chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0 - #5916

Merged
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0
May 19, 2026
Merged

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0#5916
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubMay 19, 2026

Copy link
Copy Markdown
Contributor

Bumps oxsecurity/megalinter from 9.4.0 to 9.5.0.

Release notes

Sourced from oxsecurity/megalinter's releases.

v9.5.0

What's Changed

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

... (truncated)

Changelog

Sourced from oxsecurity/megalinter's changelog.

[v9.5.0] - 2026-05-16

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

    • Console output: linters now show their log sections (not only on errors), the results table and reporter logs are printed after linters complete, and parallel-run logs are no longer interleaved

... (truncated)

Commits
  • 0e3ce9b Fix release workflows.
  • 3e132b1 Release MegaLinter v9.5.0
  • cbb7fe9 Doc + prepare 9.5.0 release (#7836)
  • 29bcf10 [automation] Auto-update linters version, help and documentation (#7832)
  • ed753c5 chore(deps): update jdkato/vale docker tag to v3.14.2 (#7829)
  • e04f202 feat: implement user notifications system and replace migration warnings (#7833)
  • 54bfad8 chore(deps): update dependency @​stoplight/spectral-cli to v6.16.0 (#7830)
  • f809408 Eslint legacy detection & warning (#7831)
  • 6725b65 chore(deps): update dependency langsmith to v0.8.5 (#7828)
  • cbcc02f chore(deps): update dependency rumdl to v0.1.93 (#7825)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabotdependabotBot added dependencies github_actions Pull requests that update GitHub Actions code labels May 19, 2026
prql-bot
prql-bot previously approved these changes May 19, 2026

@prql-botprql-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MegaLinter v9.5.0 enables two new linters by default that did not run on v9.4.0:

  • ACTION_ZIZMOR (GitHub Actions security audit, v1.25.0)
  • REPOSITORY_OSV_SCANNER (vulnerability scanner, v2.3.8)

Both fail on this PR — see run 26073032632:

  • zizmor: Zizmor failed to reach the GitHub API. — it needs GITHUB_TOKEN access to query the API for full audits. MegaLinter's own error message gives the fix:
    ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES:
    - GITHUB_TOKEN
  • osv-scanner: 22 known vulnerabilities across Cargo.lock, web/playground/package-lock.json, prqlc/bindings/js/package-lock.json, and prqlc/bindings/prqlc-python/uv.lock. Highlights: serialize-javascript 6.0.2 (GHSA-5c6j-r48x-rmvq, CVSS 8.1), rustls-webpki 0.101.7/0.103.9 (GHSA-82j2-j2ch-gfr8, CVSS 7.5), several dompurify 3.2.7 advisories. Most are fixable by version bumps Dependabot would normally produce.

The existing pattern in .mega-linter.yaml is to disable blocking vulnerability scanners (REPOSITORY_GRYPE comment: "Blocking unrelated PRs. We already have dependabot." — same applies to REPOSITORY_GITLEAKS, REPOSITORY_TRUFFLEHOG, REPOSITORY_KICS, REPOSITORY_KINGFISHER), and REPOSITORY_TRIVY is in DISABLE_ERRORS_LINTERS (warns, doesn't block). Two consistent options:

  1. Disable both in DISABLE_LINTERS — matches the GRYPE pattern, defers vuln scanning to Dependabot.
  2. Move to DISABLE_ERRORS_LINTERS — surfaces findings as warnings without blocking. For zizmor, also add the ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES: [GITHUB_TOKEN] snippet so it can actually run.

Happy to push either fix as a follow-up commit to this branch — let me know which you prefer.

@prql-bot
prql-bot dismissed their stale reviewMay 19, 2026 03:07

CI failed — megalinter v9.5.0 enabled new linters by default (zizmor, osv-scanner) that block on findings

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot Please push the fix for the two newly-failing MegaLinter v9.5 linters to this branch so CI goes green. Use option 1 from your review (disable ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS), since it matches the existing REPOSITORY_GRYPE pattern in .mega-linter.yaml ("we already have dependabot"). Rebase onto the latest main first if the branch is behind.

This was written by Claude Code on behalf of Maximilian Roos

@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from d9c14fc to 53a32ccCompareMay 19, 2026 16:58
@prql-bot

Copy link
Copy Markdown
Collaborator

Pushed 53a32cce — rebased onto main and disabled both ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS, with comments matching the GRYPE pattern. MegaLinter passed in 4m9s on the rebased commit.

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot You approved this but it's still red and unmerged, and there's no human author to act. Please push the fix to this branch: in .mega-linter.yaml, add ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER to DISABLE_LINTERS (matching the existing REPOSITORY_GRYPE "we already have dependabot" pattern). Rebase onto the latest main first, then push so CI goes green and this can merge.

This was written by Claude Code on behalf of Maximilian Roos

dependabotBotand others added 2 commits May 19, 2026 17:54
Bumps [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) from 9.4.0 to 9.5.0.
- [Release notes](https://github.com/oxsecurity/megalinter/releases)
- [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md)
- [Commits](oxsecurity/megalinter@v9.4.0...v9.5.0)
---
updated-dependencies:
- dependency-name: oxsecurity/megalinter
dependency-version: 9.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
MegaLinter v9.5.0 enables both by default. OSV scanner duplicates
Dependabot; zizmor needs GITHUB_TOKEN access to run. Disable both
to match the existing REPOSITORY_GRYPE pattern.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from 53a32cc to c3b4ae0CompareMay 19, 2026 17:54
@prql-bot

Copy link
Copy Markdown
Collaborator

Force-pushed c3b4ae00 — rebased onto current main (which had moved one commit forward since the prior rebase) with the same ACTION_ZIZMOR + REPOSITORY_OSV_SCANNER disable in .mega-linter.yaml. All required checks pass on the new commit (MegaLinter green in 4m43s).

mergeStateStatus shows BLOCKED, but that's the manual-merge gate, not CI — per the repo's tend config, the automerge job was removed in #5753, so bot PRs need a maintainer to land them.

@max-sixty
max-sixty merged commit b2dec67 into mainMay 19, 2026
41 checks passed
@max-sixty
max-sixty deleted the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch May 19, 2026 19:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesgithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@max-sixty@prql-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0 - #5916

Merged
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0
May 19, 2026
Merged

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0#5916
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubMay 19, 2026

Copy link
Copy Markdown
Contributor

Bumps oxsecurity/megalinter from 9.4.0 to 9.5.0.

Release notes

Sourced from oxsecurity/megalinter's releases.

v9.5.0

What's Changed

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

... (truncated)

Changelog

Sourced from oxsecurity/megalinter's changelog.

[v9.5.0] - 2026-05-16

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

    • Console output: linters now show their log sections (not only on errors), the results table and reporter logs are printed after linters complete, and parallel-run logs are no longer interleaved

... (truncated)

Commits
  • 0e3ce9b Fix release workflows.
  • 3e132b1 Release MegaLinter v9.5.0
  • cbb7fe9 Doc + prepare 9.5.0 release (#7836)
  • 29bcf10 [automation] Auto-update linters version, help and documentation (#7832)
  • ed753c5 chore(deps): update jdkato/vale docker tag to v3.14.2 (#7829)
  • e04f202 feat: implement user notifications system and replace migration warnings (#7833)
  • 54bfad8 chore(deps): update dependency @​stoplight/spectral-cli to v6.16.0 (#7830)
  • f809408 Eslint legacy detection & warning (#7831)
  • 6725b65 chore(deps): update dependency langsmith to v0.8.5 (#7828)
  • cbcc02f chore(deps): update dependency rumdl to v0.1.93 (#7825)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabotdependabotBot added dependencies github_actions Pull requests that update GitHub Actions code labels May 19, 2026
prql-bot
prql-bot previously approved these changes May 19, 2026

@prql-botprql-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MegaLinter v9.5.0 enables two new linters by default that did not run on v9.4.0:

  • ACTION_ZIZMOR (GitHub Actions security audit, v1.25.0)
  • REPOSITORY_OSV_SCANNER (vulnerability scanner, v2.3.8)

Both fail on this PR — see run 26073032632:

  • zizmor: Zizmor failed to reach the GitHub API. — it needs GITHUB_TOKEN access to query the API for full audits. MegaLinter's own error message gives the fix:
    ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES:
    - GITHUB_TOKEN
  • osv-scanner: 22 known vulnerabilities across Cargo.lock, web/playground/package-lock.json, prqlc/bindings/js/package-lock.json, and prqlc/bindings/prqlc-python/uv.lock. Highlights: serialize-javascript 6.0.2 (GHSA-5c6j-r48x-rmvq, CVSS 8.1), rustls-webpki 0.101.7/0.103.9 (GHSA-82j2-j2ch-gfr8, CVSS 7.5), several dompurify 3.2.7 advisories. Most are fixable by version bumps Dependabot would normally produce.

The existing pattern in .mega-linter.yaml is to disable blocking vulnerability scanners (REPOSITORY_GRYPE comment: "Blocking unrelated PRs. We already have dependabot." — same applies to REPOSITORY_GITLEAKS, REPOSITORY_TRUFFLEHOG, REPOSITORY_KICS, REPOSITORY_KINGFISHER), and REPOSITORY_TRIVY is in DISABLE_ERRORS_LINTERS (warns, doesn't block). Two consistent options:

  1. Disable both in DISABLE_LINTERS — matches the GRYPE pattern, defers vuln scanning to Dependabot.
  2. Move to DISABLE_ERRORS_LINTERS — surfaces findings as warnings without blocking. For zizmor, also add the ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES: [GITHUB_TOKEN] snippet so it can actually run.

Happy to push either fix as a follow-up commit to this branch — let me know which you prefer.

@prql-bot
prql-bot dismissed their stale reviewMay 19, 2026 03:07

CI failed — megalinter v9.5.0 enabled new linters by default (zizmor, osv-scanner) that block on findings

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot Please push the fix for the two newly-failing MegaLinter v9.5 linters to this branch so CI goes green. Use option 1 from your review (disable ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS), since it matches the existing REPOSITORY_GRYPE pattern in .mega-linter.yaml ("we already have dependabot"). Rebase onto the latest main first if the branch is behind.

This was written by Claude Code on behalf of Maximilian Roos

@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from d9c14fc to 53a32ccCompareMay 19, 2026 16:58
@prql-bot

Copy link
Copy Markdown
Collaborator

Pushed 53a32cce — rebased onto main and disabled both ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS, with comments matching the GRYPE pattern. MegaLinter passed in 4m9s on the rebased commit.

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot You approved this but it's still red and unmerged, and there's no human author to act. Please push the fix to this branch: in .mega-linter.yaml, add ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER to DISABLE_LINTERS (matching the existing REPOSITORY_GRYPE "we already have dependabot" pattern). Rebase onto the latest main first, then push so CI goes green and this can merge.

This was written by Claude Code on behalf of Maximilian Roos

dependabotBotand others added 2 commits May 19, 2026 17:54
Bumps [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) from 9.4.0 to 9.5.0.
- [Release notes](https://github.com/oxsecurity/megalinter/releases)
- [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md)
- [Commits](oxsecurity/megalinter@v9.4.0...v9.5.0)
---
updated-dependencies:
- dependency-name: oxsecurity/megalinter
dependency-version: 9.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
MegaLinter v9.5.0 enables both by default. OSV scanner duplicates
Dependabot; zizmor needs GITHUB_TOKEN access to run. Disable both
to match the existing REPOSITORY_GRYPE pattern.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from 53a32cc to c3b4ae0CompareMay 19, 2026 17:54
@prql-bot

Copy link
Copy Markdown
Collaborator

Force-pushed c3b4ae00 — rebased onto current main (which had moved one commit forward since the prior rebase) with the same ACTION_ZIZMOR + REPOSITORY_OSV_SCANNER disable in .mega-linter.yaml. All required checks pass on the new commit (MegaLinter green in 4m43s).

mergeStateStatus shows BLOCKED, but that's the manual-merge gate, not CI — per the repo's tend config, the automerge job was removed in #5753, so bot PRs need a maintainer to land them.

@max-sixty
max-sixty merged commit b2dec67 into mainMay 19, 2026
41 checks passed
@max-sixty
max-sixty deleted the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch May 19, 2026 19:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesgithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@max-sixty@prql-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0 - #5916

Merged
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0
May 19, 2026
Merged

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0#5916
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubMay 19, 2026

Copy link
Copy Markdown
Contributor

Bumps oxsecurity/megalinter from 9.4.0 to 9.5.0.

Release notes

Sourced from oxsecurity/megalinter's releases.

v9.5.0

What's Changed

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

... (truncated)

Changelog

Sourced from oxsecurity/megalinter's changelog.

[v9.5.0] - 2026-05-16

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

    • Console output: linters now show their log sections (not only on errors), the results table and reporter logs are printed after linters complete, and parallel-run logs are no longer interleaved

... (truncated)

Commits
  • 0e3ce9b Fix release workflows.
  • 3e132b1 Release MegaLinter v9.5.0
  • cbb7fe9 Doc + prepare 9.5.0 release (#7836)
  • 29bcf10 [automation] Auto-update linters version, help and documentation (#7832)
  • ed753c5 chore(deps): update jdkato/vale docker tag to v3.14.2 (#7829)
  • e04f202 feat: implement user notifications system and replace migration warnings (#7833)
  • 54bfad8 chore(deps): update dependency @​stoplight/spectral-cli to v6.16.0 (#7830)
  • f809408 Eslint legacy detection & warning (#7831)
  • 6725b65 chore(deps): update dependency langsmith to v0.8.5 (#7828)
  • cbcc02f chore(deps): update dependency rumdl to v0.1.93 (#7825)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabotdependabotBot added dependencies github_actions Pull requests that update GitHub Actions code labels May 19, 2026
prql-bot
prql-bot previously approved these changes May 19, 2026

@prql-botprql-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MegaLinter v9.5.0 enables two new linters by default that did not run on v9.4.0:

  • ACTION_ZIZMOR (GitHub Actions security audit, v1.25.0)
  • REPOSITORY_OSV_SCANNER (vulnerability scanner, v2.3.8)

Both fail on this PR — see run 26073032632:

  • zizmor: Zizmor failed to reach the GitHub API. — it needs GITHUB_TOKEN access to query the API for full audits. MegaLinter's own error message gives the fix:
    ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES:
    - GITHUB_TOKEN
  • osv-scanner: 22 known vulnerabilities across Cargo.lock, web/playground/package-lock.json, prqlc/bindings/js/package-lock.json, and prqlc/bindings/prqlc-python/uv.lock. Highlights: serialize-javascript 6.0.2 (GHSA-5c6j-r48x-rmvq, CVSS 8.1), rustls-webpki 0.101.7/0.103.9 (GHSA-82j2-j2ch-gfr8, CVSS 7.5), several dompurify 3.2.7 advisories. Most are fixable by version bumps Dependabot would normally produce.

The existing pattern in .mega-linter.yaml is to disable blocking vulnerability scanners (REPOSITORY_GRYPE comment: "Blocking unrelated PRs. We already have dependabot." — same applies to REPOSITORY_GITLEAKS, REPOSITORY_TRUFFLEHOG, REPOSITORY_KICS, REPOSITORY_KINGFISHER), and REPOSITORY_TRIVY is in DISABLE_ERRORS_LINTERS (warns, doesn't block). Two consistent options:

  1. Disable both in DISABLE_LINTERS — matches the GRYPE pattern, defers vuln scanning to Dependabot.
  2. Move to DISABLE_ERRORS_LINTERS — surfaces findings as warnings without blocking. For zizmor, also add the ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES: [GITHUB_TOKEN] snippet so it can actually run.

Happy to push either fix as a follow-up commit to this branch — let me know which you prefer.

@prql-bot
prql-bot dismissed their stale reviewMay 19, 2026 03:07

CI failed — megalinter v9.5.0 enabled new linters by default (zizmor, osv-scanner) that block on findings

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot Please push the fix for the two newly-failing MegaLinter v9.5 linters to this branch so CI goes green. Use option 1 from your review (disable ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS), since it matches the existing REPOSITORY_GRYPE pattern in .mega-linter.yaml ("we already have dependabot"). Rebase onto the latest main first if the branch is behind.

This was written by Claude Code on behalf of Maximilian Roos

@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from d9c14fc to 53a32ccCompareMay 19, 2026 16:58
@prql-bot

Copy link
Copy Markdown
Collaborator

Pushed 53a32cce — rebased onto main and disabled both ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS, with comments matching the GRYPE pattern. MegaLinter passed in 4m9s on the rebased commit.

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot You approved this but it's still red and unmerged, and there's no human author to act. Please push the fix to this branch: in .mega-linter.yaml, add ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER to DISABLE_LINTERS (matching the existing REPOSITORY_GRYPE "we already have dependabot" pattern). Rebase onto the latest main first, then push so CI goes green and this can merge.

This was written by Claude Code on behalf of Maximilian Roos

dependabotBotand others added 2 commits May 19, 2026 17:54
Bumps [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) from 9.4.0 to 9.5.0.
- [Release notes](https://github.com/oxsecurity/megalinter/releases)
- [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md)
- [Commits](oxsecurity/megalinter@v9.4.0...v9.5.0)
---
updated-dependencies:
- dependency-name: oxsecurity/megalinter
dependency-version: 9.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
MegaLinter v9.5.0 enables both by default. OSV scanner duplicates
Dependabot; zizmor needs GITHUB_TOKEN access to run. Disable both
to match the existing REPOSITORY_GRYPE pattern.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from 53a32cc to c3b4ae0CompareMay 19, 2026 17:54
@prql-bot

Copy link
Copy Markdown
Collaborator

Force-pushed c3b4ae00 — rebased onto current main (which had moved one commit forward since the prior rebase) with the same ACTION_ZIZMOR + REPOSITORY_OSV_SCANNER disable in .mega-linter.yaml. All required checks pass on the new commit (MegaLinter green in 4m43s).

mergeStateStatus shows BLOCKED, but that's the manual-merge gate, not CI — per the repo's tend config, the automerge job was removed in #5753, so bot PRs need a maintainer to land them.

@max-sixty
max-sixty merged commit b2dec67 into mainMay 19, 2026
41 checks passed
@max-sixty
max-sixty deleted the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch May 19, 2026 19:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesgithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@max-sixty@prql-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0 - #5916

Merged
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0
May 19, 2026
Merged

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0#5916
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubMay 19, 2026

Copy link
Copy Markdown
Contributor

Bumps oxsecurity/megalinter from 9.4.0 to 9.5.0.

Release notes

Sourced from oxsecurity/megalinter's releases.

v9.5.0

What's Changed

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

... (truncated)

Changelog

Sourced from oxsecurity/megalinter's changelog.

[v9.5.0] - 2026-05-16

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

    • Console output: linters now show their log sections (not only on errors), the results table and reporter logs are printed after linters complete, and parallel-run logs are no longer interleaved

... (truncated)

Commits
  • 0e3ce9b Fix release workflows.
  • 3e132b1 Release MegaLinter v9.5.0
  • cbb7fe9 Doc + prepare 9.5.0 release (#7836)
  • 29bcf10 [automation] Auto-update linters version, help and documentation (#7832)
  • ed753c5 chore(deps): update jdkato/vale docker tag to v3.14.2 (#7829)
  • e04f202 feat: implement user notifications system and replace migration warnings (#7833)
  • 54bfad8 chore(deps): update dependency @​stoplight/spectral-cli to v6.16.0 (#7830)
  • f809408 Eslint legacy detection & warning (#7831)
  • 6725b65 chore(deps): update dependency langsmith to v0.8.5 (#7828)
  • cbcc02f chore(deps): update dependency rumdl to v0.1.93 (#7825)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabotdependabotBot added dependencies github_actions Pull requests that update GitHub Actions code labels May 19, 2026
prql-bot
prql-bot previously approved these changes May 19, 2026

@prql-botprql-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MegaLinter v9.5.0 enables two new linters by default that did not run on v9.4.0:

  • ACTION_ZIZMOR (GitHub Actions security audit, v1.25.0)
  • REPOSITORY_OSV_SCANNER (vulnerability scanner, v2.3.8)

Both fail on this PR — see run 26073032632:

  • zizmor: Zizmor failed to reach the GitHub API. — it needs GITHUB_TOKEN access to query the API for full audits. MegaLinter's own error message gives the fix:
    ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES:
    - GITHUB_TOKEN
  • osv-scanner: 22 known vulnerabilities across Cargo.lock, web/playground/package-lock.json, prqlc/bindings/js/package-lock.json, and prqlc/bindings/prqlc-python/uv.lock. Highlights: serialize-javascript 6.0.2 (GHSA-5c6j-r48x-rmvq, CVSS 8.1), rustls-webpki 0.101.7/0.103.9 (GHSA-82j2-j2ch-gfr8, CVSS 7.5), several dompurify 3.2.7 advisories. Most are fixable by version bumps Dependabot would normally produce.

The existing pattern in .mega-linter.yaml is to disable blocking vulnerability scanners (REPOSITORY_GRYPE comment: "Blocking unrelated PRs. We already have dependabot." — same applies to REPOSITORY_GITLEAKS, REPOSITORY_TRUFFLEHOG, REPOSITORY_KICS, REPOSITORY_KINGFISHER), and REPOSITORY_TRIVY is in DISABLE_ERRORS_LINTERS (warns, doesn't block). Two consistent options:

  1. Disable both in DISABLE_LINTERS — matches the GRYPE pattern, defers vuln scanning to Dependabot.
  2. Move to DISABLE_ERRORS_LINTERS — surfaces findings as warnings without blocking. For zizmor, also add the ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES: [GITHUB_TOKEN] snippet so it can actually run.

Happy to push either fix as a follow-up commit to this branch — let me know which you prefer.

@prql-bot
prql-bot dismissed their stale reviewMay 19, 2026 03:07

CI failed — megalinter v9.5.0 enabled new linters by default (zizmor, osv-scanner) that block on findings

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot Please push the fix for the two newly-failing MegaLinter v9.5 linters to this branch so CI goes green. Use option 1 from your review (disable ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS), since it matches the existing REPOSITORY_GRYPE pattern in .mega-linter.yaml ("we already have dependabot"). Rebase onto the latest main first if the branch is behind.

This was written by Claude Code on behalf of Maximilian Roos

@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from d9c14fc to 53a32ccCompareMay 19, 2026 16:58
@prql-bot

Copy link
Copy Markdown
Collaborator

Pushed 53a32cce — rebased onto main and disabled both ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS, with comments matching the GRYPE pattern. MegaLinter passed in 4m9s on the rebased commit.

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot You approved this but it's still red and unmerged, and there's no human author to act. Please push the fix to this branch: in .mega-linter.yaml, add ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER to DISABLE_LINTERS (matching the existing REPOSITORY_GRYPE "we already have dependabot" pattern). Rebase onto the latest main first, then push so CI goes green and this can merge.

This was written by Claude Code on behalf of Maximilian Roos

dependabotBotand others added 2 commits May 19, 2026 17:54
Bumps [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) from 9.4.0 to 9.5.0.
- [Release notes](https://github.com/oxsecurity/megalinter/releases)
- [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md)
- [Commits](oxsecurity/megalinter@v9.4.0...v9.5.0)
---
updated-dependencies:
- dependency-name: oxsecurity/megalinter
dependency-version: 9.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
MegaLinter v9.5.0 enables both by default. OSV scanner duplicates
Dependabot; zizmor needs GITHUB_TOKEN access to run. Disable both
to match the existing REPOSITORY_GRYPE pattern.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from 53a32cc to c3b4ae0CompareMay 19, 2026 17:54
@prql-bot

Copy link
Copy Markdown
Collaborator

Force-pushed c3b4ae00 — rebased onto current main (which had moved one commit forward since the prior rebase) with the same ACTION_ZIZMOR + REPOSITORY_OSV_SCANNER disable in .mega-linter.yaml. All required checks pass on the new commit (MegaLinter green in 4m43s).

mergeStateStatus shows BLOCKED, but that's the manual-merge gate, not CI — per the repo's tend config, the automerge job was removed in #5753, so bot PRs need a maintainer to land them.

@max-sixty
max-sixty merged commit b2dec67 into mainMay 19, 2026
41 checks passed
@max-sixty
max-sixty deleted the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch May 19, 2026 19:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesgithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@max-sixty@prql-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0 - #5916

Merged
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0
May 19, 2026
Merged

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0#5916
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubMay 19, 2026

Copy link
Copy Markdown
Contributor

Bumps oxsecurity/megalinter from 9.4.0 to 9.5.0.

Release notes

Sourced from oxsecurity/megalinter's releases.

v9.5.0

What's Changed

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

... (truncated)

Changelog

Sourced from oxsecurity/megalinter's changelog.

[v9.5.0] - 2026-05-16

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

    • Console output: linters now show their log sections (not only on errors), the results table and reporter logs are printed after linters complete, and parallel-run logs are no longer interleaved

... (truncated)

Commits
  • 0e3ce9b Fix release workflows.
  • 3e132b1 Release MegaLinter v9.5.0
  • cbb7fe9 Doc + prepare 9.5.0 release (#7836)
  • 29bcf10 [automation] Auto-update linters version, help and documentation (#7832)
  • ed753c5 chore(deps): update jdkato/vale docker tag to v3.14.2 (#7829)
  • e04f202 feat: implement user notifications system and replace migration warnings (#7833)
  • 54bfad8 chore(deps): update dependency @​stoplight/spectral-cli to v6.16.0 (#7830)
  • f809408 Eslint legacy detection & warning (#7831)
  • 6725b65 chore(deps): update dependency langsmith to v0.8.5 (#7828)
  • cbcc02f chore(deps): update dependency rumdl to v0.1.93 (#7825)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabotdependabotBot added dependencies github_actions Pull requests that update GitHub Actions code labels May 19, 2026
prql-bot
prql-bot previously approved these changes May 19, 2026

@prql-botprql-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MegaLinter v9.5.0 enables two new linters by default that did not run on v9.4.0:

  • ACTION_ZIZMOR (GitHub Actions security audit, v1.25.0)
  • REPOSITORY_OSV_SCANNER (vulnerability scanner, v2.3.8)

Both fail on this PR — see run 26073032632:

  • zizmor: Zizmor failed to reach the GitHub API. — it needs GITHUB_TOKEN access to query the API for full audits. MegaLinter's own error message gives the fix:
    ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES:
    - GITHUB_TOKEN
  • osv-scanner: 22 known vulnerabilities across Cargo.lock, web/playground/package-lock.json, prqlc/bindings/js/package-lock.json, and prqlc/bindings/prqlc-python/uv.lock. Highlights: serialize-javascript 6.0.2 (GHSA-5c6j-r48x-rmvq, CVSS 8.1), rustls-webpki 0.101.7/0.103.9 (GHSA-82j2-j2ch-gfr8, CVSS 7.5), several dompurify 3.2.7 advisories. Most are fixable by version bumps Dependabot would normally produce.

The existing pattern in .mega-linter.yaml is to disable blocking vulnerability scanners (REPOSITORY_GRYPE comment: "Blocking unrelated PRs. We already have dependabot." — same applies to REPOSITORY_GITLEAKS, REPOSITORY_TRUFFLEHOG, REPOSITORY_KICS, REPOSITORY_KINGFISHER), and REPOSITORY_TRIVY is in DISABLE_ERRORS_LINTERS (warns, doesn't block). Two consistent options:

  1. Disable both in DISABLE_LINTERS — matches the GRYPE pattern, defers vuln scanning to Dependabot.
  2. Move to DISABLE_ERRORS_LINTERS — surfaces findings as warnings without blocking. For zizmor, also add the ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES: [GITHUB_TOKEN] snippet so it can actually run.

Happy to push either fix as a follow-up commit to this branch — let me know which you prefer.

@prql-bot
prql-bot dismissed their stale reviewMay 19, 2026 03:07

CI failed — megalinter v9.5.0 enabled new linters by default (zizmor, osv-scanner) that block on findings

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot Please push the fix for the two newly-failing MegaLinter v9.5 linters to this branch so CI goes green. Use option 1 from your review (disable ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS), since it matches the existing REPOSITORY_GRYPE pattern in .mega-linter.yaml ("we already have dependabot"). Rebase onto the latest main first if the branch is behind.

This was written by Claude Code on behalf of Maximilian Roos

@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from d9c14fc to 53a32ccCompareMay 19, 2026 16:58
@prql-bot

Copy link
Copy Markdown
Collaborator

Pushed 53a32cce — rebased onto main and disabled both ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS, with comments matching the GRYPE pattern. MegaLinter passed in 4m9s on the rebased commit.

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot You approved this but it's still red and unmerged, and there's no human author to act. Please push the fix to this branch: in .mega-linter.yaml, add ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER to DISABLE_LINTERS (matching the existing REPOSITORY_GRYPE "we already have dependabot" pattern). Rebase onto the latest main first, then push so CI goes green and this can merge.

This was written by Claude Code on behalf of Maximilian Roos

dependabotBotand others added 2 commits May 19, 2026 17:54
Bumps [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) from 9.4.0 to 9.5.0.
- [Release notes](https://github.com/oxsecurity/megalinter/releases)
- [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md)
- [Commits](oxsecurity/megalinter@v9.4.0...v9.5.0)
---
updated-dependencies:
- dependency-name: oxsecurity/megalinter
dependency-version: 9.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
MegaLinter v9.5.0 enables both by default. OSV scanner duplicates
Dependabot; zizmor needs GITHUB_TOKEN access to run. Disable both
to match the existing REPOSITORY_GRYPE pattern.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from 53a32cc to c3b4ae0CompareMay 19, 2026 17:54
@prql-bot

Copy link
Copy Markdown
Collaborator

Force-pushed c3b4ae00 — rebased onto current main (which had moved one commit forward since the prior rebase) with the same ACTION_ZIZMOR + REPOSITORY_OSV_SCANNER disable in .mega-linter.yaml. All required checks pass on the new commit (MegaLinter green in 4m43s).

mergeStateStatus shows BLOCKED, but that's the manual-merge gate, not CI — per the repo's tend config, the automerge job was removed in #5753, so bot PRs need a maintainer to land them.

@max-sixty
max-sixty merged commit b2dec67 into mainMay 19, 2026
41 checks passed
@max-sixty
max-sixty deleted the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch May 19, 2026 19:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesgithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@max-sixty@prql-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0 - #5916

Merged
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0
May 19, 2026
Merged

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0#5916
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubMay 19, 2026

Copy link
Copy Markdown
Contributor

Bumps oxsecurity/megalinter from 9.4.0 to 9.5.0.

Release notes

Sourced from oxsecurity/megalinter's releases.

v9.5.0

What's Changed

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

... (truncated)

Changelog

Sourced from oxsecurity/megalinter's changelog.

[v9.5.0] - 2026-05-16

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

    • Console output: linters now show their log sections (not only on errors), the results table and reporter logs are printed after linters complete, and parallel-run logs are no longer interleaved

... (truncated)

Commits
  • 0e3ce9b Fix release workflows.
  • 3e132b1 Release MegaLinter v9.5.0
  • cbb7fe9 Doc + prepare 9.5.0 release (#7836)
  • 29bcf10 [automation] Auto-update linters version, help and documentation (#7832)
  • ed753c5 chore(deps): update jdkato/vale docker tag to v3.14.2 (#7829)
  • e04f202 feat: implement user notifications system and replace migration warnings (#7833)
  • 54bfad8 chore(deps): update dependency @​stoplight/spectral-cli to v6.16.0 (#7830)
  • f809408 Eslint legacy detection & warning (#7831)
  • 6725b65 chore(deps): update dependency langsmith to v0.8.5 (#7828)
  • cbcc02f chore(deps): update dependency rumdl to v0.1.93 (#7825)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabotdependabotBot added dependencies github_actions Pull requests that update GitHub Actions code labels May 19, 2026
prql-bot
prql-bot previously approved these changes May 19, 2026

@prql-botprql-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MegaLinter v9.5.0 enables two new linters by default that did not run on v9.4.0:

  • ACTION_ZIZMOR (GitHub Actions security audit, v1.25.0)
  • REPOSITORY_OSV_SCANNER (vulnerability scanner, v2.3.8)

Both fail on this PR — see run 26073032632:

  • zizmor: Zizmor failed to reach the GitHub API. — it needs GITHUB_TOKEN access to query the API for full audits. MegaLinter's own error message gives the fix:
    ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES:
    - GITHUB_TOKEN
  • osv-scanner: 22 known vulnerabilities across Cargo.lock, web/playground/package-lock.json, prqlc/bindings/js/package-lock.json, and prqlc/bindings/prqlc-python/uv.lock. Highlights: serialize-javascript 6.0.2 (GHSA-5c6j-r48x-rmvq, CVSS 8.1), rustls-webpki 0.101.7/0.103.9 (GHSA-82j2-j2ch-gfr8, CVSS 7.5), several dompurify 3.2.7 advisories. Most are fixable by version bumps Dependabot would normally produce.

The existing pattern in .mega-linter.yaml is to disable blocking vulnerability scanners (REPOSITORY_GRYPE comment: "Blocking unrelated PRs. We already have dependabot." — same applies to REPOSITORY_GITLEAKS, REPOSITORY_TRUFFLEHOG, REPOSITORY_KICS, REPOSITORY_KINGFISHER), and REPOSITORY_TRIVY is in DISABLE_ERRORS_LINTERS (warns, doesn't block). Two consistent options:

  1. Disable both in DISABLE_LINTERS — matches the GRYPE pattern, defers vuln scanning to Dependabot.
  2. Move to DISABLE_ERRORS_LINTERS — surfaces findings as warnings without blocking. For zizmor, also add the ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES: [GITHUB_TOKEN] snippet so it can actually run.

Happy to push either fix as a follow-up commit to this branch — let me know which you prefer.

@prql-bot
prql-bot dismissed their stale reviewMay 19, 2026 03:07

CI failed — megalinter v9.5.0 enabled new linters by default (zizmor, osv-scanner) that block on findings

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot Please push the fix for the two newly-failing MegaLinter v9.5 linters to this branch so CI goes green. Use option 1 from your review (disable ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS), since it matches the existing REPOSITORY_GRYPE pattern in .mega-linter.yaml ("we already have dependabot"). Rebase onto the latest main first if the branch is behind.

This was written by Claude Code on behalf of Maximilian Roos

@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from d9c14fc to 53a32ccCompareMay 19, 2026 16:58
@prql-bot

Copy link
Copy Markdown
Collaborator

Pushed 53a32cce — rebased onto main and disabled both ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS, with comments matching the GRYPE pattern. MegaLinter passed in 4m9s on the rebased commit.

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot You approved this but it's still red and unmerged, and there's no human author to act. Please push the fix to this branch: in .mega-linter.yaml, add ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER to DISABLE_LINTERS (matching the existing REPOSITORY_GRYPE "we already have dependabot" pattern). Rebase onto the latest main first, then push so CI goes green and this can merge.

This was written by Claude Code on behalf of Maximilian Roos

dependabotBotand others added 2 commits May 19, 2026 17:54
Bumps [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) from 9.4.0 to 9.5.0.
- [Release notes](https://github.com/oxsecurity/megalinter/releases)
- [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md)
- [Commits](oxsecurity/megalinter@v9.4.0...v9.5.0)
---
updated-dependencies:
- dependency-name: oxsecurity/megalinter
dependency-version: 9.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
MegaLinter v9.5.0 enables both by default. OSV scanner duplicates
Dependabot; zizmor needs GITHUB_TOKEN access to run. Disable both
to match the existing REPOSITORY_GRYPE pattern.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from 53a32cc to c3b4ae0CompareMay 19, 2026 17:54
@prql-bot

Copy link
Copy Markdown
Collaborator

Force-pushed c3b4ae00 — rebased onto current main (which had moved one commit forward since the prior rebase) with the same ACTION_ZIZMOR + REPOSITORY_OSV_SCANNER disable in .mega-linter.yaml. All required checks pass on the new commit (MegaLinter green in 4m43s).

mergeStateStatus shows BLOCKED, but that's the manual-merge gate, not CI — per the repo's tend config, the automerge job was removed in #5753, so bot PRs need a maintainer to land them.

@max-sixty
max-sixty merged commit b2dec67 into mainMay 19, 2026
41 checks passed
@max-sixty
max-sixty deleted the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch May 19, 2026 19:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesgithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@max-sixty@prql-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0 - #5916

Merged
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0
May 19, 2026
Merged

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0#5916
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubMay 19, 2026

Copy link
Copy Markdown
Contributor

Bumps oxsecurity/megalinter from 9.4.0 to 9.5.0.

Release notes

Sourced from oxsecurity/megalinter's releases.

v9.5.0

What's Changed

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

... (truncated)

Changelog

Sourced from oxsecurity/megalinter's changelog.

[v9.5.0] - 2026-05-16

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

    • Console output: linters now show their log sections (not only on errors), the results table and reporter logs are printed after linters complete, and parallel-run logs are no longer interleaved

... (truncated)

Commits
  • 0e3ce9b Fix release workflows.
  • 3e132b1 Release MegaLinter v9.5.0
  • cbb7fe9 Doc + prepare 9.5.0 release (#7836)
  • 29bcf10 [automation] Auto-update linters version, help and documentation (#7832)
  • ed753c5 chore(deps): update jdkato/vale docker tag to v3.14.2 (#7829)
  • e04f202 feat: implement user notifications system and replace migration warnings (#7833)
  • 54bfad8 chore(deps): update dependency @​stoplight/spectral-cli to v6.16.0 (#7830)
  • f809408 Eslint legacy detection & warning (#7831)
  • 6725b65 chore(deps): update dependency langsmith to v0.8.5 (#7828)
  • cbcc02f chore(deps): update dependency rumdl to v0.1.93 (#7825)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabotdependabotBot added dependencies github_actions Pull requests that update GitHub Actions code labels May 19, 2026
prql-bot
prql-bot previously approved these changes May 19, 2026

@prql-botprql-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MegaLinter v9.5.0 enables two new linters by default that did not run on v9.4.0:

  • ACTION_ZIZMOR (GitHub Actions security audit, v1.25.0)
  • REPOSITORY_OSV_SCANNER (vulnerability scanner, v2.3.8)

Both fail on this PR — see run 26073032632:

  • zizmor: Zizmor failed to reach the GitHub API. — it needs GITHUB_TOKEN access to query the API for full audits. MegaLinter's own error message gives the fix:
    ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES:
    - GITHUB_TOKEN
  • osv-scanner: 22 known vulnerabilities across Cargo.lock, web/playground/package-lock.json, prqlc/bindings/js/package-lock.json, and prqlc/bindings/prqlc-python/uv.lock. Highlights: serialize-javascript 6.0.2 (GHSA-5c6j-r48x-rmvq, CVSS 8.1), rustls-webpki 0.101.7/0.103.9 (GHSA-82j2-j2ch-gfr8, CVSS 7.5), several dompurify 3.2.7 advisories. Most are fixable by version bumps Dependabot would normally produce.

The existing pattern in .mega-linter.yaml is to disable blocking vulnerability scanners (REPOSITORY_GRYPE comment: "Blocking unrelated PRs. We already have dependabot." — same applies to REPOSITORY_GITLEAKS, REPOSITORY_TRUFFLEHOG, REPOSITORY_KICS, REPOSITORY_KINGFISHER), and REPOSITORY_TRIVY is in DISABLE_ERRORS_LINTERS (warns, doesn't block). Two consistent options:

  1. Disable both in DISABLE_LINTERS — matches the GRYPE pattern, defers vuln scanning to Dependabot.
  2. Move to DISABLE_ERRORS_LINTERS — surfaces findings as warnings without blocking. For zizmor, also add the ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES: [GITHUB_TOKEN] snippet so it can actually run.

Happy to push either fix as a follow-up commit to this branch — let me know which you prefer.

@prql-bot
prql-bot dismissed their stale reviewMay 19, 2026 03:07

CI failed — megalinter v9.5.0 enabled new linters by default (zizmor, osv-scanner) that block on findings

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot Please push the fix for the two newly-failing MegaLinter v9.5 linters to this branch so CI goes green. Use option 1 from your review (disable ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS), since it matches the existing REPOSITORY_GRYPE pattern in .mega-linter.yaml ("we already have dependabot"). Rebase onto the latest main first if the branch is behind.

This was written by Claude Code on behalf of Maximilian Roos

@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from d9c14fc to 53a32ccCompareMay 19, 2026 16:58
@prql-bot

Copy link
Copy Markdown
Collaborator

Pushed 53a32cce — rebased onto main and disabled both ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS, with comments matching the GRYPE pattern. MegaLinter passed in 4m9s on the rebased commit.

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot You approved this but it's still red and unmerged, and there's no human author to act. Please push the fix to this branch: in .mega-linter.yaml, add ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER to DISABLE_LINTERS (matching the existing REPOSITORY_GRYPE "we already have dependabot" pattern). Rebase onto the latest main first, then push so CI goes green and this can merge.

This was written by Claude Code on behalf of Maximilian Roos

dependabotBotand others added 2 commits May 19, 2026 17:54
Bumps [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) from 9.4.0 to 9.5.0.
- [Release notes](https://github.com/oxsecurity/megalinter/releases)
- [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md)
- [Commits](oxsecurity/megalinter@v9.4.0...v9.5.0)
---
updated-dependencies:
- dependency-name: oxsecurity/megalinter
dependency-version: 9.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
MegaLinter v9.5.0 enables both by default. OSV scanner duplicates
Dependabot; zizmor needs GITHUB_TOKEN access to run. Disable both
to match the existing REPOSITORY_GRYPE pattern.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from 53a32cc to c3b4ae0CompareMay 19, 2026 17:54
@prql-bot

Copy link
Copy Markdown
Collaborator

Force-pushed c3b4ae00 — rebased onto current main (which had moved one commit forward since the prior rebase) with the same ACTION_ZIZMOR + REPOSITORY_OSV_SCANNER disable in .mega-linter.yaml. All required checks pass on the new commit (MegaLinter green in 4m43s).

mergeStateStatus shows BLOCKED, but that's the manual-merge gate, not CI — per the repo's tend config, the automerge job was removed in #5753, so bot PRs need a maintainer to land them.

@max-sixty
max-sixty merged commit b2dec67 into mainMay 19, 2026
41 checks passed
@max-sixty
max-sixty deleted the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch May 19, 2026 19:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesgithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@max-sixty@prql-bot
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0 - #5916

Merged
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0
May 19, 2026
Merged

chore: bump oxsecurity/megalinter from 9.4.0 to 9.5.0#5916
max-sixty merged 2 commits into
mainfrom
dependabot/github_actions/oxsecurity/megalinter-9.5.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubMay 19, 2026

Copy link
Copy Markdown
Contributor

Bumps oxsecurity/megalinter from 9.4.0 to 9.5.0.

Release notes

Sourced from oxsecurity/megalinter's releases.

v9.5.0

What's Changed

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

... (truncated)

Changelog

Sourced from oxsecurity/megalinter's changelog.

[v9.5.0] - 2026-05-16

Take 2 mn to read MegaLinter v9.5.0 announcements

  • Breaking changes

    • Docker images published only to GitHub Container Registry (ghcr.io) until OIDC-based publishing to Docker Hub is implemented. The Docker Hub registry (docker.io/oxsecurity/megalinter) is frozen at v9.4.0: pulls of oxsecurity/megalinter:v9 (or :beta, or any flavor tag) will keep returning v9.4.0. To get v9.5.0 and later from CI tools other than GitHub Actions (GitLab CI, Azure Pipelines, Bitbucket, Jenkins, Drone, raw docker run, …), switch your image references:

      • oxsecurity/megalinter:v9ghcr.io/oxsecurity/megalinter:v9
      • oxsecurity/megalinter:betaghcr.io/oxsecurity/megalinter:beta
      • oxsecurity/megalinter-<flavor>:v9ghcr.io/oxsecurity/megalinter-<flavor>:v9

      GitHub Action users (uses: oxsecurity/megalinter@v9) and mega-linter-runner users are not affected, as both already pull from ghcr.io.

    • ESLint-based linters upgraded to v10+. Legacy .eslintrc.* configs are no longer supported: you must migrate to flat-config (eslint.config.js) to keep using JAVASCRIPT_ES, TYPESCRIPT_ES, JSX_ESLINT, TSX_ESLINT, and JSON_ESLINT_PLUGIN_JSONC.

    • Airbnb and Standard ESLint configs replaced (they never shipped ESLint 9+ support):

      • extends: ["airbnb"]extends: ["airbnb-extended"]
      • extends: ["standard"]extends: ["neostandard"]
  • Core

    • User notifications system: linters can surface structured "Notices" to end users in the PR comment / report footer (used for ESLint migration, deprecated options, etc.), replaces the ad-hoc migration warnings
    • Security: more default hidden environment variables, so a compromised linter cannot leak your secrets
    • Upgrade .NET runtime to 10.0 (csharpier, dotnet-format, roslynator, devskim, tsqllint, vbdotnet-format)
    • Upgrade GO runtime to 1.26.3
  • New linters

    • osv-scanner: trivy-like vulnerability scanner by Google
    • zizmor: GitHub Actions static analysis
  • Disabled linters

    • KICS (until upstream security issue is fixed)
    • Spectral (crashing)
  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

    • ESLint: legacy .eslintrc.* configs are now detected and a migration notice is emitted in the report so users know they need to switch to flat-config
    • shellcheck: honour the BASH_SHELLCHECK_CONFIG_FILE variable / .shellcheckrc config file
    • raku (Rakudo): now ships on ARM64 too
    • scala: linter installation is now deterministic (same binary across rebuilds)
    • v8r (JSON/YAML schema validation): output now shows only validation errors (no more "no schema found" or success noise)
    • lychee: removed the deprecated exclude_mail option (no longer supported by lychee upstream)
    • Faster image pulls: several linters (Lua/StyLua arm64, clj-kondo, kubescape, ls-lint, dotenv-linter) now use pre-built Alpine binaries instead of compiling from source
  • Fixes

    • Console output: linters now show their log sections (not only on errors), the results table and reporter logs are printed after linters complete, and parallel-run logs are no longer interleaved

... (truncated)

Commits
  • 0e3ce9b Fix release workflows.
  • 3e132b1 Release MegaLinter v9.5.0
  • cbb7fe9 Doc + prepare 9.5.0 release (#7836)
  • 29bcf10 [automation] Auto-update linters version, help and documentation (#7832)
  • ed753c5 chore(deps): update jdkato/vale docker tag to v3.14.2 (#7829)
  • e04f202 feat: implement user notifications system and replace migration warnings (#7833)
  • 54bfad8 chore(deps): update dependency @​stoplight/spectral-cli to v6.16.0 (#7830)
  • f809408 Eslint legacy detection & warning (#7831)
  • 6725b65 chore(deps): update dependency langsmith to v0.8.5 (#7828)
  • cbcc02f chore(deps): update dependency rumdl to v0.1.93 (#7825)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabotdependabotBot added dependencies github_actions Pull requests that update GitHub Actions code labels May 19, 2026
prql-bot
prql-bot previously approved these changes May 19, 2026

@prql-botprql-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MegaLinter v9.5.0 enables two new linters by default that did not run on v9.4.0:

  • ACTION_ZIZMOR (GitHub Actions security audit, v1.25.0)
  • REPOSITORY_OSV_SCANNER (vulnerability scanner, v2.3.8)

Both fail on this PR — see run 26073032632:

  • zizmor: Zizmor failed to reach the GitHub API. — it needs GITHUB_TOKEN access to query the API for full audits. MegaLinter's own error message gives the fix:
    ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES:
    - GITHUB_TOKEN
  • osv-scanner: 22 known vulnerabilities across Cargo.lock, web/playground/package-lock.json, prqlc/bindings/js/package-lock.json, and prqlc/bindings/prqlc-python/uv.lock. Highlights: serialize-javascript 6.0.2 (GHSA-5c6j-r48x-rmvq, CVSS 8.1), rustls-webpki 0.101.7/0.103.9 (GHSA-82j2-j2ch-gfr8, CVSS 7.5), several dompurify 3.2.7 advisories. Most are fixable by version bumps Dependabot would normally produce.

The existing pattern in .mega-linter.yaml is to disable blocking vulnerability scanners (REPOSITORY_GRYPE comment: "Blocking unrelated PRs. We already have dependabot." — same applies to REPOSITORY_GITLEAKS, REPOSITORY_TRUFFLEHOG, REPOSITORY_KICS, REPOSITORY_KINGFISHER), and REPOSITORY_TRIVY is in DISABLE_ERRORS_LINTERS (warns, doesn't block). Two consistent options:

  1. Disable both in DISABLE_LINTERS — matches the GRYPE pattern, defers vuln scanning to Dependabot.
  2. Move to DISABLE_ERRORS_LINTERS — surfaces findings as warnings without blocking. For zizmor, also add the ACTION_ZIZMOR_UNSECURED_ENV_VARIABLES: [GITHUB_TOKEN] snippet so it can actually run.

Happy to push either fix as a follow-up commit to this branch — let me know which you prefer.

@prql-bot
prql-bot dismissed their stale reviewMay 19, 2026 03:07

CI failed — megalinter v9.5.0 enabled new linters by default (zizmor, osv-scanner) that block on findings

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot Please push the fix for the two newly-failing MegaLinter v9.5 linters to this branch so CI goes green. Use option 1 from your review (disable ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS), since it matches the existing REPOSITORY_GRYPE pattern in .mega-linter.yaml ("we already have dependabot"). Rebase onto the latest main first if the branch is behind.

This was written by Claude Code on behalf of Maximilian Roos

@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from d9c14fc to 53a32ccCompareMay 19, 2026 16:58
@prql-bot

Copy link
Copy Markdown
Collaborator

Pushed 53a32cce — rebased onto main and disabled both ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER in DISABLE_LINTERS, with comments matching the GRYPE pattern. MegaLinter passed in 4m9s on the rebased commit.

@max-sixty

Copy link
Copy Markdown
Member

@prql-bot You approved this but it's still red and unmerged, and there's no human author to act. Please push the fix to this branch: in .mega-linter.yaml, add ACTION_ZIZMOR and REPOSITORY_OSV_SCANNER to DISABLE_LINTERS (matching the existing REPOSITORY_GRYPE "we already have dependabot" pattern). Rebase onto the latest main first, then push so CI goes green and this can merge.

This was written by Claude Code on behalf of Maximilian Roos

dependabotBotand others added 2 commits May 19, 2026 17:54
Bumps [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) from 9.4.0 to 9.5.0.
- [Release notes](https://github.com/oxsecurity/megalinter/releases)
- [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md)
- [Commits](oxsecurity/megalinter@v9.4.0...v9.5.0)
---
updated-dependencies:
- dependency-name: oxsecurity/megalinter
dependency-version: 9.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
MegaLinter v9.5.0 enables both by default. OSV scanner duplicates
Dependabot; zizmor needs GITHUB_TOKEN access to run. Disable both
to match the existing REPOSITORY_GRYPE pattern.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@prql-bot
prql-botforce-pushed the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch from 53a32cc to c3b4ae0CompareMay 19, 2026 17:54
@prql-bot

Copy link
Copy Markdown
Collaborator

Force-pushed c3b4ae00 — rebased onto current main (which had moved one commit forward since the prior rebase) with the same ACTION_ZIZMOR + REPOSITORY_OSV_SCANNER disable in .mega-linter.yaml. All required checks pass on the new commit (MegaLinter green in 4m43s).

mergeStateStatus shows BLOCKED, but that's the manual-merge gate, not CI — per the repo's tend config, the automerge job was removed in #5753, so bot PRs need a maintainer to land them.

@max-sixty
max-sixty merged commit b2dec67 into mainMay 19, 2026
41 checks passed
@max-sixty
max-sixty deleted the dependabot/github_actions/oxsecurity/megalinter-9.5.0 branch May 19, 2026 19:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesgithub_actionsPull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@max-sixty@prql-bot