chore(deps): bump oxsecurity/megalinter from 8 to 10 - #3
Open
dependabot[bot] wants to merge 1 commit into
Open
Conversation
Bumps [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) from 8 to 10. - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@v8...v10) --- updated-dependencies: - dependency-name: oxsecurity/megalinter dependency-version: '10' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
✅
|
| Descriptor | Linter | Files | Fixed | Errors | Max errors | Warnings | Elapsed time |
|---|---|---|---|---|---|---|---|
| ✅ ACTION | actionlint | 1 | 0 | 0 | 0.01s | ||
| zizmor | 1 | 0 | 1 | 0 | 0.47s | ||
| bash-exec | 4 | 4 | 0 | 0.03s | |||
| shellcheck | 4 | 3 | 0 | 0.26s | |||
| ✅ BASH | shfmt | 4 | 4 | 0 | 0 | 0.04s | |
| ✅ COPYPASTE | jscpd | yes | no | no | 0.83s | ||
| jsonlint | 2 | 1 | 0 | 0.12s | |||
| prettier | 2 | 0 | 1 | 0 | 0.29s | ||
| ✅ JSON | v8r | 2 | 0 | 0 | 1.45s | ||
| markdownlint | 13 | 6 | 12 | 0 | 1.11s | ||
| ✅ MARKDOWN | markdown-table-formatter | 13 | 11 | 0 | 0 | 0.25s | |
| ✅ REPOSITORY | betterleaks | yes | no | no | 0.72s | ||
| ✅ REPOSITORY | checkov | yes | no | no | 21.24s | ||
| devskim | yes | 1 | 1 | 2.42s | |||
| ✅ REPOSITORY | dustilock | yes | no | no | 0.01s | ||
| ✅ REPOSITORY | git_diff | yes | no | no | 0.01s | ||
| ✅ REPOSITORY | grype | yes | no | no | 67.02s | ||
| ✅ REPOSITORY | kingfisher | yes | no | no | 20.96s | ||
| ✅ REPOSITORY | osv-scanner | yes | no | no | 0.22s | ||
| secretlint | yes | 1 | no | 1.52s | |||
| ✅ REPOSITORY | syft | yes | no | no | 1.72s | ||
| ✅ REPOSITORY | trivy | yes | no | no | 11.56s | ||
| ✅ REPOSITORY | trivy-sbom | yes | no | no | 0.28s | ||
| ✅ REPOSITORY | trufflehog | yes | no | no | 3.77s | ||
| cspell | 31 | 264 | 0 | 14.81s | |||
| lychee | 19 | 23 | 0 | 19.8s | |||
| ✅ YAML | prettier | 4 | 1 | 0 | 0 | 0.33s | |
| ✅ YAML | v8r | 4 | 0 | 0 | 4.71s | ||
| ✅ YAML | yamllint | 4 | 0 | 0 | 0.45s |
Detailed Issues
⚠️ BASH / bash-exec - 4 errors
Results of bash-exec linter (version 5.3.9)
See documentation on https://megalinter.io/10.0.0/descriptors/bash_bash_exec/
-----------------------------------------------
❌ [ERROR] scripts/build-mcpb.sh
Error: File:[scripts/build-mcpb.sh] is not executable
❌ [ERROR] scripts/release-all.sh
Error: File:[scripts/release-all.sh] is not executable
❌ [ERROR] scripts/rotate-tokens.sh
Error: File:[scripts/rotate-tokens.sh] is not executable
❌ [ERROR] scripts/setup-secrets.sh
Error: File:[scripts/setup-secrets.sh] is not executable
⚠️ SPELL / cspell - 264 errors
- Unknown word (ENVPACT) -- needs the consumer's `ENVPACT_VAULT_TOKEN` set on
Suggestions: [ENACT, EPACT, ENRAPT, EVICT, EXPAT]
TOOLING.md:10:12 - Unknown word (lockfiles) -- from stale lockfiles.
Suggestions: [lockfile, loadfiles, loadFiles, Loadfiles, LoadFiles]
TOOLING.md:28:13 - Unknown word (fflate) -- one bug (`fflate` was a transitive of
Suggestions: [fate, flat, flake, flame, flare]
TOOLING.md:28:56 - Unknown word (mcpb) -- transitive of `@anthropic-ai/mcpb`,
Suggestions: [pcb, maps, mcap, mchp, merb]
TOOLING.md:54:27 - Unknown word (footguns) -- catches supply-chain footguns at install time.
Suggestions: [foots, flotus, foetus, foot's, footers]
TOOLING.md:60:3 - Unknown word (envpact) -- | envpact-mcp | esbuild |
Suggestions: [enact, epact, enrapt, evict, expat]
TOOLING.md:61:3 - Unknown word (envpact) -- | envpact-mcp/worker | workerd
Suggestions: [enact, epact, enrapt, evict, expat]
TOOLING.md:61:24 - Unknown word (workerd) -- envpact-mcp/worker | workerd, esbuild, sharp |
Suggestions: [worked, worker, workers, worded, wormed]
TOOLING.md:62:3 - Unknown word (envpact) -- | envpact-vscode | @vscode/vsce
Suggestions: [enact, epact, enrapt, evict, expat]
TOOLING.md:62:48 - Unknown word (keytar) -- vsce-sign, esbuild, keytar |
Suggestions: [katar, kantar, kelter, kevlar, keyman]
TOOLING.md:63:3 - Unknown word (envpact) -- | envpact-dashboard | esbuild
Suggestions: [enact, epact, enrapt, evict, expat]
TOOLING.md:64:3 - Unknown word (envpact) -- | envpact-action | (none — pure
Suggestions: [enact, epact, enrapt, evict, expat]
TOOLING.md:127:34 - Unknown word (stdlib) -- cli | (zero deps; node stdlib only) | node --test
Suggestions: [tslib, stdin, stdio, styli, stalin]
TOOLING.md:128:27 - Unknown word (mcpb) -- envpact-mcp | esbuild → mcpb pack | scripts/test
Suggestions: [pcb, maps, mcap, mchp, merb]
TOOLING.md:133:34 - Unknown word (pytest) -- Python) | hatchling | pytest |
Suggestions: [pest, pates, prest, pyres, pyxes]
TOOLING.md:164:21 - Unknown word (mcpb) -- - envpact-mcp build-mcpb.yml → attaches `.mcpb
Suggestions: [pcb, maps, mcap, mchp, merb]
TOOLING.md:164:43 - Unknown word (mcpb) -- mcpb.yml → attaches `.mcpb` to the GitHub Release
Suggestions: [pcb, maps, mcap, mchp, merb]
CSpell: Files checked: 31, Issues found: 264 in 26 files.
You can skip this misspellings by defining the following .cspell.json file at the root of your repository
Of course, please correct real typos before :)
{
"version": "0.2",
"language": "en",
"ignorePaths": [
"**/node_modules/**",
"**/vscode-extension/**",
"**/.git/**",
"**/.pnpm-lock.json",
".vscode",
"package-lock.json",
"megalinter-reports"
],
"words": [
"Behaviour",
"Chirag",
"EEXISTS",
"ENVPACT",
"Kolkata",
"OVSX",
"Singhal",
"Streamable",
"Synthesise",
"Theia",
"USERPROFILE",
"Winget",
"Yubi",
"bbwe",
"callees",
"chirag",
"ciphertext",
"cmdline",
"envpact",
"envpact's",
"envrc",
"esbuild",
"excludesfile",
"fflate",
"footguns",
"getpid",
"gitdir",
"greppable",
"htmlcov",
"keytar",
"libsodium",
"lockfiles",
"mcpb",
"modelcontextprotocol",
"myapp",
"mypy",
"newhost",
"oriz",
"pathlib",
"pycache",
"pypi",
"pyproject",
"pytest",
"rstrip",
"specialise",
"stdlib",
"stty",
"summarised",
"syncignore",
"venv",
"wekyb",
"workerd",
"worktrees"
]
}
You can also copy-paste megalinter-reports/.cspell.json at the root of your repository
(Truncated to last 4000 characters out of 40036)
⚠️ REPOSITORY / devskim - 1 error
{"$schema":"https://schemastore.azurewebsites.net/schemas/json/sarif-2.1.0-rtm.6.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"devskim","fullName":"Microsoft DevSkim Command Line Interface","version":"1.0.70+d69541fde7","informationUri":"https://github.com/microsoft/DevSkim/","rules":[{"id":"DS137138","name":"InsecureUrl","fullDescription":{"text":"Insecure URL: An HTTP-based URL without TLS was detected."},"help":{"text":"Update to an HTTPS-based URL if possible.","markdown":"Update to an HTTPS-based URL if possible. Visit [https://github.com/Microsoft/DevSkim/blob/main/guidance/DS137138.md](https://github.com/Microsoft/DevSkim/blob/main/guidance/DS137138.md) for additional guidance on this issue."},"shortDescription":{"text":"An HTTP-based URL without TLS was detected."},"helpUri":"https://github.com/Microsoft/DevSkim/blob/main/guidance/DS137138.md","properties":{"precision":"high","problem.severity":"warning","DevSkimSeverity":"Moderate","DevSkimConfidence":"High"},"defaultConfiguration":{"level":"warning"}}]}},"versionControlProvenance":[{"repositoryUri":"https://github.com/chirag127/envpact","revisionId":"b115c6a61c43b76beecd1a12cf618b23677a1a6f","branch":"(no branch)"}],"results":[{"ruleId":"DS137138","message":{"text":"Insecure URL"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"_build/specs/v2.schema.json"},"region":{"startLine":5,"startColumn":14,"endLine":5,"endColumn":36,"charOffset":170,"charLength":22,"snippet":{"text":"http://json-schema.org","rendered":{"text":"http://json-schema.org","markdown":"`http://json-schema.org`"}},"sourceLanguage":"json"}}}],"fixes":[{"description":{"text":"An HTTP-based URL without TLS was detected."},"artifactChanges":[{"artifactLocation":{"uri":"_build/specs/v2.schema.json"},"replacements":[{"deletedRegion":{"charOffset":170,"charLength":22},"insertedContent":{"text":"https://json-schema.org"}}]}]}],"properties":{"tags":["ThreatModel.Integration.HTTP"],"DevSkimSeverity":"Moderate","DevSkimConfidence":"High"},"level":"warning"}],"columnKind":"utf16CodeUnits"}]}
⚠️ JSON / jsonlint - 1 error
File: _build/specs/v2.schema.json
Parse error on line 1, column 1:
# JSON Schema for en...
^
Unexpected token "#"
⚠️ SPELL / lychee - 23 errors
📝 Summary
---------------------
🔍 Total...........91
🔗 Unique..........66
✅ Successful......66
⏳ Timeouts.........0
🔀 Redirected......12
👻 Excluded.........2
❓ Unknown..........0
🚫 Errors..........23
⛔ Unsupported.....23
Errors in CONTRIBUTING.md
[ERROR] file://envpact-cli/CONTRIBUTING.md (at 7:3) | File not found. Check if file exists and path is correct
[ERROR] file://envpact-mcp/CONTRIBUTING.md (at 8:3) | File not found. Check if file exists and path is correct
[ERROR] file://envpact-python/CONTRIBUTING.md (at 9:3) | File not found. Check if file exists and path is correct
Errors in docs/index.md
[ERROR] file://docs/architecture.html (at 107:23) | File not found. Check if file exists and path is correct
[ERROR] file://docs/architecture.html (at 113:5) | File not found. Check if file exists and path is correct
[ERROR] file://docs/environments.html (at 115:5) | File not found. Check if file exists and path is correct
[ERROR] file://docs/schema.html (at 114:5) | File not found. Check if file exists and path is correct
[ERROR] file://docs/security.html (at 116:5) | File not found. Check if file exists and path is correct
[ERROR] file://docs/security.html (at 61:37) | File not found. Check if file exists and path is correct
[404] https://github.com/chirag127/envpact-python (at 76:3) | Rejected status code: 404 Not Found
Errors in README.md
[ERROR] file://envpact-mcp/SMITHERY.md (at 39:20) | File not found. Check if file exists and path is correct
[ERROR] file://envpact-mcp/worker/README.md (at 38:3) | File not found. Check if file exists and path is correct
[ERROR] file://envpact-python (at 64:23) | File not found. Check if file exists and path is correct
[ERROR] https://mcp.envpact.oriz.in/mcp (at 36:29) | Connection failed. Check network connectivity and firewall settings
[ERROR] https://mcp.envpact.oriz.in/mcp (at 63:199) | Connection failed. Check network connectivity and firewall settings
[500] https://smithery.ai/badge/envpact (at 10:2) | Rejected status code: 500 Internal Server Error
[403] https://www.npmjs.com/package/envpact-cli (at 5:1) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/envpact-mcp (at 6:1) | Rejected status code: 403 Forbidden
Errors in TOKENS.md
[403] https://dash.cloudflare.com/ (at 118:15) | Rejected status code: 403 Forbidden
[403] https://dash.cloudflare.com/ (at 167:4) | Rejected status code: 403 Forbidden
[403] https://dash.cloudflare.com/?to=/:account/pages/view/envpact-dashboard/domains (at 172:4) | Rejected status code: 403 Forbidden
[403] https://dash.cloudflare.com/profile/api-tokens (at 122:6) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/ (at 29:15) | Rejected status code: 403 Forbidden
Hint: Followed 12 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ MARKDOWN / markdownlint - 12 errors
_build/specs/SHARED_SPEC.md:242 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
_build/specs/SHARED_SPEC.md:258 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
_build/specs/SHARED_SPEC.md:374 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
_build/specs/SHARED_SPEC.md:406 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
_build/specs/SHARED_SPEC.md:433 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
AGENTS.md:19:401 error MD013/line-length Line length [Expected: 400; Actual: 444]
AGENTS.md:30:401 error MD013/line-length Line length [Expected: 400; Actual: 513]
CLAUDE.md:1 error MD041/first-line-heading/first-line-h1 First line in a file should be a top-level heading [Context: "@AGENTS.md"]
CONTRIBUTING.md:13 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
docs/architecture.md:15 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
docs/index.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "envpact"]
README.md:106 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
⚠️ JSON / prettier - 1 error
_build/specs/MCP_TOOLS.json 74ms (unchanged)
[error] _build/specs/v2.schema.json: SyntaxError: Unexpected token (1:1)
[error] > 1 | # JSON Schema for envpact secrets.json (v2)
[error] | ^
[error] 2 | # Hosted at https://envpact.oriz.in/schema/v2.json
[error] 3 | # (mirror it from envpact-dashboard/public/schema/v2.json)
[error] 4 | {
⚠️ REPOSITORY / secretlint - 1 error
TOKENS.md
38:5 error [NPM_ACCESS_TOKEN] found npm access token: **************************************** @secretlint/secretlint-rule-preset-recommend > @secretlint/secretlint-rule-npm
✖ 1 problem (1 error, 0 warnings, 0 infos)
⚠️ BASH / shellcheck - 3 errors
In scripts/setup-secrets.sh line 120:
echo "$CLOUDFLARE_ACCOUNT_ID" | gh secret set CLOUDFLARE_ACCOUNT_ID --repo "chirag127/$REPO_DASHBOARD" >/dev/null 2>&1 &&
^-- SC2015 (info): Note that A && B || C is not if-then-else. C may run when A is true.
In scripts/setup-secrets.sh line 125:
echo "$CLOUDFLARE_API_TOKEN" | gh secret set CLOUDFLARE_API_TOKEN --repo "chirag127/$REPO_DASHBOARD" >/dev/null 2>&1 &&
^-- SC2015 (info): Note that A && B || C is not if-then-else. C may run when A is true.
In scripts/setup-secrets.sh line 136:
echo "$GH_OAUTH_ID" | gh secret set PUBLIC_GITHUB_OAUTH_CLIENT_ID --repo "chirag127/$REPO_DASHBOARD" >/dev/null 2>&1 &&
^-- SC2015 (info): Note that A && B || C is not if-then-else. C may run when A is true.
For more information:
https://www.shellcheck.net/wiki/SC2015 -- Note that A && B || C is not if-t...
⚠️ ACTION / zizmor - 1 error
INFO zizmor: 🌈 zizmor v1.25.0
fatal: no audit was performed
'ref-confusion' audit failed on file://.github/workflows/megalinter.yml
Caused by:
0: error in 'ref-confusion' audit
1: couldn't list branches for actions/checkout
2: request error while accessing GitHub API
3: HTTP status client error (401 Unauthorized) for url (https://github.com/actions/checkout.git/git-upload-pack)
[ACTION_ZIZMOR_ERROR_GITHUB_API_UNREACHABLE] Zizmor could not access a repository referenced by a `uses:` clause via the GitHub API (missing token, insufficient scope, or cross-repo private access).
To allow zizmor to authenticate with GITHUB_TOKEN (or a PAT with `Contents: read-only`), whitelist the variable in your .mega-linter.yml:
ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES:
- GITHUB_TOKEN
If the referenced workflow is in a private repo outside the current one, provide a PAT with cross-repo access instead of the default GITHUB_TOKEN, or run zizmor in offline mode.
See detailed reports in MegaLinter artifacts

Show us your support by starring ⭐ the repository
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps oxsecurity/megalinter from 8 to 10.
Release notes
Sourced from oxsecurity/megalinter's releases.
... (truncated)
Changelog
Sourced from oxsecurity/megalinter's changelog.
... (truncated)
Commits
15e5b45Release MegaLinter v10.0.0861855amegalinter-setup skill: enforce ghcr.io image references in upgrade mode (#8694)572dc81[automation] Auto-update linters version, help and documentation (#8695)2f62977Refresh OX Security PR comment banner and home page banner (#8692)3b8c632chore(deps): update dependency mongodb/kingfisher to v1.112.0 (#8691)7efac01chore(deps): update mstruebing/editorconfig-checker docker tag to v3.10.0 (#8...8cea326Make custom flavor generator output pass MegaLinter (#8686)a057dcb[automation] Auto-update linters version, help and documentation (#8690)6dece72chore(deps): update dependency virtualenv to v21.7.2 (#8683)08a6d16docs: highlight impactful contributors in the Special thanks section (#8688)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)