Skip to content

ci(deps): bump the github-actions group with 6 updates - #132

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-1bf67618b7
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-1bf67618b7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 6 updates:

Package From To
zizmorcore/zizmor-action 0.6.3 0.6.4
oxsecurity/megalinter/flavors/dotnet 10.0.0 10.1.0
github/codeql-action/upload-sarif 4.37.9 4.38.2
reviewdog/action-suggester 1.24.3 1.26.1
docker/setup-buildx-action 4.3.0 4.4.1
docker/build-push-action 7.3.0 7.4.0

Updates zizmorcore/zizmor-action from 0.6.3 to 0.6.4

Release notes

Sourced from zizmorcore/zizmor-action's releases.

v0.6.4

Sponsorship is appreciated!

zizmor 1.30.1 is now the default version.

Release notes: zizmorcore/zizmor-action#1301

Commits

Updates oxsecurity/megalinter/flavors/dotnet from 10.0.0 to 10.1.0

Release notes

Sourced from oxsecurity/megalinter/flavors/dotnet's releases.

v10.1.0

What's Changed

  • Core

    • MegaLinter now prints a crash traceback when it is killed by a fatal signal (SIGSEGV, SIGBUS…), instead of exiting silently with no clue about what happened (#8779)
    • The LLM Advisor supports a new provider, OrcaRouter, an OpenAI-compatible AI gateway: set LLM_PROVIDER: orcarouter and ORCAROUTER_API_KEY in your environment to get fix suggestions routed through OrcaRouter (see the OrcaRouter provider page) (#8826)
  • New linters

    • biome, one fast toolchain linting, formatting and sorting imports of JavaScript, TypeScript, JSX, TSX, JSON, CSS and GraphQL files, available as JAVASCRIPT_BIOME, TYPESCRIPT_BIOME, JSX_BIOME, TSX_BIOME, JSON_BIOME, CSS_BIOME and GRAPHQL_BIOME (#8706)
      • Activated only when a biome.json or biome.jsonc configuration file is found in the repository
      • Supports APPLY_FIXES (safe fixes with --write) and native SARIF output
      • EXCLUDED_DIRECTORIES are forwarded in project lint mode through a generated configuration extending the workspace one
    • ApexGuru, the AI-driven engine of Salesforce Code Analyzer, available as SALESFORCE_CODE_ANALYZER_APEXGURU (#8820)
      • Detects SOQL inefficiencies, critical anti-patterns and scalability hotspots in your .cls and .trigger files, with line-level highlights, severity ratings and suggested fixes
      • The analysis runs in a connected Salesforce org, not locally: store the auth url of the target org in a CI secret named SFDX_AUTH_URL, and MegaLinter logs in to that org before the scan
      • The scan is sent to that org explicitly, so a .sfdx/sfdx-config.json left at the root of the repository, usually naming a long gone scratch org, can not hijack it
      • Inactive by default: it activates only when SFDX_AUTH_URL is defined, so nothing changes for existing Salesforce projects
      • Requires ApexGuru to be enabled on the org: it needs Scale Center, and is available for Unlimited Edition production orgs, full copy sandboxes, Signature orgs and Scale Test customers
      • A run where the engine could not analyze anything is reported as an error rather than a silent success, together with the reason and how to fix it
      • Supports native SARIF output, like the other Code Analyzer engines
    • tofu fmt, the built-in formatter of OpenTofu (the MPL-2.0 licensed fork of Terraform), available as TERRAFORM_TOFU_FMT (#8729)
      • Analyzes .tofu files only, the OpenTofu specific extension, so it never doubles up with TERRAFORM_TERRAFORM_FMT which keeps .tf
      • To format your .tf files with OpenTofu instead, set TERRAFORM_TOFU_FMT_FILE_EXTENSIONS: [".tofu", ".tf", ".tfvars"] and DISABLE_LINTERS: [TERRAFORM_TERRAFORM_FMT]
      • Supports APPLY_FIXES to rewrite files in the canonical OpenTofu style
    • tofu validate, the built-in validator of OpenTofu, available as TERRAFORM_TOFU_VALIDATE (#8793)
      • Reports what formatters and rule-based linters can not see: unsupported or missing arguments, wrong attribute types, references to undeclared variables, locals or outputs, and broken module input contracts
      • Analyzes .tofu files only, like TERRAFORM_TOFU_FMT, leaving .tf free for a future terraform validate linter. To validate .tf files, set TERRAFORM_TOFU_VALIDATE_FILE_EXTENSIONS: [".tofu", ".tf"]
      • Validates one whole module per directory, so every .tf and .tofu file of a selected directory is parsed and can produce diagnostics
      • Every directory is initialized with tofu init -backend=false beforehand, so no state is read, no state lock is taken and no cloud credentials are needed
      • Set TERRAFORM_TOFU_VALIDATE_INIT_ARGUMENTS to change those initialization arguments, for example adding -lockfile=readonly to have an out-of-sync .terraform.lock.hcl reported as an error instead of being updated
  • Disabled linters

    • COFFEE_COFFEELINT is disabled: CoffeeScript tooling is discontinued, and coffeelint can not receive EXCLUDED_DIRECTORIES in project lint mode (it has no exclusion option and reads .coffeelintignore only from its working directory). The linter will be removed in a future version (#8720)
    • GRAPHQL_GRAPHQL_SCHEMA_LINTER is disabled: graphql-schema-linter is unmaintained, with no release or commit since May 2022, and its peer dependency range pins graphql to ^15 || ^16, which held the whole GraphQL install back from graphql v17. Use GRAPHQL_BIOME to lint your GraphQL files. The linter will be removed in a future version (#8894)
  • Re-enabled linters

    • spectral is back as API_SPECTRAL, together with the API descriptor, to lint your OpenAPI, AsyncAPI and Arazzo specifications (#8717)
      • It was removed in v10.0.0 because it crashed at startup on every run: the cause has been found and fixed
      • Nothing to change in your configuration: API_SPECTRAL works again in ENABLE_LINTERS / DISABLE_LINTERS, and the default ruleset file is still .spectral.yaml
  • Linters enhancements

    • TERRAFORM_TFLINT now documents the tflint native GITHUB_TOKEN_github_com variable to authenticate plugin downloads on github.com, which is the recommended way to fix tflint --init failures when your GITHUB_TOKEN targets a GitHub Enterprise instance (#8795)
      • Set your github.com token in GITHUB_TOKEN_github_com, then list it in TERRAFORM_TFLINT_UNSECURED_ENV_VARIABLES: tflint gives it priority over GITHUB_TOKEN, which other linters and reporters keep using
      • PAT_GITHUB_COM is deprecated: it still works and now logs a warning, and will be removed in a future major release
    • CLOJURE_CLJSTYLE now forwards EXCLUDED_DIRECTORIES through its native repeatable --ignore argument, instead of a temporary .cljstyle written in your repository. Exclusions are now also applied when your repository already has a .cljstyle config, whose own ignore patterns are preserved (#8720)
    • SQL_SQLFLUFF does not receive EXCLUDED_DIRECTORIES in project lint mode anymore: sqlfluff reads path exclusions only from a .sqlfluffignore, .sqlfluff or pyproject.toml located inside the analyzed sources, where MegaLinter used to write a temporary file. List the directories to skip in your own .sqlfluffignore, or keep the default list_of_files lint mode where MegaLinter filters the files itself (#8720)
    • SARIF output is now available for 13 more linters: zizmor, bicep_linter, cppcheck, clj-kondo, roslynator, htmlhint, protolint, sqlfluff, swiftlint, osv-scanner, trufflehog, jscpd and lintr. Enable it the same way as any other SARIF-capable linter, with SARIF_REPORTER: true (optionally scoped with SARIF_REPORTER_LINTERS) (#8715)
      • The 4 Salesforce Code Analyzer engines (SALESFORCE_CODE_ANALYZER_APEX, _AURA, _LWC, _FLOW) also gained SARIF output: their report switches from CSV to SARIF automatically when SARIF reporting is requested
      • csharp_roslynator is bumped from 0.12.0 to 0.13.0, the first release including its SARIF output support

... (truncated)

Changelog

Sourced from oxsecurity/megalinter/flavors/dotnet's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased] (beta, main branch content)

Note: Can be used with oxsecurity/megalinter@beta in your GitHub Action mega-linter.yml file, or with oxsecurity/megalinter:beta docker image

  • Breaking changes

  • Core

  • New linters

  • Disabled linters

  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • CLOJURE_CLJ_KONDO now lints all your Clojure files in a single clj-kondo run, with the new default list_of_files lint mode
      • Cross-namespace checks, such as calls with a wrong number of arguments to a function defined in another file, are now reported without a clj-kondo cache
      • The console log and reports now show clj-kondo's warnings count, and its errors count when errors are found, instead of a single error for any failing run
      • clj-kondo now runs with --cache false: it no longer writes into your repository's .clj-kondo/.cache folder during the run, and no longer reads a cache built beforehand. To use such a cache, for example one built with --dependencies, set CLOJURE_CLJ_KONDO_COMMAND_REMOVE_ARGUMENTS: ["--cache", "false"]
      • To lint each file separately as before, set CLOJURE_CLJ_KONDO_CLI_LINT_MODE: file
  • Fixes

    • CLOJURE_CLJ_KONDO now really forwards EXCLUDED_DIRECTORIES and ADDITIONAL_EXCLUDED_DIRECTORIES in project lint mode: they were never applied before, so files in folders like node_modules or .wireit could be reported
      • The directories are passed as a merged :output {:exclude-files [...]} inline configuration, so your own :output :exclude-files patterns in .clj-kondo/config.edn are kept
      • Disable the forwarding with CLOJURE_CLJ_KONDO_FORWARD_EXCLUDED_DIRECTORIES: false
  • Reporters

  • Flavors

  • Doc

  • mega-linter-runner

    • --container-engine container: run MegaLinter with Apple's native macOS container engine (Apple Silicon only, no Docker Desktop needed): https://github.com/apple/container
  • Agent Skills

    • megalinter-fix now explains how to fix clj-kondo :type-mismatch and :constant-condition findings, and the difference between the top-level :exclude-files and :output :exclude-files clj-kondo settings

... (truncated)

Commits
  • 9949bad Release MegaLinter v10.1.0
  • 4270990 fix release workflow
  • 4d8bf14 [automation] Auto-update linters version, help and documentation (#8902)
  • 98bcce2 fix(ci): install zensical in the auto-update linters container (#8901)
  • b63dee7 fix(deps): update langchain (minor) (#8878)
  • 4d17aee fix(renovate-rebase): force UTF-8 console output in tick_dashboard (#8900)
  • b034be4 Disable the unmaintained graphql-schema-linter (#8894)
  • e00d096 chore(deps): update dependency snakemake to v9.26.1 (#8897)
  • 9591933 chore(deps): update dependency langsmith to v0.11.2 (#8896)
  • e87989e chore(deps): update dependency golangci/golangci-lint to v2.13.2 (#8895)
  • Additional commits viewable in compare view

Updates github/codeql-action/upload-sarif from 4.37.9 to 4.38.2

Release notes

Sourced from github/codeql-action/upload-sarif's releases.

v4.38.2

  • Update default CodeQL bundle version to 2.27.1. #4160

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

v4.38.0

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129
Changelog

Sourced from github/codeql-action/upload-sarif's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 2892aa5 Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f
  • 8ad03a3 Trigger workflows
  • 98af865 Update changelog for v4.38.2
  • a6ef2c9 Merge pull request #4156 from github/mario-campos/fix-validate-cmd
  • 1ef28a1 Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...
  • 26cb08b Merge pull request #4163 from github/mbg/fix-getCommitOid-stubs
  • f035ce3 Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...
  • 5e4e255 Rebuild
  • b13f5f4 Bump ruby/setup-ruby
  • c87fe57 Rebuild
  • Additional commits viewable in compare view

Updates reviewdog/action-suggester from 1.24.3 to 1.26.1

Release notes

Sourced from reviewdog/action-suggester's releases.

Release v1.26.1

What's Changed

Full Changelog: reviewdog/action-suggester@v1.26.0...v1.26.1

Release v1.26.0

What's Changed

Full Changelog: reviewdog/action-suggester@v1.25.0...v1.26.0

Release v1.25.0

What's Changed

Full Changelog: reviewdog/action-suggester@v1.24.3...v1.25.0

Commits
  • c387862 Merge pull request #137 from reviewdog/fix-path-input-does-not-work
  • 8d62657 Merge pull request #139 from reviewdog/renovate/reviewdog-action-shellcheck-1.x
  • f15af1b Merge pull request #138 from reviewdog/renovate/reviewdog-action-misspell-1.x
  • 67b551b update README.md to add the path input
  • 32f7902 chore(deps): update reviewdog/action-shellcheck action to v1.34.0
  • ce32542 chore(deps): update reviewdog/action-misspell action to v1.30.0
  • f1cc1db fix path input doesn't work. close #132
  • a435ab6 Merge pull request #136 from reviewdog/renovate/reviewdog-action-alex-1.x
  • 62fe6f1 Merge pull request #135 from reviewdog/renovate/reviewdog-action-actionlint-1.x
  • adef167 chore(deps): update reviewdog/action-alex action to v1.19.0
  • Additional commits viewable in compare view

Updates docker/setup-buildx-action from 4.3.0 to 4.4.1

Release notes

Sourced from docker/setup-buildx-action's releases.

v4.4.1

Full Changelog: docker/setup-buildx-action@v4.4.0...v4.4.1

v4.4.0

Full Changelog: docker/setup-buildx-action@v4.3.0...v4.4.0

Commits
  • f87e599 Merge pull request #624 from crazy-max/skip-pull-with-endpoint
  • e700274 chore: update generated content
  • 3061c91 skip BuildKit image pre-pulls for explicit endpoints
  • 594f3bf Merge pull request #609 from crazy-max/pull-buildkit-image-before-create
  • bd6e702 chore: update generated content
  • 6268c9d pull BuildKit image before builder creation
  • e823525 Merge pull request #621 from docker/dependabot/github_actions/codeql-actions-...
  • 533ed8e build(deps): bump the codeql-actions group with 2 updates
  • bedaf13 Merge pull request #620 from crazy-max/shared-error-helpers
  • d5079fb chore: update generated content
  • Additional commits viewable in compare view

Updates docker/build-push-action from 7.3.0 to 7.4.0

Release notes

Sourced from docker/build-push-action's releases.

v7.4.0

Full Changelog: docker/build-push-action@v7.3.0...v7.4.0

Commits
  • c3c9e26 Merge pull request #1621 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 459b674 [dependabot skip] chore: update generated content
  • 4dedcb2 chore(deps): Bump @​docker/actions-toolkit from 0.99.0 to 0.100.0
  • 379bf63 Merge pull request #1620 from crazy-max/buildx-error-message
  • 9877975 chore: update generated content
  • 7ed0556 use the shared Buildx error summary helper
  • 91670ba Merge pull request #1618 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 80dbc86 [dependabot skip] chore: update generated content
  • 50cac3a chore(deps): Bump @​docker/actions-toolkit from 0.98.0 to 0.99.0
  • 03b4d6c Merge pull request #1617 from crazy-max/fix-metadata-workflow-commands
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) | `0.6.3` | `0.6.4` |
| [oxsecurity/megalinter/flavors/dotnet](https://github.com/oxsecurity/megalinter) | `10.0.0` | `10.1.0` |
| [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.9` | `4.38.2` |
| [reviewdog/action-suggester](https://github.com/reviewdog/action-suggester) | `1.24.3` | `1.26.1` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.3.0` | `4.4.1` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.3.0` | `7.4.0` |


Updates `zizmorcore/zizmor-action` from 0.6.3 to 0.6.4
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@70fb788...cc914d7)

Updates `oxsecurity/megalinter/flavors/dotnet` from 10.0.0 to 10.1.0
- [Release notes](https://github.com/oxsecurity/megalinter/releases)
- [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md)
- [Commits](oxsecurity/megalinter@15e5b45...9949bad)

Updates `github/codeql-action/upload-sarif` from 4.37.9 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@cdf488f...2892aa5)

Updates `reviewdog/action-suggester` from 1.24.3 to 1.26.1
- [Release notes](https://github.com/reviewdog/action-suggester/releases)
- [Commits](reviewdog/action-suggester@2558ba1...c387862)

Updates `docker/setup-buildx-action` from 4.3.0 to 4.4.1
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@37fe631...f87e599)

Updates `docker/build-push-action` from 7.3.0 to 7.4.0
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@53b7df9...c3c9e26)

---
updated-dependencies:
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: oxsecurity/megalinter/flavors/dotnet
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: reviewdog/action-suggester
  dependency-version: 1.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: docker/build-push-action
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

❌MegaLinter analysis: Error

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ ACTION actionlint 24 0 0 0.47s
⚠️ ACTION zizmor 24 0 0 1 3.89s
✅ DOCKERFILE hadolint 3 0 0 0.42s
✅ JSON npm-package-json-lint yes no no 0.59s
✅ JSON prettier 22 3 0 0 2.56s
✅ JSON v8r 22 0 0 10.46s
✅ MARKDOWN markdownlint 12 0 0 0 1.47s
✅ MARKDOWN markdown-table-formatter 12 1 0 0 0.3s
✅ REPOSITORY betterleaks yes no no 1.2s
✅ REPOSITORY checkov yes no no 22.85s
✅ REPOSITORY git_diff yes no no 0.04s
❌ REPOSITORY grype yes 2 1 101.79s
❌ REPOSITORY osv-scanner yes 1 9 3.96s
✅ REPOSITORY secretlint yes no no 1.47s
✅ REPOSITORY syft yes no no 6.08s
❌ REPOSITORY trivy yes 2 1 12.86s
✅ REPOSITORY trivy-sbom yes no no 0.49s
✅ REPOSITORY trufflehog yes no no 3.54s
⚠️ SPELL lychee 86 1 0 10.42s
✅ YAML prettier 32 0 0 0 1.17s
✅ YAML v8r 32 0 0 11.01s
✅ YAML yamllint 32 0 0 1.27s

Detailed Issues

❌ REPOSITORY / grype - 2 errors
error: A high vulnerability in python package: urllib3, version 2.7.0 was found at: /.devcontainer/cpp/requirements.txt

error: A high vulnerability in python package: urllib3, version 2.7.0 was found at: /.devcontainer/cpp/requirements.txt

warning: A medium vulnerability in python package: urllib3, version 2.7.0 was found at: /.devcontainer/cpp/requirements.txt

warning: 1 warnings emitted
error: 2 errors emitted
❌ REPOSITORY / osv-scanner - 1 error
e the target server's `ssl_context` for the proxy TLS handshake. The proxy may therefore be verified using the target server's trust and certificate policy instead of the policy explicitly configured for the proxy.
   
   ### 2. The target verification policy overrides the proxy policy
   
   An HTTPS proxy is configured with `proxy_ssl_context`, while the target server uses a different certificate-verification policy.
   
   urllib3 may apply the target server's `cert_reqs` value to the proxy SSL context. For example, setting `cert_reqs="CERT_NONE"` for the target server may also disable certificate verification for the HTTPS proxy, even when `proxy_ssl_context` was configured to require verification.
   
   This issue can affect the TLS connection to an HTTPS proxy in both forwarding and CONNECT tunneling configurations.
   
   ### 3. A mutated proxy SSL context is reused
   
   The same SSL context is reused as `proxy_ssl_context` across multiple connections, and certificate verification is disabled for one target server.
   
   urllib3 may modify the proxy SSL context's `verify_mode` in place. Later connections that reuse the same context may therefore connect to the HTTPS proxy without certificate verification.
   
   ### 4. Target-specific TLS identity or credentials are applied to the proxy
   
   HTTPS requests are forwarded through an HTTPS proxy with `use_forwarding_for_https=True`, and target-specific SNI, hostname assertions, certificate fingerprint assertions, or TLS client credentials are configured.
   
   urllib3 may apply these target-specific settings to the proxy TLS handshake. This may cause urllib3 to:
   
   - send SNI intended for the target server to the proxy;
   - verify the proxy using a hostname or certificate fingerprint intended for the target server; or
   - present a TLS client certificate intended for the target server to the proxy.
   
   Code connecting through a plain HTTP proxy does not establish a TLS connection to the proxy and is not affected by this issue.
   
   ## Remediation
   
   Upgrade to urllib3 2.8.0 or later.
   
   urllib3 2.8.0 independently applies the explicitly configured `proxy_ssl_context` and proxy-specific certificate assertions to the HTTPS proxy connection. Target-specific SNI, certificate assertions, and TLS client certificate parameters are no longer applied to the HTTPS proxy handshake.
   
   For backward compatibility, when an HTTPS proxy is used with `use_forwarding_for_https=True` and `proxy_ssl_context` is not provided, urllib3 2.8.0 continues to use `ssl_context` for the TLS connection to the proxy. This configuration emits a `FutureWarning`. In urllib3 3.0, passing `ssl_context` with `use_forwarding_for_https=True` for an HTTPS proxy will raise an error. Applications should use `proxy_ssl_context` to configure TLS for an HTTPS forwarding proxy.
   
   The fixes were implemented in commits b6447295fff7b38fdffc67e0df9712d60cef3cc3 and 07408cec79d1856d81bb42c74a904a24fdb9e465.

warning: Package 'urllib3@2.7.0' is vulnerable to 'CVE-2026-97688' (also known as 'PYSEC-2026-4176', 'GHSA-gh4c-6fx4-qh6g').
 = CVE-2026-97688: urllib3: Chunked Deflate streaming can enter an infinite loop
 = ### Impact
   
   urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading content in chunks instead of loading the entire response body into memory at once.
   
   urllib3 can decompress response bodies according to the HTTP `Content-Encoding` header. When streaming a compressed, chunked response, urllib3 first consumes data already buffered by the decoder before reading the next HTTP chunk.
   
   However, urllib3 versions from 2.6.2 through 2.7.0 could enter an infinite loop when a chunked response contained bytes after the end of the Deflate stream. If the decompressed body exceeded the requested streaming chunk size, Python's zlib implementation could retain the trailing bytes as unconsumed input after reaching the end of the compressed stream. urllib3 would repeatedly attempt to decode those same bytes without making progress or reading more data from the network.
   
   A malicious server could exploit this behavior to cause excessive CPU usage and prevent the affected request from completing on the client. Network read timeouts would not interrupt the loop because no further socket operation was required.
   
   ### Affected usages
   
   Applications and libraries using urllib3 versions 2.6.2 through 2.7.0 may be affected when all of the following conditions are met:
   
   1. Compressed responses from an untrusted source are streamed using `HTTPResponse.stream(amt=N)` or `HTTPResponse.read_chunked(amt=N)` with a positive, finite chunk size.
   2. Content decoding is enabled.
   3. The response uses both `Transfer-Encoding: chunked` and `Content-Encoding: deflate`.
   4. The decoded body exceeds the requested chunk size and the encoded body contains bytes after the end of the Deflate stream.
   
   `HTTPResponse.stream()` uses a finite chunk size by default and is therefore affected when the other conditions are met.
   
   ### Remediation
   
   Upgrade to urllib3 2.8.0, in which the Deflate decoder stops accepting input after reaching the end of the compressed stream and no longer reports trailing bytes as data that can produce more decoded output.
   
   If upgrading is not immediately possible, disable automatic content decoding for responses from untrusted sources by setting `decode_content=False`, or reject streamed responses using the Deflate content encoding. Applications that disable automatic decoding must handle the compressed response safely at another layer.

warning: Package 'urllib3@2.7.0' is vulnerable to 'CVE-2026-97689' (also known as 'PYSEC-2026-4177', 'GHSA-vxq7-64xx-v4gw').
 = CVE-2026-97689: urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
 = ## Impact
   
   urllib3's [streaming API](https://urllib3.readthedocs.io/en/2.7.0/advanced-usage.html#streaming-and-i-o) is designed for efficiently handling large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When decoding a [chunked-transfer-encoded response](https://httpwg.org/specs/rfc9112.html#chunked.encoding), this API reads each chunk's size field by buffering until it sees `\n` or EOF.
   
   A malicious HTTP server can return `Transfer-Encoding: chunked` and then send a very long run of bytes without any newline, causing the streaming client to buffer that entire run before urllib3 can reject the chunk size as invalid and allocate more memory than intended.
   
   To fix the issue, we'll reject chunk-size fields larger than 65536 bytes, as already done in the non-streaming case, which is currently handled by the Python standard library. Note that this only applies to reading the chunk-size field, not the chunk data, which is already handled correctly. Thus, there shouldn't be any impact for non-malicious servers.
   
   ## Affected usages
   
   Applications and libraries using urllib3 versions earlier than 2.8.0 may be affected when streaming a chunked response from untrusted sources. Specifically, this affects the [read_chunked()](https://urllib3.readthedocs.io/en/stable/reference/urllib3.response.html#urllib3.response.BaseHTTPResponse.read_chunked) and [stream()](https://urllib3.readthedocs.io/en/stable/reference/urllib3.response.html#urllib3.response.BaseHTTPResponse.stream) methods of the HTTPResponse object.
   
   This also affects requests streaming API, which uses urllib3 under the hood.
   
   ## Remediation
   
   Upgrade to urllib3 version 2.8.0 or later, where chunk-size fields larger than 65536 will be rejected. If upgrading is not immediately possible, consider reading the response at once using the [read()](https://urllib3.readthedocs.io/en/stable/reference/urllib3.response.html#urllib3.response.BaseHTTPResponse.read) method.

warning: 9 warnings emitted

(Truncated to last 8000 characters out of 33211)
❌ REPOSITORY / trivy - 2 errors
error: Package: urllib3
Installed Version: 2.7.0
Vulnerability CVE-2026-97687
Severity: HIGH
Fixed Version: 2.8.0
Link: [CVE-2026-97687](https://avd.aquasec.com/nvd/cve-2026-97687)
    ┌─ .devcontainer/cpp/requirements.txt:518:1
    │
518 │ urllib3==2.7.0 \
    │ ^
    │
    = urllib3: urllib3: Traffic interception via HTTPS proxy TLS configuration override
    = urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0.

error: Package: urllib3
Installed Version: 2.7.0
Vulnerability CVE-2026-97689
Severity: HIGH
Fixed Version: 2.8.0
Link: [CVE-2026-97689](https://avd.aquasec.com/nvd/cve-2026-97689)
    ┌─ .devcontainer/cpp/requirements.txt:518:1
    │
518 │ urllib3==2.7.0 \
    │ ^
    │
    = urllib3: urllib3: Denial of Service via unbounded memory allocation in chunk parser
    = urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.

warning: Package: urllib3
Installed Version: 2.7.0
Vulnerability CVE-2026-97688
Severity: MEDIUM
Fixed Version: 2.8.0
Link: [CVE-2026-97688](https://avd.aquasec.com/nvd/cve-2026-97688)
    ┌─ .devcontainer/cpp/requirements.txt:518:1
    │
518 │ urllib3==2.7.0 \
    │ ^
    │
    = urllib3: urllib3: Denial of Service via infinite loop during chunked Deflate decoding
    = urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.

warning: 1 warnings emitted
error: 2 errors emitted
⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total..........133
🔗 Unique.........112
✅ Successful.....127
⏳ Timeouts.........0
🔀 Redirected......13
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1

Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 30:7) | Rejected status code: 403 Forbidden

Hint: Followed 13 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ ACTION / zizmor - 1 warning
INFO zizmor: 🌈 zizmor v1.25.0
 WARN audit: zizmor: one or more inputs contains YAML anchors; see https://docs.zizmor.sh/usage/#yaml-anchors for details
 INFO audit: zizmor: 🌈 completed .github/workflows/build-push-test.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/continuous-integration.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/image-cleanup.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/issue-cleanup.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/issue-creation-tool-versions.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/linting-formatting.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/ossf-scorecard.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/pr-conventional-title.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/pr-image-cleanup.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/pr-report.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/release-build.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/release-please.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/update-dependencies.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/vulnerability-scan.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/wc-acceptance-test.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/wc-build-push-test.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/wc-build-push.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/wc-dependency-review.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/wc-document-generation.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/wc-integration-test-docker.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/wc-integration-test-podman.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/wc-integration-test.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/wc-publish-templates.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/wc-sanitize-image-name.yml
{
  "$schema": "https://docs.oasis-open.org/sarif/sarif/v2.1.0/os/schemas/sarif-schema-2.1.0.json",
  "runs": [
    {
      "invocations": [
        {
          "executionSuccessful": true
        }
      ],
      "results": [],
      "tool": {
        "driver": {
          "downloadUri": "https://github.com/zizmorcore/zizmor",
          "informationUri": "https://docs.zizmor.sh",
          "name": "zizmor",
          "rules": [],
          "semanticVersion": "1.25.0",
          "version": "1.25.0"
        }
      }
    }
  ],
  "version": "2.1.0"
No fixes available to apply.
}

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_KICS. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,ACTION_ZIZMOR,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant