601 error MD013/line-length Line length [Expected: 600; Actual: 620]

(Truncated to last 6666 characters out of 45647)
⚠️ YAML / prettier - 14 errors
nchanged)
mega-linter-runner/generators/mega-linter-custom-flavor/templates/action.yml 3ms (unchanged)
mega-linter-runner/generators/mega-linter-custom-flavor/templates/check-new-megalinter-version.yml 12ms (unchanged)
mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor-builder.yml 15ms (unchanged)
[error] mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor.yml: SyntaxError: Implicit map keys need to be followed by map values (6:1)
[error]   4 | label: <%= CUSTOM_FLAVOR_LABEL %>
[error]   5 | linters:
[error] > 6 | <%= CUSTOM_FLAVOR_LINTERS %>
[error]     | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[error]   7 |
mega-linter-runner/generators/mega-linter-custom-flavor/templates/zizmor.yml 2ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/.drone.yml 3ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/.gitlab-ci.yml 5ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/azure-pipelines.yml 5ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/bitbucket-pipelines.yml 6ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/concourse-task.yml 3ms (unchanged)
[error] mega-linter-runner/generators/mega-linter/templates/mega-linter.yml: SyntaxError: Implicit map keys need to be followed by map values (67:11)
[error]   65 |           # Only define `secrets.PAT` if you fully understand the trade-off.
[error]   66 |           token: ${{ secrets.PAT || secrets.GITHUB_TOKEN }}
[error] > 67 |           <%- PERSIST_CREDENTIALS %>
[error]      |           ^^^^^^^^^^^^^^^^^^^^^^^^^^
[error]   68 |
[error]   69 |           # If you use VALIDATE_ALL_CODEBASE = true, you can remove this line to
[error]   70 |           # improve performance
megalinter/descriptors/action.megalinter-descriptor.yml 18ms (unchanged)
megalinter/descriptors/ansible.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/api.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/arm.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/bash.megalinter-descriptor.yml 21ms (unchanged)
megalinter/descriptors/bicep.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/c.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/clojure.megalinter-descriptor.yml 13ms (unchanged)
megalinter/descriptors/cloudformation.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/coffee.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/copypaste.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/cpp.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/csharp.megalinter-descriptor.yml 12ms (unchanged)
megalinter/descriptors/css.megalinter-descriptor.yml 16ms (unchanged)
megalinter/descriptors/dart.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/dockerfile.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/editorconfig.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/env.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/gherkin.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/go.megalinter-descriptor.yml 9ms (unchanged)
megalinter/descriptors/graphql.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/groovy.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/html.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/java.megalinter-descriptor.yml 15ms (unchanged)
megalinter/descriptors/javascript.megalinter-descriptor.yml 19ms (unchanged)
megalinter/descriptors/json.megalinter-descriptor.yml 12ms (unchanged)
megalinter/descriptors/jsx.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/kotlin.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/kubernetes.megalinter-descriptor.yml 11ms (unchanged)
megalinter/descriptors/latex.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/lua.megalinter-descriptor.yml 9ms (unchanged)
megalinter/descriptors/markdown.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/perl.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/php.megalinter-descriptor.yml 37ms (unchanged)
megalinter/descriptors/powershell.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/protobuf.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/python.megalinter-descriptor.yml 61ms (unchanged)
megalinter/descriptors/r.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/raku.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/repository.megalinter-descriptor.yml 81ms (unchanged)
megalinter/descriptors/robotframework.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/rst.megalinter-descriptor.yml 15ms (unchanged)
megalinter/descriptors/ruby.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/rust.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/salesforce.megalinter-descriptor.yml 30ms (unchanged)
megalinter/descriptors/scala.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/shared/biome.megalinter-linter.yml 5ms (unchanged)
megalinter/descriptors/shared/clang-format.megalinter-linter.yml 3ms (unchanged)
megalinter/descriptors/shared/cppcheck.megalinter-linter.yml 3ms (unchanged)
megalinter/descriptors/shared/cpplint.megalinter-linter.yml 2ms (unchanged)
megalinter/descriptors/shared/dotnet-format.megalinter-linter.yml 3ms (unchanged)
megalinter/descriptors/shared/eslint.megalinter-linter.yml 4ms (unchanged)
megalinter/descriptors/shared/prettier.megalinter-linter.yml 5ms (unchanged)
megalinter/descriptors/shared/v8r.megalinter-linter.yml 3ms (unchanged)
megalinter/descriptors/snakemake.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/spell.megalinter-descriptor.yml 25ms (unchanged)
megalinter/descriptors/sql.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/swift.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/tekton.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/terraform.megalinter-descriptor.yml 13ms (unchanged)
megalinter/descriptors/tsx.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/typescript.megalinter-descriptor.yml 12ms (unchanged)
megalinter/descriptors/vbdotnet.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/xml.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/yaml.megalinter-descriptor.yml 9ms (unchanged)
server/docker-compose-dev.yml 3ms (unchanged)
server/docker-compose.yml 4ms (unchanged)
trivy-secret.yaml 1ms (unchanged)
zizmor.yml 2ms (unchanged)

(Truncated to last 6666 characters out of 12555)
⚠️ YAML / yamllint - 42 errors
.grype.yaml
  6:1       warning  missing document start "---"  (document-start)

mega-linter-runner/.eslintrc.yml
  11:9      warning  too few spaces inside empty braces  (braces)

mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor-builder.yml
  48:15     warning  too few spaces inside empty braces  (braces)

mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor.yml
  7:1       error    syntax error: could not find expected ':' (syntax)

mega-linter-runner/generators/mega-linter/templates/mega-linter.yml
  38:15     warning  too few spaces inside empty braces  (braces)
  69:11     error    syntax error: could not find expected ':' (syntax)

megalinter/descriptors/copypaste.megalinter-descriptor.yml
  19:301    warning  line too long (313 > 300 characters)  (line-length)
  25:301    warning  line too long (384 > 300 characters)  (line-length)

megalinter/descriptors/javascript.megalinter-descriptor.yml
  52:301    warning  line too long (475 > 300 characters)  (line-length)
  328:301   warning  line too long (307 > 300 characters)  (line-length)
  354:301   warning  line too long (315 > 300 characters)  (line-length)

megalinter/descriptors/json.megalinter-descriptor.yml
  112:301   warning  line too long (315 > 300 characters)  (line-length)

megalinter/descriptors/jsx.megalinter-descriptor.yml
  29:301    warning  line too long (475 > 300 characters)  (line-length)

megalinter/descriptors/perl.megalinter-descriptor.yml
  25:301    warning  line too long (310 > 300 characters)  (line-length)

megalinter/descriptors/php.megalinter-descriptor.yml
  200:301   warning  line too long (389 > 300 characters)  (line-length)
  214:301   warning  line too long (302 > 300 characters)  (line-length)

megalinter/descriptors/repository.megalinter-descriptor.yml
  27:301    warning  line too long (666 > 300 characters)  (line-length)
  193:301   warning  line too long (408 > 300 characters)  (line-length)
  299:301   warning  line too long (345 > 300 characters)  (line-length)
  478:301   warning  line too long (306 > 300 characters)  (line-length)
  557:301   warning  line too long (374 > 300 characters)  (line-length)
  642:301   warning  line too long (316 > 300 characters)  (line-length)
  979:301   warning  line too long (1263 > 300 characters)  (line-length)
  1076:301  warning  line too long (879 > 300 characters)  (line-length)
  1090:301  warning  line too long (358 > 300 characters)  (line-length)
  1153:301  warning  line too long (346 > 300 characters)  (line-length)
  1160:301  warning  line too long (307 > 300 characters)  (line-length)

megalinter/descriptors/salesforce.megalinter-descriptor.yml
  54:301    warning  line too long (359 > 300 characters)  (line-length)

megalinter/descriptors/spell.megalinter-descriptor.yml
  181:301   warning  line too long (315 > 300 characters)  (line-length)

megalinter/descriptors/sql.megalinter-descriptor.yml
  27:301    warning  line too long (403 > 300 characters)  (line-length)

megalinter/descriptors/terraform.megalinter-descriptor.yml
  28:301    warning  line too long (330 > 300 characters)  (line-length)
  88:301    warning  line too long (346 > 300 characters)  (line-length)
  155:301   warning  line too long (328 > 300 characters)  (line-length)

megalinter/descriptors/tsx.megalinter-descriptor.yml
  29:301    warning  line too long (475 > 300 characters)  (line-length)

megalinter/descriptors/typescript.megalinter-descriptor.yml
  39:301    warning  line too long (475 > 300 characters)  (line-length)
  318:301   warning  line too long (314 > 300 characters)  (line-length)
  344:301   warning  line too long (315 > 300 characters)  (line-length)

megalinter/descriptors/yaml.megalinter-descriptor.yml
  38:301    warning  line too long (315 > 300 characters)  (line-length)

mkdocs.yml
  8:301     warning  line too long (590 > 300 characters)  (line-length)
  72:5      warning  wrong indentation: expected 6 but found 4  (indentation)
  85:5      warning  wrong indentation: expected 6 but found 4  (indentation)

zizmor.yml
  1:1       warning  missing document start "---"  (document-start)

✅ Linters with no issues

actionlint, betterleaks, black, checkov, cspell, flake8, git_diff, grype, hadolint, isort, jscpd, jsonlint, markdown-table-formatter (1 fix), mypy, npm-groovy-lint, osv-scanner, pylint, ruff, secretlint, shellcheck, shfmt, spectral, syft, trivy, trivy-sbom, trufflehog, v8r, v8r, xmllint, zizmor

See detailed reports in MegaLinter artifacts

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@github-actions
github-actions Bot force-pushed the create-pull-request/patch branch 4 times, most recently from d732052 to ec83a3e Compare August 20, 2026 22:35
…ckets DoS

Go stdlib CVE-2026-56853 / 56858 / 56859 / 56860 / 56862 (fixed in go1.26.6) are
flagged on every Go binary in the images. Only revive and dustilock are compiled
in-repo; the rest come from upstream vendor images already pinned at their latest
release, so there is no upgrade path. Four are availability-only and unreachable
from a one-shot lint CLI that binds no listener and terminates no TLS; the
encoding/xml one is documented as bounded rather than unreachable.

CVE-2026-62901 is a System.Net.WebSockets receive-loop hang in the .NET runtime
bundled with PowerShell. PowerShell 7.6.5 is still built against SDK 10.0.302
(runtime 10.0.10), so bumping the pin does not clear it. arm-ttk and the
powershell linters never open a WebSocket.
…ve; ignore the rest

Upgrades that genuinely clear the findings:
- GO_IMAGE_VERSION 1.26.5 -> 1.26.7 (go1.26.6 fixes CVE-2026-33818 and
  CVE-2026-46600), which rebuilds the two binaries MegaLinter compiles itself,
  revive and dustilock.
- golangci-lint 2.12.2 -> 2.13.1 and revive v1.15.0 -> v1.16.0: both vendor the
  fixed golang.org/x/mod v0.40.0, clearing CVE-2026-56864 and CVE-2026-56865.

Ignore entries for what has no upgrade path, each with its justification:
- CVE-2026-33818 (encoding/asn1) and CVE-2026-46600 (x/net dns/dnsmessage) for
  actionlint, shfmt, editorconfig-checker and the other binaries copied from
  upstream vendor images already pinned at their latest release.
- CVE-2026-56864 / CVE-2026-56865 for editorconfig-checker, syft and trivy. The
  flaw is in x/mod's sumdb / module-proxy client, i.e. the code run while
  downloading and verifying modules. These tools link x/mod only to parse go.mod
  and resolve module metadata in a checked-out tree; module downloads during the
  Docker build use the go toolchain's own copy against the default
  proxy.golang.org / sum.golang.org.
- CVE-2026-73507 (netty-codec-xml) and CVE-2026-59902 (netty-transport-sctp):
  an XML wire-protocol decoder and the SCTP transport, bundled in
  code-analyzer-sfge-engine/dist/java-lib. The Salesforce Graph Engine walks Apex
  source locally to build a call graph; it opens no socket, speaks no SCTP and
  decodes no network XML frames. @salesforce/plugin-code-analyzer 5.15.0, which
  vendors them, is the latest release.
- CVE-2026-73566 (node-tar): availability-only DoS on a crafted long-path
  archive. node-tar runs when sf extracts an archive, which happens while
  installing plugins at Docker build time, not at lint time.
The good fixture was the stock `helm create` scaffold, which kubescape now
fails on two High controls: C-0211 (no security context) and C-0237 (the
referenced image carries no signature). kubescape downloads its policies at
scan time, so this surfaced without any repository change.

The chart is now genuinely well configured rather than merely passing:
- pod and container security contexts set (runAsNonRoot, runAsUser/Group,
  fsGroup, seccompProfile RuntimeDefault, seLinuxOptions,
  allowPrivilegeEscalation false, readOnlyRootFilesystem, drop ALL capabilities)
- added the ServiceAccount template that the scaffold referenced but never
  defined, with automountServiceAccountToken disabled
- added a NetworkPolicy restricting ingress to the container port and egress
  to DNS
- image switched to the cosign-signed cgr.dev/chainguard/nginx, which also
  runs unprivileged on port 8080
- added an `app` selector label, required by the label-usage control

The bad fixture is unchanged and still fails as expected.
@nvuillam
nvuillam merged commit 0e17b43 into main Aug 22, 2026
146 checks passed
@nvuillam
nvuillam deleted the create-pull-request/patch branch August 22, 2026 08:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automerge dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant