ci: bump oxsecurity/megalinter from 8 to 9 - #22
Closed
dependabot[bot] wants to merge 1 commit into
Closed
Conversation
Bumps [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) from 8 to 9. - [Release notes](https://github.com/oxsecurity/megalinter/releases) - [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md) - [Commits](oxsecurity/megalinter@v8...v9) --- updated-dependencies: - dependency-name: oxsecurity/megalinter dependency-version: '9' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
✅
|
| Descriptor | Linter | Files | Fixed | Errors | Warnings | Elapsed time |
|---|---|---|---|---|---|---|
| ✅ ACTION | actionlint | 5 | 0 | 0 | 0.27s | |
| zizmor | 5 | 0 | 1 | 0 | 0.27s | |
| jscpd | yes | 1 | no | 0.23s | ||
| stylelint | 1 | 1 | 38 | 0 | 2.47s | |
| djlint | 1 | 2 | 0 | 1.0s | ||
| htmlhint | 1 | 1 | 0 | 0.22s | ||
| ✅ JSON | jsonlint | 4 | 0 | 0 | 0.13s | |
| ✅ JSON | npm-package-json-lint | yes | no | no | 0.69s | |
| ✅ JSON | prettier | 4 | 1 | 0 | 0 | 0.68s |
| ✅ JSON | v8r | 4 | 0 | 0 | 9.45s | |
| ✅ MARKDOWN | markdownlint | 5 | 2 | 0 | 0 | 0.63s |
| ✅ MARKDOWN | markdown-table-formatter | 5 | 2 | 0 | 0 | 0.27s |
| ✅ REPOSITORY | betterleaks | yes | no | no | 0.87s | |
| checkov | yes | 1 | no | 20.81s | ||
| devskim | yes | 1 | no | 1.6s | ||
| ✅ REPOSITORY | dustilock | yes | no | no | 0.11s | |
| ✅ REPOSITORY | gitleaks | yes | no | no | 0.36s | |
| ✅ REPOSITORY | git_diff | yes | no | no | 0.01s | |
| grype | yes | 12 | no | 64.2s | ||
| kingfisher | yes | 1 | no | 8.23s | ||
| osv-scanner | yes | 12 | no | 1.09s | ||
| ✅ REPOSITORY | secretlint | yes | no | no | 0.68s | |
| ✅ REPOSITORY | syft | yes | no | no | 2.78s | |
| trivy | yes | 1 | no | 11.22s | ||
| ✅ REPOSITORY | trivy-sbom | yes | no | no | 6.79s | |
| ✅ REPOSITORY | trufflehog | yes | no | no | 4.21s | |
| cspell | 30 | 333 | 0 | 12.13s | ||
| lychee | 20 | 49 | 0 | 1.73s | ||
| ts-standard | 1 | 0 | 1 | 0 | 4.14s | |
| ✅ YAML | prettier | 10 | 4 | 0 | 0 | 1.24s |
| v8r | 10 | 1 | 0 | 7.58s | ||
| ✅ YAML | yamllint | 10 | 0 | 0 | 1.65s |
Detailed Issues
⚠️ REPOSITORY / checkov - 1 error
github_actions scan results:
Passed checks: 115, Failed checks: 1, Skipped checks: 0
Check: CKV2_GHA_1: "Ensure top-level permissions are not set to write-all"
FAILED for resource: on(CI)
File: /.github/workflows/ci.yml:0-1
⚠️ SPELL / cspell - 333 errors
t/**",
"**/.pnpm-lock.json",
".vscode",
"package-lock.json",
"megalinter-reports"
],
"words": [
"Aion",
"Cerebras",
"Chirag",
"DPDP",
"Datasheet",
"Firestore",
"Groq",
"Hashnode",
"Klaro",
"MOBI",
"MSIX",
"Markua",
"Ollama",
"Oriz",
"Pandoc",
"Pollinations",
"SARIF",
"Singhal",
"Tauri",
"Wordmark",
"anymatch",
"argparse",
"arrayish",
"astrojs",
"axobject",
"boolbase",
"bottombar",
"browserify",
"capsizecss",
"ccount",
"chirag",
"chokidar",
"cliui",
"clsx",
"colour",
"commonmark",
"crossws",
"csso",
"defu",
"dequal",
"destr",
"devlop",
"domelementtype",
"domhandler",
"domutils",
"dset",
"eabi",
"emmetio",
"emnapi",
"esbuild",
"estree",
"eventemitter",
"fdir",
"fontace",
"fontkitten",
"fontsource",
"fsevents",
"fullwidth",
"gnueabihf",
"hastscript",
"ioredis",
"jiti",
"jridgewell",
"keyval",
"kleur",
"languageservice",
"lede",
"libc",
"libvips",
"lightningcss",
"linuxmusl",
"loong",
"magicast",
"mergify",
"micromark",
"mrmime",
"msvc",
"musleabihf",
"neotraverse",
"nlcst",
"obug",
"ofetch",
"ohash",
"openharmony",
"oriz",
"oslojs",
"ossf",
"piccolore",
"picocolors",
"picomatch",
"planetscale",
"pluginutils",
"prismjs",
"readdirp",
"rehype",
"riscv",
"rollup",
"sarif",
"shiki",
"shikijs",
"sisteransi",
"smol",
"strikethrough",
"subtokenize",
"sugarss",
"sunos",
"tagfilter",
"tinyclip",
"tinyexec",
"tinyglobby",
"twoslash",
"typesafe",
"ultrahtml",
"uncrypto",
"undici",
"ungap",
"unifont",
"uploadthing",
"vercel",
"vite",
"vitefu",
"webcrypto",
"wordmark",
"xxhash",
"yargs",
"yocto",
"zwitch"
]
}
You can also copy-paste megalinter-reports/.cspell.json at the root of your repository
(Truncated to last 2666 characters out of 48741)
⚠️ REPOSITORY / devskim - 1 error
{"$schema":"https://schemastore.azurewebsites.net/schemas/json/sarif-2.1.0-rtm.6.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"devskim","fullName":"Microsoft DevSkim Command Line Interface","version":"1.0.70+d69541fde7","informationUri":"https://github.com/microsoft/DevSkim/","rules":[{"id":"DS126858","name":"WeakbrokenHashAlgorithm","fullDescription":{"text":"Weak/Broken Hash Algorithm: A weak or broken hash algorithm was detected."},"help":{"text":"Consider switching to use SHA-256 or SHA-512 instead.","markdown":"Consider switching to use SHA-256 or SHA-512 instead. Visit [https://github.com/Microsoft/DevSkim/blob/main/guidance/DS126858.md](https://github.com/Microsoft/DevSkim/blob/main/guidance/DS126858.md) for additional guidance on this issue."},"shortDescription":{"text":"A weak or broken hash algorithm was detected."},"defaultConfiguration":{"level":"error"},"helpUri":"https://github.com/Microsoft/DevSkim/blob/main/guidance/DS126858.md","properties":{"precision":"high","problem.severity":"error","DevSkimSeverity":"Critical","DevSkimConfidence":"High"}}]}},"versionControlProvenance":[{"repositoryUri":"https://github.com/chirag127/packages","revisionId":"HIDDEN_BY_MEGALINTER","branch":"(no branch)"}],"results":[{"ruleId":"DS126858","level":"error","message":{"text":"Weak/Broken Hash Algorithm"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"pnpm-lock.yaml"},"region":{"startLine":2269,"startColumn":98,"endLine":2269,"endColumn":101,"charOffset":65253,"charLength":3,"snippet":{"text":"mD4","rendered":{"text":"mD4","markdown":"`mD4`"}},"sourceLanguage":"yaml"}}}],"fixes":[],"properties":{"tags":["Cryptography.BannedHashAlgorithm"],"DevSkimSeverity":"Critical","DevSkimConfidence":"High"}}],"columnKind":"utf16CodeUnits"}]}
⚠️ HTML / djlint - 2 errors
::warning file=docs/index.html,line=2::H025 Tag seems to be an orphan.
::warning file=docs/index.html,line=16::H025 Tag seems to be an orphan.
⚠️ REPOSITORY / grype - 12 errors
[0000] WARN no explicit name and version provided for directory source, deriving artifact ID from the given path (which is not ideal) from=syft
NAME INSTALLED FIXED IN TYPE VULNERABILITY SEVERITY EPSS RISK
js-yaml 4.2.0 4.3.0 npm GHSA-52cp-r559-cp3m High 0.4% (34th) 0.3
fast-uri 3.1.2 3.1.3 npm GHSA-4c8g-83qw-93j6 High 0.4% (31st) 0.3
yaml 2.7.1 2.8.3 npm GHSA-48c2-rrv3-qjmp Medium 0.5% (38th) 0.2
fast-uri 3.1.2 3.1.4 npm GHSA-v2hh-gcrm-f6hx High 0.2% (12th) 0.2
astro 6.4.8 7.0.6 npm GHSA-f48w-9m4c-m7f5 Medium 0.3% (25th) 0.2
astro 6.4.8 7.0.4 npm GHSA-7pw4-f3q4-r2p2 Low 0.3% (23rd) < 0.1
postcss 8.5.15 8.5.18 npm GHSA-r28c-9q8g-f849 High N/A N/A
sharp 0.33.5 0.35.0 npm GHSA-f88m-g3jw-g9cj High N/A N/A
sharp 0.34.5 0.35.0 npm GHSA-f88m-g3jw-g9cj High N/A N/A
svgo 4.0.1 4.0.2 npm GHSA-2p49-hgcm-8545 High N/A N/A
astro 6.4.8 7.1.0 npm GHSA-4g3v-8h47-v7g6 Medium N/A N/A
esbuild 0.27.7 0.28.1 npm GHSA-g7r4-m6w7-qqqr Low N/A N/A
[0064] ERROR discovered vulnerabilities at or above the severity threshold
⚠️ HTML / htmlhint - 1 error
Config loaded: /action/lib/.automation/.htmlhintrc
docs/index.html
L21 |</div>
^ Tag must be paired, missing: [ </body></html> ], open tag match failed [ <body> ] on line 16. (tag-pair)
Scanned 1 files, found 1 errors in 1 files (28 ms)
⚠️ COPYPASTE / jscpd - 1 error
Using config from /action/lib/.automation/.jscpd.json
Clone found (javascript)
- src/components/Layout.astro:javascript [74:13 - 81:12] (8 lines, 62 tokens)
src/components/Layout.astro:javascript [83:11 - 90:10]
┌────────────┬────────────────┬─────────────┬──────────────┬──────────────┬──────────────────┬───────────────────┐
│ Format │ Files analyzed │ Total lines │ Total tokens │ Clones found │ Duplicated lines │ Duplicated tokens │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ astro │ 2 │ 252 │ 1421 │ 0 │ 0 (0.00%) │ 0 (0.00%) │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ css │ 2 │ 686 │ 5369 │ 0 │ 0 (0.00%) │ 0 (0.00%) │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ html │ 2 │ 254 │ 543 │ 0 │ 0 (0.00%) │ 0 (0.00%) │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ javascript │ 3 │ 392 │ 1584 │ 1 │ 7 (1.79%) │ 62 (3.91%) │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ typescript │ 3 │ 100 │ 412 │ 0 │ 0 (0.00%) │ 0 (0.00%) │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ Total: │ 12 │ 1684 │ 9329 │ 1 │ 7 (0.42%) │ 62 (0.66%) │
└────────────┴────────────────┴─────────────┴──────────────┴──────────────┴──────────────────┴───────────────────┘
Found 1 clones.
HTML report saved to megalinter-reports/copy-paste/jscpd-report.html
ERROR: jscpd found too many duplicates (0.4%) over threshold (0.0%)
time: 68.597ms
⚠️ REPOSITORY / kingfisher - 1 error
New Kingfisher release 1.110.0 available
INFO kingfisher: Launching with 8 concurrent scan jobs. Use --num-jobs to override.
INFO kingfisher::rule_loader: Loaded 925 rules
INFO kingfisher::scanner::runner: Using Vectorscan rule cache cache_dir=/github/home/.cache/kingfisher/rule-cache
INFO kingfisher::scanner::runner: Starting secret validation phase...
GITHUB APP SERVER-TO-SERVER TOKEN (STATELESS JWT FORMAT) => [KINGFISHER.GITHUB.9]
|Finding.......: [REDACTED:e73b50a6]
|Encoding......: base64
|Fingerprint...: 9984828794684434326
|Confidence....: medium
|Entropy.......: 5.68
|Validation....: Inactive Credential
|__Response....: {
"message": "Resource not accessible by integration",
"documentation_url": "https://docs.github.com/rest/users/users#get-the-authenticated-user",
"status": "403"
}
|Language......: Unknown
|Line Num......: 12
|Path..........: ./.git/config
JSON WEB TOKEN (BASE64URL-ENCODED) => [KINGFISHER.JWT.1]
|Finding.......: [REDACTED:35304fd1]
|Encoding......: base64
|Fingerprint...: 12025323425531822005
|Confidence....: medium
|Entropy.......: 5.65
|Validation....: Inactive Credential
|__Response....: no kid in header
|Language......: Unknown
|Line Num......: 12
|Path..........: ./.git/config
==========================================
Scan Summary:
==========================================
|Findings....................: 2
|__Successful Validations....: 0
|__Failed Validations........: 2
|__Skipped Validations.......: 0
|Rules Applied...............: 925
|__Blobs Scanned.............: 137
|Bytes Scanned...............: 869.99 KiB
|Scan Duration...............: 278ms 674us 436ns
|Scan Date...................: 2026-08-02 21:49:03 +00:00
|Kingfisher Version..........: 1.104.0
|__Latest Version............: 1.110.0
New Kingfisher release 1.110.0 available
⚠️ SPELL / lychee - 49 errors
www.npmjs.com/package/@chirag127/astro-data (at 64:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/astro-distribute (at 79:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/astro-forms (at 94:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/astro-pwa (at 109:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/astro-shell (at 124:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/astro-test-utils (at 139:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/astro-tools (at 154:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/astro-widgets (at 169:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/auth-cli (at 184:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/auth-core (at 199:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/auth-vsc (at 214:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/auth-wxt (at 229:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/omni-publish (at 244:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/oriz-ai-providers (at 259:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/oriz-analytics (at 274:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/oriz-book-build (at 289:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/oriz-consent (at 304:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/oriz-rate-limit (at 319:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/oriz-seo (at 334:18) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@chirag127/oriz-ui (at 349:18) | Rejected status code: 403 Forbidden
Errors in knowledge/index.md
[ERROR] file:///knowledge (at 10:32) | File not found. Check if file exists and path is correct
Errors in README.md
[404] https://github.com/chirag127/packages/stargazers (at 5:1) | Rejected status code: 404 Not Found
Hint: Followed 1 redirect. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
(Truncated to last 2666 characters out of 5834)
⚠️ REPOSITORY / osv-scanner - 12 errors
Scanning dir .
Starting filesystem walk for root: /
Scanned pnpm-lock.yaml file and found 433 packages
End status: 57 dirs visited, 177 inodes visited, 1 Extract calls, 21.984517ms elapsed, 21.984607ms wall time
Total 9 packages affected by 12 known vulnerabilities (0 Critical, 7 High, 3 Medium, 2 Low, 0 Unknown) from 1 ecosystem.
12 vulnerabilities can be fixed.
+-------------------------------------+------+-----------+----------+---------+---------------+----------------+
| OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE |
+-------------------------------------+------+-----------+----------+---------+---------------+----------------+
| https://osv.dev/GHSA-4g3v-8h47-v7g6 | 5.3 | npm | astro | 6.4.8 | 7.1.0 | pnpm-lock.yaml |
| https://osv.dev/GHSA-7pw4-f3q4-r2p2 | 2.1 | npm | astro | 6.4.8 | 7.0.4 | pnpm-lock.yaml |
| https://osv.dev/GHSA-f48w-9m4c-m7f5 | 5.1 | npm | astro | 6.4.8 | 7.0.6 | pnpm-lock.yaml |
| https://osv.dev/GHSA-g7r4-m6w7-qqqr | 2.5 | npm | esbuild | 0.27.7 | 0.28.1 | pnpm-lock.yaml |
| https://osv.dev/GHSA-4c8g-83qw-93j6 | 7.5 | npm | fast-uri | 3.1.2 | 3.1.3 | pnpm-lock.yaml |
| https://osv.dev/GHSA-v2hh-gcrm-f6hx | 7.5 | npm | fast-uri | 3.1.2 | 3.1.4 | pnpm-lock.yaml |
| https://osv.dev/GHSA-52cp-r559-cp3m | 7.5 | npm | js-yaml | 4.2.0 | 4.3.0 | pnpm-lock.yaml |
| https://osv.dev/GHSA-r28c-9q8g-f849 | 7.5 | npm | postcss | 8.5.15 | 8.5.18 | pnpm-lock.yaml |
| https://osv.dev/GHSA-f88m-g3jw-g9cj | 7.0 | npm | sharp | 0.33.5 | 0.35.0 | pnpm-lock.yaml |
| https://osv.dev/GHSA-f88m-g3jw-g9cj | 7.0 | npm | sharp | 0.34.5 | 0.35.0 | pnpm-lock.yaml |
| https://osv.dev/GHSA-2p49-hgcm-8545 | 8.2 | npm | svgo | 4.0.1 | 4.0.2 | pnpm-lock.yaml |
| https://osv.dev/GHSA-48c2-rrv3-qjmp | 4.3 | npm | yaml | 2.7.1 | 2.8.3 | pnpm-lock.yaml |
+-------------------------------------+------+-----------+----------+---------+---------------+----------------+
⚠️ CSS / stylelint - 38 errors
claration-block-single-line-max-declarations
304:1 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
333:18 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
362:6 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
363:7 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
364:8 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
377:17 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
384:1 ✖ Expected selector ".card-links a" to come before selector ".nav a:hover", at line 143 no-descending-specificity
425:15 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
431:1 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
457:16 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
459:1 ✖ Expected selector ".footer-col a" to come before selector ".nav a:hover", at line 143 no-descending-specificity
459:15 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
460:21 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
461:13 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
464:17 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
482:1 ✖ Expected selector ".bottombar a" to come before selector ".nav a:hover", at line 143 no-descending-specificity
493:41 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
494:16 ✖ Too many declarations, maximum 1 declaration-block-single-line-max-declarations
✖ 38 problems (38 errors, 0 warnings)
(Truncated to last 2666 characters out of 5541)
⚠️ REPOSITORY / trivy - 1 error
│ │ 8.5.15 │ 8.5.18 │ PostCSS: Path Traversal in Previous Source Map Auto-Loading │
│ │ │ │ │ │ │ (sourceMappingURL) leads to Arbitrary... │
│ │ │ │ │ │ │ https://github.com/advisories/GHSA-r28c-9q8g-f849 │
├─────────┼─────────────────────┤ │ ├───────────────────┼─────────────────────┼──────────────────────────────────────────────────────────────┤
│ sharp │ GHSA-f88m-g3jw-g9cj │ │ │ 0.33.5 │ 0.35.0 │ sharp inherited vulnerabilities in libvips: CVE-2026-33327, │
│ │ │ │ │ │ │ CVE-2026-33328, CVE-2026-35590, CVE-2026-35591 │
│ │ │ │ │ │ │ https://github.com/advisories/GHSA-f88m-g3jw-g9cj │
│ │ │ │ ├───────────────────┤ │ │
│ │ │ │ │ 0.34.5 │ │ │
│ │ │ │ │ │ │ │
│ │ │ │ │ │ │ │
├─────────┼─────────────────────┤ │ ├───────────────────┼─────────────────────┼──────────────────────────────────────────────────────────────┤
│ svgo │ GHSA-2p49-hgcm-8545 │ │ │ 4.0.1 │ 2.8.3, 3.3.4, 4.0.2 │ SVGO removeScripts plugin leaves some executable scripts │
│ │ │ │ │ │ │ intact │
│ │ │ │ │ │ │ https://github.com/advisories/GHSA-2p49-hgcm-8545 │
└─────────┴─────────────────────┴──────────┴────────┴───────────────────┴─────────────────────┴──────────────────────────────────────────────────────────────┘
📣 Notices:
- Version 0.72.0 of Trivy is now available, current version is 0.71.2
To suppress version checks, run Trivy scans with the --skip-version-check flag
(Truncated to last 2666 characters out of 11660)
⚠️ TYPESCRIPT / ts-standard - 1 error
ts-standard: Standard for TypeScript! (https://github.com/standard/ts-standard)
src/lib/data.ts:0:0: Parsing error: File 'astro/tsconfigs/strict' not found. (null)
⚠️ YAML / v8r - 1 error
✖ .github/FUNDING.yml is invalid
.github/FUNDING.yml#/thanks_dev must match pattern "^u/gh/.+$"
⚠️ ACTION / zizmor - 1 error
INFO zizmor: 🌈 zizmor v1.25.0
fatal: no audit was performed
'ref-confusion' audit failed on file://.github/workflows/ci.yml
Caused by:
0: error in 'ref-confusion' audit
1: couldn't list branches for actions/checkout
2: request error while accessing GitHub API
3: HTTP status client error (401 Unauthorized) for url (https://github.com/actions/checkout.git/git-upload-pack)
[ACTION_ZIZMOR_ERROR_GITHUB_API_UNREACHABLE] Zizmor could not access a repository referenced by a `uses:` clause via the GitHub API (missing token, insufficient scope, or cross-repo private access).
To allow zizmor to authenticate with GITHUB_TOKEN (or a PAT with `Contents: read-only`), whitelist the variable in your .mega-linter.yml:
ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES:
- GITHUB_TOKEN
If the referenced workflow is in a private repo outside the current one, provide a PAT with cross-repo access instead of the default GITHUB_TOKEN, or run zizmor in offline mode.
Notices
📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)
See detailed reports in MegaLinter artifacts

Show us your support by starring ⭐ the repository
Author
|
Superseded by #24. |
dependabot
Bot
deleted the
dependabot/github_actions/oxsecurity/megalinter-9
branch
August 12, 2026 19:20
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps oxsecurity/megalinter from 8 to 9.
Release notes
Sourced from oxsecurity/megalinter's releases.
... (truncated)
Changelog
Sourced from oxsecurity/megalinter's changelog.
... (truncated)
Commits
ef3e84bRelease MegaLinter v9.6.08b9259bSkill prepare-release (#8245)5810155chore(deps): bump pymdown-extensions from 10.21.3 to 11.0 in /.config/python/...aca415cchore(deps): update dependency semver to v7.8.5 (#8198)2d8b274Remove max-parallel for linterse9ab3e9chore(ci): manual run of deploy linters beta job (#8242)a8a6368Changelog (#8241)7f363c6[automation] Auto-update linters version, help and documentation (#8215)bce5232chore(deps): update ghcr.io/astral-sh/uv docker tag to v0.11.25 (#8232)9d98266chore(deps): update dependency realm/swiftlint to v0.65.0 (#8240)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)