Skip to content

Bump megalinter/megalinter from 9.1.0 to 9.3.0#65

Merged
iggy merged 1 commit intodevelopfrom
dependabot/github_actions/megalinter/megalinter-9.3.0
Feb 21, 2026
Merged

Bump megalinter/megalinter from 9.1.0 to 9.3.0#65
iggy merged 1 commit intodevelopfrom
dependabot/github_actions/megalinter/megalinter-9.3.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Jan 5, 2026

Bumps megalinter/megalinter from 9.1.0 to 9.3.0.

Release notes

Sourced from megalinter/megalinter's releases.

v9.3.0

What's Changed

  • Core

    • Add enum name support in MegaLinter config Json schema for better autocompletion in editors
    • Update base image to python:3.13-alpine3.23
  • New linters

  • Linters enhancements

    • Change checkmake Docker image reference by @​bdovaz
  • Reporters

    • Handle multiple MegaLinter runs on the same repo using custom value sent in variable MEGALINTER_MULTIRUN_KEY
    • Allow to override url to CI build in Git based reporters using REPORTERS_ACTION_RUN_URL variable
    • Fix sections display in Gitlab console logs
  • Doc

    • Classify all JSON schema config variables by category and section
  • CI

    • Free disk space on GitHub actions runner when releasing a new flavor
    • Add missing Dockerfile patterns to Renovate Dockerfile manager
    • Remove gitpod custom image, workflow, and makefile targets
  • Linter versions upgrades (54)

... (truncated)

Changelog

Sourced from megalinter/megalinter's changelog.

[v9.3.0] - 2026-01-04

  • Core

    • Add enum name support in MegaLinter config Json schema for better autocompletion in editors
    • Update base image to python:3.13-alpine3.23
  • New linters

  • Linters enhancements

    • Change checkmake Docker image reference by @​bdovaz
  • Reporters

    • Handle multiple MegaLinter runs on the same repo using custom value sent in variable MEGALINTER_MULTIRUN_KEY
    • Allow to override url to CI build in Git based reporters using REPORTERS_ACTION_RUN_URL variable
    • Fix sections display in Gitlab console logs
  • Doc

    • Classify all JSON schema config variables by category and section
  • CI

    • Free disk space on GitHub actions runner when releasing a new flavor
    • Add missing Dockerfile patterns to Renovate Dockerfile manager
    • Remove gitpod custom image, workflow, and makefile targets
  • Linter versions upgrades (54)

... (truncated)

Commits
  • 42bb470 Release MegaLinter v9.3.0
  • fe74938 changelog
  • edb083a [automation] Auto-update linters version, help and documentation (#6889)
  • 824240c JSON Schema fix (#6888)
  • 9af8d5b chore(deps): update dependency npm-package-json-lint to v9.1.0 (#6883)
  • 781c95c [automation] Auto-update linters version, help and documentation (#6885)
  • 101b802 JSON Schema (#6887)
  • 3ab7a93 chore(deps): update dependency friendsofphp/php-cs-fixer to v3.92.4 (#6886)
  • 12f7c03 chore(deps): update ghcr.io/astral-sh/uv docker tag to v0.9.21 (#6882)
  • 91a9dfb chore(deps): update dependency sfdx-hardis to v6.20.0 (#6884)
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [megalinter/megalinter](https://github.com/megalinter/megalinter) from 9.1.0 to 9.3.0.
- [Release notes](https://github.com/megalinter/megalinter/releases)
- [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md)
- [Commits](oxsecurity/megalinter@v9.1.0...v9.3.0)

---
updated-dependencies:
- dependency-name: megalinter/megalinter
  dependency-version: 9.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jan 5, 2026
@github-actions
Copy link
Copy Markdown

github-actions bot commented Jan 5, 2026

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 2 0 0 0.01s
✅ COPYPASTE jscpd yes no no 1.32s
✅ GO golangci-lint yes no no 28.32s
✅ GO revive yes no no 21.18s
⚠️ MARKDOWN markdownlint 1 1 0 0.95s
✅ MARKDOWN markdown-table-formatter 1 0 0 0.47s
✅ REPOSITORY checkov yes no no 19.42s
✅ REPOSITORY gitleaks yes no no 0.11s
✅ REPOSITORY git_diff yes no no 0.0s
✅ REPOSITORY grype yes no no 48.87s
⚠️ REPOSITORY secretlint yes 1 no 0.97s
✅ REPOSITORY syft yes no no 2.43s
✅ REPOSITORY trivy yes no no 11.88s
✅ REPOSITORY trivy-sbom yes no no 1.49s
✅ REPOSITORY trufflehog yes no no 3.59s
✅ SPELL lychee 5 0 0 2.25s
✅ YAML prettier 4 0 0 0.99s
✅ YAML v8r 4 0 0 4.81s
✅ YAML yamllint 4 0 0 0.58s

Detailed Issues

⚠️ MARKDOWN / markdownlint - 1 error
README.md:191 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
⚠️ REPOSITORY / secretlint - 1 error
README.md
   53:9  error  [SLACK_TOKEN] found slack token: ******************************  @secretlint/secretlint-rule-preset-recommend > @secretlint/secretlint-rule-slack
   74:9  error  [SLACK_TOKEN] found slack token: ***************                 @secretlint/secretlint-rule-preset-recommend > @secretlint/secretlint-rule-slack
   79:9  error  [SLACK_TOKEN] found slack token: **************                  @secretlint/secretlint-rule-preset-recommend > @secretlint/secretlint-rule-slack
  114:9  error  [SLACK_TOKEN] found slack token: *******************             @secretlint/secretlint-rule-preset-recommend > @secretlint/secretlint-rule-slack

✖ 4 problems (4 errors, 0 warnings, 0 infos)

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.3.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,COPYPASTE_JSCPD,GO_GOLANGCI_LINT,GO_REVIVE,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_GRYPE,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security

@iggy iggy merged commit 26ee490 into develop Feb 21, 2026
3 checks passed
@iggy iggy deleted the dependabot/github_actions/megalinter/megalinter-9.3.0 branch February 21, 2026 08:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant