Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 2, 2025

Bumps megalinter/megalinter from 9.1.0 to 9.2.0.

Release notes

Sourced from megalinter/megalinter's releases.

v9.2.0

What's Changed

... (truncated)

Changelog

Sourced from megalinter/megalinter's changelog.

[v9.2.0] - 2025-11-29

... (truncated)

Commits
  • 55a59b2 Release MegaLinter v9.2.0
  • c94f8c8 prep release
  • bca0a38 chore(deps): update dependency rubocop-rails to v2.34.2 (#6648)
  • 8d505bf [automation] Auto-update linters version, help and documentation (#6659)
  • a7d0161 Add conversion from Jenkins variables to related Git provider variables (#6658)
  • 663b45a chore(deps): update mstruebing/editorconfig-checker docker tag to v3.6.0 (#6652)
  • 64fbcca chore(deps): update docker/metadata-action action to v5.10.0 (#6651)
  • b2f3c63 Hides regex compilation warning (#6657)
  • 0eac80b chore(deps): update zricethezav/gitleaks docker tag to v8.30.0 (#6653)
  • d1fdceb CI: Optimize standalone linters release perfs (#6656)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [megalinter/megalinter](https://github.com/megalinter/megalinter) from 9.1.0 to 9.2.0.
- [Release notes](https://github.com/megalinter/megalinter/releases)
- [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md)
- [Commits](oxsecurity/megalinter@v9.1.0...v9.2.0)

---
updated-dependencies:
- dependency-name: megalinter/megalinter
  dependency-version: 9.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code labels Dec 2, 2025
@github-actions
Copy link

github-actions bot commented Dec 2, 2025

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 2 0 0 0.01s
⚠️ COPYPASTE jscpd yes 22 no 2.74s
⚠️ GO golangci-lint yes 1 no 80.39s
✅ GO revive yes no no 7.89s
✅ MARKDOWN markdownlint 1 0 0 0.65s
✅ MARKDOWN markdown-table-formatter 1 0 0 0.57s
✅ REPOSITORY checkov yes no no 22.41s
✅ REPOSITORY gitleaks yes no no 0.4s
✅ REPOSITORY git_diff yes no no 0.0s
✅ REPOSITORY grype yes no no 57.75s
✅ REPOSITORY secretlint yes no no 1.1s
✅ REPOSITORY syft yes no no 6.26s
✅ REPOSITORY trivy yes no no 13.33s
✅ REPOSITORY trivy-sbom yes no no 4.19s
✅ REPOSITORY trufflehog yes no no 4.49s
✅ SPELL lychee 5 0 0 0.63s
⚠️ YAML prettier 4 1 2 0.79s
✅ YAML v8r 4 0 0 5.17s
✅ YAML yamllint 4 0 0 0.78s

Detailed Issues

⚠️ GO / golangci-lint - 1 error
../../..pkg/mesh/service.go:94:14: unlambda: replace `func(shardID, replicaID uint64) statemachine.IStateMachine {
	return NewMeshStateMachine(shardID, replicaID)
}` with `NewMeshStateMachine` (gocritic)
	createSM := func(shardID, replicaID uint64) statemachine.IStateMachine {
	            ^
../../..pkg/laws/user.go:166:2: QF1003: could use tagged switch on facts.Facts.Distro.Family (staticcheck)
	if facts.Facts.Distro.Family == "alpine" {
	^
2 issues:
* gocritic: 1
* staticcheck: 1
⚠️ COPYPASTE / jscpd - 22 errors
Clone found (go):
 - pkg/mesh/http.go [124:16 - 151:8] (27 lines, 275 tokens)
   pkg/mesh/http.go [86:14 - 113:7]

Clone found (go):
 - pkg/mesh/http.go [201:9 - 216:6] (15 lines, 119 tokens)
   pkg/mesh/http.go [177:10 - 192:7]

Clone found (go):
 - pkg/mesh/http.go [237:2 - 247:7] (10 lines, 90 tokens)
   pkg/mesh/http.go [182:2 - 192:7]

Clone found (go):
 - pkg/mesh/http.go [261:13 - 278:8] (17 lines, 138 tokens)
   pkg/mesh/http.go [230:11 - 192:7]

Clone found (go):
 - pkg/laws/ssh.go [99:3 - 110:2] (11 lines, 131 tokens)
   pkg/laws/ssh.go [70:4 - 82:7]

Clone found (go):
 - pkg/laws/service.go [175:5 - 180:4] (5 lines, 77 tokens)
   pkg/laws/service.go [156:7 - 161:4]

Clone found (go):
 - pkg/laws/pkgrepo.go [65:28 - 74:2] (9 lines, 88 tokens)
   pkg/laws/script.go [73:23 - 82:2]

Clone found (go):
 - pkg/laws/file.go [135:27 - 143:17] (8 lines, 82 tokens)
   pkg/laws/script.go [73:23 - 81:5]

Clone found (go):
 - pkg/laws/file.go [286:2 - 316:8] (30 lines, 378 tokens)
   pkg/laws/file.go [135:2 - 165:23]

Clone found (go):
 - pkg/laws/file.go [318:3 - 324:5] (6 lines, 92 tokens)
   pkg/laws/file.go [172:3 - 178:22]

Clone found (go):
 - pkg/laws/file.go [412:2 - 422:4] (10 lines, 97 tokens)
   pkg/laws/file.go [362:2 - 372:6]

Clone found (go):
 - pkg/laws/file.go [445:3 - 464:7] (19 lines, 222 tokens)
   pkg/laws/file.go [394:3 - 412:3]

Clone found (go):
 - pkg/laws/file.go [472:2 - 510:9] (38 lines, 478 tokens)
   pkg/laws/file.go [135:2 - 324:13]

Clone found (go):
 - pkg/laws/file.go [550:2 - 563:89] (13 lines, 120 tokens)
   pkg/laws/file.go [363:3 - 425:3]

Clone found (go):
 - pkg/laws/file.go [580:5 - 602:7] (22 lines, 259 tokens)
   pkg/laws/file.go [440:5 - 411:2]

Clone found (go):
 - pkg/laws/container.go [90:26 - 99:4] (9 lines, 88 tokens)
   pkg/laws/script.go [73:23 - 82:2]

Clone found (go):
 - cmd/mesh-commands.go [51:38 - 62:6] (11 lines, 113 tokens)
   cmd/mesh-commands.go [23:80 - 34:7]

Clone found (go):
 - cmd/mesh-commands.go [173:17 - 179:22] (6 lines, 81 tokens)
   cmd/mesh-commands.go [124:16 - 130:28]

Clone found (go):
 - cmd/mesh-commands.go [179:22 - 192:14] (13 lines, 82 tokens)
   cmd/mesh-commands.go [130:28 - 143:14]

Clone found (go):
 - cmd/mesh-commands.go [227:17 - 233:23] (6 lines, 81 tokens)
   cmd/mesh-commands.go [124:16 - 130:28]

Clone found (go):
 - cmd/local-lint.go [48:3 - 62:4] (14 lines, 135 tokens)
   cmd/local-pretend.go [48:3 - 62:4]

Clone found (go):
 - cmd/local-apply.go [48:18 - 63:2] (15 lines, 117 tokens)
   cmd/local-pretend.go [49:12 - 63:4]

┌────────┬────────────────┬─────────────┬──────────────┬──────────────┬──────────────────┬───────────────────┐
│ Format │ Files analyzed │ Total lines │ Total tokens │ Clones found │ Duplicated lines │ Duplicated tokens │
├────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ go     │ 32             │ 5800        │ 41700        │ 22           │ 314 (5.41%)      │ 3343 (8.02%)      │
├────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ Total: │ 32             │ 5800        │ 41700        │ 22           │ 314 (5.41%)      │ 3343 (8.02%)      │
└────────┴────────────────┴─────────────┴──────────────┴──────────────┴──────────────────┴───────────────────┘
Found 22 clones.
HTML report saved to megalinter-reports/copy-paste/html/
ERROR: jscpd found too many duplicates (5.41%) over threshold (0%)
Error: ERROR: jscpd found too many duplicates (5.41%) over threshold (0%)
    at ThresholdReporter.report (/node-deps/node_modules/@jscpd/finder/dist/index.js:612:13)
    at /node-deps/node_modules/@jscpd/finder/dist/index.js:110:18
    at Array.forEach (<anonymous>)
    at /node-deps/node_modules/@jscpd/finder/dist/index.js:109:22
    at async /node-deps/node_modules/jscpd/dist/jscpd.js:351:5
⚠️ YAML / prettier - 1 error
Checking formatting...
[warn] .github/workflows/megalinter.yaml
[warn] Code style issues found in the above file. Run Prettier with --write to fix.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.2.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,COPYPASTE_JSCPD,GO_GOLANGCI_LINT,GO_REVIVE,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_GRYPE,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jan 5, 2026

Superseded by #242.

@dependabot dependabot bot closed this Jan 5, 2026
@dependabot dependabot bot deleted the dependabot/github_actions/megalinter/megalinter-9.2.0 branch January 5, 2026 23:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant