Skip to content

Commit 3e132b1

Browse files
committed
Release MegaLinter v9.5.0
1 parent cbb7fe9 commit 3e132b1

192 files changed

Lines changed: 3360 additions & 3167 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎README.md‎

Lines changed: 21 additions & 21 deletions
Large diffs are not rendered by default.

‎action.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ outputs:
88
description: "0 if no source file has been updated, 1 if source files has been updated"
99
runs:
1010
using: "docker"
11-
image: "docker://ghcr.io/oxsecurity/megalinter:v9.4.0"
11+
image: "docker://ghcr.io/oxsecurity/megalinter:v9.5.0"
1212
args:
1313
- "-v"
1414
- "/var/run/docker.sock:/var/run/docker.sock:rw"

‎docs/config-apply-fixes.md‎

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,14 +21,23 @@ Only for the GitHub Actions workflow file, if you use it:
2121

2222
You may see GitHub permission errors, or workflows not running on the new commit.
2323

24+
> **Security warning — Personal Access Tokens (PAT) are NOT recommended.**
25+
> Open-source projects have been heavily targeted by supply-chain attacks in recent months, and a leaked or compromised PAT can give attackers broad write access to your repository — better safe than sorry!
26+
> Before adding a `PAT` secret, ask yourself if you really need workflows to re-trigger automatically after MegaLinter pushes a fix commit. In most cases the simpler and safer workaround is enough:
27+
>
28+
> - **Manually re-run the failed workflow** from the GitHub Actions tab, or
29+
> - **Push another commit** on the branch (even an empty one: `git commit --allow-empty -m "trigger CI"`) so GitHub re-runs the workflows.
30+
>
31+
> Only set up a PAT if you fully understand the trade-off. If you do, use a **fine-grained token scoped to a single repository** with the **minimum required permissions**, and rotate it regularly.
32+
2433
To solve these issues, apply one of the following solutions.
2534

26-
- Method 1: The most secured
35+
- Method 1: The most secured (still discouraged — read the warning above)
2736
- [Create a Fine-Grained Personal Access Token](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/creating-a-personal-access-token#creating-a-fine-grained-personal-access-token), scoped only to your repository and with **Contents: Read/Write**, then copy the PAT value
2837
- [Define environment secret variable](https://docs.github.com/en/actions/security-guides/encrypted-secrets#creating-encrypted-secrets-for-an-environment) named **PAT** on your repository, and paste the PAT value
2938
- Update your GitHub Actions workflow to add the environment name
3039

31-
-- Method 2: Easier, but any contributor with write access can see your Personal Access Token, so use it only on private repositories.
40+
-- Method 2: Easier, but **strongly discouraged** — any contributor with write access can see your Personal Access Token, so use it only on private repositories.
3241
- [Create a Classic Personal Access Token](https://docs.github.com/en/free-pro-team@latest/github/authenticating-to-github/creating-a-personal-access-token#creating-a-token), then copy the PAT value
3342
- [Define secret variable](https://docs.github.com/en/free-pro-team@latest/actions/reference/encrypted-secrets#creating-encrypted-secrets-for-a-repository) named **PAT** on your repository, and paste the PAT value
3443

‎docs/descriptors/action_actionlint.md‎

Lines changed: 20 additions & 20 deletions
Large diffs are not rendered by default.

‎docs/descriptors/action_zizmor.md‎

Lines changed: 21 additions & 21 deletions
Large diffs are not rendered by default.

‎docs/descriptors/ansible_ansible_lint.md‎

Lines changed: 21 additions & 21 deletions
Large diffs are not rendered by default.

‎docs/descriptors/api_spectral.md‎

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -42,8 +42,8 @@ Spectral helps ensure your API specifications follow best practices and maintain
4242

4343
## Configuration in MegaLinter
4444

45-
- Enable spectral by adding `API_SPECTRAL` in [ENABLE_LINTERS variable](https://megalinter.io/beta/configuration/#activation-and-deactivation)
46-
- Disable spectral by adding `API_SPECTRAL` in [DISABLE_LINTERS variable](https://megalinter.io/beta/configuration/#activation-and-deactivation)
45+
- Enable spectral by adding `API_SPECTRAL` in [ENABLE_LINTERS variable](https://megalinter.io/9.5.0/configuration/#activation-and-deactivation)
46+
- Disable spectral by adding `API_SPECTRAL` in [DISABLE_LINTERS variable](https://megalinter.io/9.5.0/configuration/#activation-and-deactivation)
4747

4848
| Variable | Description | Default value |
4949
|------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------|
@@ -76,9 +76,9 @@ Use spectral in your favorite IDE to catch errors before MegaLinter !
7676

7777
This linter is available in the following flavors
7878

79-
| <!-- --> | Flavor | Description | Embedded linters | Info |
80-
|:--------------------------------------------------------------------------------------------------------------------------------------------------------:|:-----------------------------------------------------|:--------------------------|:----------------:|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------:|
81-
| <img src="https://github.com/oxsecurity/megalinter/raw/main/docs/assets/images/mega-linter-square.png" alt="" height="32px" class="megalinter-icon"></a> | [all](https://megalinter.io/beta/supported-linters/) | Default MegaLinter Flavor | 136 | ![Docker Image Size (tag)](https://img.shields.io/docker/image-size/oxsecurity/megalinter/beta) ![Docker Pulls](https://img.shields.io/docker/pulls/oxsecurity/megalinter) |
79+
| <!-- --> | Flavor | Description | Embedded linters | Info |
80+
|:--------------------------------------------------------------------------------------------------------------------------------------------------------:|:------------------------------------------------------|:--------------------------|:----------------:|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------:|
81+
| <img src="https://github.com/oxsecurity/megalinter/raw/main/docs/assets/images/mega-linter-square.png" alt="" height="32px" class="megalinter-icon"></a> | [all](https://megalinter.io/9.5.0/supported-linters/) | Default MegaLinter Flavor | 136 | ![Docker Image Size (tag)](https://img.shields.io/docker/image-size/oxsecurity/megalinter/v9.5.0) ![Docker Pulls](https://img.shields.io/docker/pulls/oxsecurity/megalinter) |
8282

8383
## Behind the scenes
8484

‎docs/descriptors/arm_arm_ttk.md‎

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -32,8 +32,8 @@ ARM TTK helps ensure your ARM templates are secure, maintainable, and follow Azu
3232

3333
## Configuration in MegaLinter
3434

35-
- Enable arm-ttk by adding `ARM_ARM_TTK` in [ENABLE_LINTERS variable](https://megalinter.io/beta/configuration/#activation-and-deactivation)
36-
- Disable arm-ttk by adding `ARM_ARM_TTK` in [DISABLE_LINTERS variable](https://megalinter.io/beta/configuration/#activation-and-deactivation)
35+
- Enable arm-ttk by adding `ARM_ARM_TTK` in [ENABLE_LINTERS variable](https://megalinter.io/9.5.0/configuration/#activation-and-deactivation)
36+
- Disable arm-ttk by adding `ARM_ARM_TTK` in [DISABLE_LINTERS variable](https://megalinter.io/9.5.0/configuration/#activation-and-deactivation)
3737

3838
| Variable | Description | Default value |
3939
|-----------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------|
@@ -65,11 +65,11 @@ Use arm-ttk in your favorite IDE to catch errors before MegaLinter !
6565

6666
This linter is available in the following flavors
6767

68-
| <!-- --> | Flavor | Description | Embedded linters | Info |
69-
|:--------------------------------------------------------------------------------------------------------------------------------------------------------:|:-----------------------------------------------------------|:---------------------------------------------------------|:----------------:|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------:|
70-
| <img src="https://github.com/oxsecurity/megalinter/raw/main/docs/assets/images/mega-linter-square.png" alt="" height="32px" class="megalinter-icon"></a> | [all](https://megalinter.io/beta/supported-linters/) | Default MegaLinter Flavor | 136 | ![Docker Image Size (tag)](https://img.shields.io/docker/image-size/oxsecurity/megalinter/beta) ![Docker Pulls](https://img.shields.io/docker/pulls/oxsecurity/megalinter) |
71-
| <img src="https://github.com/oxsecurity/megalinter/raw/main/docs/assets/icons/dotnet.ico" alt="" height="32px" class="megalinter-icon"></a> | [dotnet](https://megalinter.io/beta/flavors/dotnet/) | Optimized for C, C++, C# or VB based projects | 67 | ![Docker Image Size (tag)](https://img.shields.io/docker/image-size/oxsecurity/megalinter-dotnet/beta) ![Docker Pulls](https://img.shields.io/docker/pulls/oxsecurity/megalinter-dotnet) |
72-
| <img src="https://github.com/oxsecurity/megalinter/raw/main/docs/assets/icons/dotnetweb.ico" alt="" height="32px" class="megalinter-icon"></a> | [dotnetweb](https://megalinter.io/beta/flavors/dotnetweb/) | Optimized for C, C++, C# or VB based projects with JS/TS | 76 | ![Docker Image Size (tag)](https://img.shields.io/docker/image-size/oxsecurity/megalinter-dotnetweb/beta) ![Docker Pulls](https://img.shields.io/docker/pulls/oxsecurity/megalinter-dotnetweb) |
68+
| <!-- --> | Flavor | Description | Embedded linters | Info |
69+
|:--------------------------------------------------------------------------------------------------------------------------------------------------------:|:------------------------------------------------------------|:---------------------------------------------------------|:----------------:|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------:|
70+
| <img src="https://github.com/oxsecurity/megalinter/raw/main/docs/assets/images/mega-linter-square.png" alt="" height="32px" class="megalinter-icon"></a> | [all](https://megalinter.io/9.5.0/supported-linters/) | Default MegaLinter Flavor | 136 | ![Docker Image Size (tag)](https://img.shields.io/docker/image-size/oxsecurity/megalinter/v9.5.0) ![Docker Pulls](https://img.shields.io/docker/pulls/oxsecurity/megalinter) |
71+
| <img src="https://github.com/oxsecurity/megalinter/raw/main/docs/assets/icons/dotnet.ico" alt="" height="32px" class="megalinter-icon"></a> | [dotnet](https://megalinter.io/9.5.0/flavors/dotnet/) | Optimized for C, C++, C# or VB based projects | 67 | ![Docker Image Size (tag)](https://img.shields.io/docker/image-size/oxsecurity/megalinter-dotnet/v9.5.0) ![Docker Pulls](https://img.shields.io/docker/pulls/oxsecurity/megalinter-dotnet) |
72+
| <img src="https://github.com/oxsecurity/megalinter/raw/main/docs/assets/icons/dotnetweb.ico" alt="" height="32px" class="megalinter-icon"></a> | [dotnetweb](https://megalinter.io/9.5.0/flavors/dotnetweb/) | Optimized for C, C++, C# or VB based projects with JS/TS | 76 | ![Docker Image Size (tag)](https://img.shields.io/docker/image-size/oxsecurity/megalinter-dotnetweb/v9.5.0) ![Docker Pulls](https://img.shields.io/docker/pulls/oxsecurity/megalinter-dotnetweb) |
7373

7474
## Behind the scenes
7575

0 commit comments

Comments
 (0)