Skip to content

Bump github/codeql-action/upload-sarif from 6e93df3c1b954c609ccb2761345ddc9dba76b649 to b6a472f63d85b9c78a3ac5e89422239fc15e9b3c - #23

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/github/codeql-action/upload-sarif-b6a472f63d85b9c78a3ac5e89422239fc15e9b3c
Open

Bump github/codeql-action/upload-sarif from 6e93df3c1b954c609ccb2761345ddc9dba76b649 to b6a472f63d85b9c78a3ac5e89422239fc15e9b3c#23
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/github/codeql-action/upload-sarif-b6a472f63d85b9c78a3ac5e89422239fc15e9b3c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown

Bumps github/codeql-action/upload-sarif from 6e93df3c1b954c609ccb2761345ddc9dba76b649 to b6a472f63d85b9c78a3ac5e89422239fc15e9b3c.

Changelog

Sourced from github/codeql-action/upload-sarif's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

4.37.2 - 21 Jul 2026

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #4007

4.37.1 - 16 Jul 2026

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #3956
  • Update default CodeQL bundle version to 2.26.1. #4019

4.37.0 - 08 Jul 2026

  • Update default CodeQL bundle version to 2.26.0. #3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973

4.36.3 - 01 Jul 2026

No user facing changes.

4.36.2 - 04 Jun 2026

  • Cache CodeQL CLI version information across Actions steps. #3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #3937
  • Update default CodeQL bundle version to 2.25.6. #3948

4.36.1 - 02 Jun 2026

No user facing changes.

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 6e93df3c1b954c609ccb2761345ddc9dba76b649 to b6a472f63d85b9c78a3ac5e89422239fc15e9b3c.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@6e93df3...b6a472f)

---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: b6a472f63d85b9c78a3ac5e89422239fc15e9b3c
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 3, 2026
@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

MegaLinter analysis: Error

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 1 0 0 0.19s
❌ ACTION zizmor 1 0 1 0 0.58s
❌ COPYPASTE jscpd yes 3755 no 29.61s
✅ REPOSITORY betterleaks yes no no 3.18s
❌ REPOSITORY checkov yes 5 no 34.37s
❌ REPOSITORY devskim yes 62 154 82.38s
✅ REPOSITORY dustilock yes no no 0.07s
✅ REPOSITORY gitleaks yes no no 20.78s
✅ REPOSITORY git_diff yes no no 0.41s
✅ REPOSITORY grype yes no no 91.33s
✅ REPOSITORY kingfisher yes no no 16.21s
❌ REPOSITORY osv-scanner yes 1 no 2.28s
✅ REPOSITORY secretlint yes no no 51.52s
✅ REPOSITORY syft yes no no 2.52s
✅ REPOSITORY trivy yes no no 12.46s
✅ REPOSITORY trivy-sbom yes no no 0.4s
✅ REPOSITORY trufflehog yes no no 8.15s
❌ SPELL cspell 2 5 0 5.51s
✅ SPELL lychee 1 0 0 0.16s
✅ YAML prettier 1 0 0 0 0.81s
✅ YAML v8r 1 0 0 4.02s
✅ YAML yamllint 1 0 0 1.08s

Detailed Issues

❌ REPOSITORY / checkov - 5 errors
terraform_plan scan results:

Passed checks: 0, Failed checks: 0, Skipped checks: 0, Parsing errors: 6

gitlab_ci scan results:

Passed checks: 7, Failed checks: 0, Skipped checks: 0

github_actions scan results:

Passed checks: 330, Failed checks: 5, Skipped checks: 0

Check: CKV_GHA_7: "The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. "
	FAILED for resource: on(Create Release)
	File: /.github/workflows/create_release.yml:7-12

		7  |       version:
		8  |         description: 'New Version (do not include v)'
		9  |         required: true
		10 | 
		11 | jobs:
		12 |   release:

Check: CKV2_GHA_1: "Ensure top-level permissions are not set to write-all"
	FAILED for resource: on(Post Release)
	File: /.github/workflows/post_release.yml:0-1
Check: CKV2_GHA_1: "Ensure top-level permissions are not set to write-all"
	FAILED for resource: on(Update translation files)
	File: /.github/workflows/lupdate.yml:0-1
Check: CKV2_GHA_1: "Ensure top-level permissions are not set to write-all"
	FAILED for resource: on(Create Release)
	File: /.github/workflows/create_release.yml:0-1
Check: CKV2_GHA_1: "Ensure top-level permissions are not set to write-all"
	FAILED for resource: on(Labeler)
	File: /.github/workflows/label.yml:15-16
❌ SPELL / cspell - 5 errors
.github/workflows/devskim.yml:33:43     - Unknown word (sarif)      -- codeql-action/upload-sarif@b6a472f63d85b9c78a3ac
	 Suggestions: [sari, saris, serif, sadi, saic]
.github/workflows/devskim.yml:35:11     - Unknown word (sarif)      -- sarif_file: devskim-results
	 Suggestions: [sari, saris, serif, sadi, saic]
.github/workflows/devskim.yml:35:23     - Unknown word (devskim)    -- sarif_file: devskim-results.sarif
	 Suggestions: [desk, devi, devs, dkim, deism]
.github/workflows/devskim.yml:35:39     - Unknown word (sarif)      -- file: devskim-results.sarif
	 Suggestions: [sari, saris, serif, sadi, saic]
ab9f59f7-006b-4ca2-a5bf-6111c15cf427-megalinter_file_names_cspell.txt:1:19      - Unknown word (devskim)    -- github workflows devskim
	 Suggestions: [desk, devi, devs, dkim, deism]
CSpell: Files checked: 2, Issues found: 5 in 2 files.


You can skip this misspellings by defining the following .cspell.json file at the root of your repository
Of course, please correct real typos before :)

{
    "version": "0.2",
    "language": "en",
    "ignorePaths": [
        "**/node_modules/**",
        "**/vscode-extension/**",
        "**/.git/**",
        "**/.pnpm-lock.json",
        ".vscode",
        "package-lock.json",
        "megalinter-reports"
    ],
    "words": [
        "devskim",
        "sarif"
    ]
}


You can also copy-paste megalinter-reports/.cspell.json at the root of your repository
❌ REPOSITORY / devskim - 62 errors
illa/lexers/LexPowerPro.cxx"},"replacements":[{"deletedRegion":{"charOffset":5645,"charLength":14},"insertedContent":{"text":"strlen_s(s_save, <size of s_save>)"}}]}]},{"description":{"text":"If a string is missing a null terminator, strlen will read past the end of the buffer"},"artifactChanges":[{"artifactLocation":{"uri":"thirdparty/lexilla/lexers/LexPowerPro.cxx"},"replacements":[{"deletedRegion":{"charOffset":5645,"charLength":14},"insertedContent":{"text":"strnlen(s_save, <size of s_save>)"}}]}]}],"properties":{"tags":["API.DangerousAPI.ProblematicFunction"],"DevSkimSeverity":"BestPractice","DevSkimConfidence":"High"}},{"ruleId":"DS185832","level":"error","message":{"text":"Banned C function detected (strcpy)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"thirdparty/lexilla/lexers/LexPowerPro.cxx"},"region":{"startLine":158,"startColumn":3,"endLine":158,"endColumn":19,"charOffset":5598,"charLength":16,"snippet":{"text":"strcpy(s_save,s)","rendered":{"text":"strcpy(s_save,s)","markdown":"`strcpy(s_save,s)`"}},"sourceLanguage":"cpp"}}}],"fixes":[{"description":{"text":"strcpy is frequently dangerous, as it will cause a buffer overflow if the source is larger than the destination."},"artifactChanges":[{"artifactLocation":{"uri":"thirdparty/lexilla/lexers/LexPowerPro.cxx"},"replacements":[{"deletedRegion":{"charOffset":5598,"charLength":16},"insertedContent":{"text":"strcpy_s(s_save, <size of s_save>, s)"}}]}]},{"description":{"text":"strcpy is frequently dangerous, as it will cause a buffer overflow if the source is larger than the destination."},"artifactChanges":[{"artifactLocation":{"uri":"thirdparty/lexilla/lexers/LexPowerPro.cxx"},"replacements":[{"deletedRegion":{"charOffset":5598,"charLength":16},"insertedContent":{"text":"strlcpy(s_save, s, <size of s_save>)"}}]}]}],"properties":{"tags":["API.DangerousAPI.BannedFunction"],"DevSkimSeverity":"Important","DevSkimConfidence":"High"}},{"ruleId":"DS137138","message":{"text":"Insecure URL"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"thirdparty/lexilla/lexers/LexPowerPro.cxx"},"region":{"startLine":3,"startColumn":65,"endLine":3,"endColumn":93,"charOffset":128,"charLength":28,"snippet":{"text":"http://powerpro.webeddie.com","rendered":{"text":"http://powerpro.webeddie.com","markdown":"`http://powerpro.webeddie.com`"}},"sourceLanguage":"cpp"}}}],"fixes":[{"description":{"text":"An HTTP-based URL without TLS was detected."},"artifactChanges":[{"artifactLocation":{"uri":"thirdparty/lexilla/lexers/LexPowerPro.cxx"},"replacements":[{"deletedRegion":{"charOffset":128,"charLength":28},"insertedContent":{"text":"https://powerpro.webeddie.com"}}]}]}],"properties":{"tags":["ThreatModel.Integration.HTTP"],"DevSkimSeverity":"Moderate","DevSkimConfidence":"High"},"level":"warning"},{"ruleId":"DS154189","message":{"text":"Banned C function detected"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"thirdparty/scintilla/qt/ScintillaEditBase/ScintillaQt.h"},"region":{"startLine":21,"startColumn":10,"endLine":21,"endColumn":15,"charOffset":521,"charLength":5,"snippet":{"text":"ctime","rendered":{"text":"ctime","markdown":"`ctime`"}},"sourceLanguage":"c"}}}],"properties":{"tags":["API.DangerousAPI.BannedFunction"],"DevSkimSeverity":"Moderate","DevSkimConfidence":"High"},"level":"warning"},{"ruleId":"DS137138","message":{"text":"Insecure URL"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"thirdparty/scintilla/cocoa/ScintillaTest/main.m"},"region":{"startLine":7,"startColumn":73,"endLine":7,"endColumn":97,"charOffset":209,"charLength":24,"snippet":{"text":"http://www.scintilla.org","rendered":{"text":"http://www.scintilla.org","markdown":"`http://www.scintilla.org`"}},"sourceLanguage":"objective-c"}}}],"fixes":[{"description":{"text":"An HTTP-based URL without TLS was detected."},"artifactChanges":[{"artifactLocation":{"uri":"thirdparty/scintilla/cocoa/ScintillaTest/main.m"},"replacements":[{"deletedRegion":{"charOffset":209,"charLength":24},"insertedContent":{"text":"https://www.scintilla.org"}}]}]}],"properties":{"tags":["ThreatModel.Integration.HTTP"],"DevSkimSeverity":"Moderate","DevSkimConfidence":"High"},"level":"warning"},{"ruleId":"DS137138","message":{"text":"Insecure URL"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"thirdparty/lexilla/test/examples/json/AllStyles.json"},"region":{"startLine":31,"startColumn":1,"endLine":31,"endColumn":13,"charOffset":258,"charLength":12,"snippet":{"text":"http://9.org","rendered":{"text":"http://9.org","markdown":"`http://9.org`"}},"sourceLanguage":"json"}}}],"fixes":[{"description":{"text":"An HTTP-based URL without TLS was detected."},"artifactChanges":[{"artifactLocation":{"uri":"thirdparty/lexilla/test/examples/json/AllStyles.json"},"replacements":[{"deletedRegion":{"charOffset":258,"charLength":12},"insertedContent":{"text":"https://9.org"}}]}]}],"properties":{"tags":["ThreatModel.Integration.HTTP"],"DevSkimSeverity":"Moderate","DevSkimConfidence":"High"},"level":"warning"},{"ruleId":"DS162092","level":"note","message":{"text":"Do not leave debug code in production"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"thirdparty/scintilla/cocoa/ScintillaTest/TestData.sql"},"region":{"startLine":93,"startColumn":43,"endLine":93,"endColumn":52,"charOffset":3583,"charLength":9,"snippet":{"text":"localhost","rendered":{"text":"localhost","markdown":"`localhost`"}},"sourceLanguage":"sql"}}}],"properties":{"tags":["Hygiene.Network.AccessingLocalhost"],"DevSkimSeverity":"ManualReview","DevSkimConfidence":"High"}},{"ruleId":"DS162092","level":"note","message":{"text":"Do not leave debug code in production"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"thirdparty/scintilla/cocoa/ScintillaTest/TestData.sql"},"region":{"startLine":86,"startColumn":25,"endLine":86,"endColumn":34,"charOffset":3314,"charLength":9,"snippet":{"text":"localhost","rendered":{"text":"localhost","markdown":"`localhost`"}},"sourceLanguage":"sql"}}}],"properties":{"tags":["Hygiene.Network.AccessingLocalhost"],"DevSkimSeverity":"ManualReview","DevSkimConfidence":"High"}},{"ruleId":"DS176209","level":"note","message":{"text":"Suspicious comment"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"thirdparty/lexilla/test/examples/ruby/Issue69.rb"},"region":{"startLine":40,"startColumn":2,"endLine":40,"endColumn":6,"charOffset":546,"charLength":4,"snippet":{"text":"TODO","rendered":{"text":"TODO","markdown":"`TODO`"}},"sourceLanguage":"ruby"}}}],"properties":{"tags":["Hygiene.Comment.Suspicious"],"DevSkimSeverity":"ManualReview","DevSkimConfidence":"High"}}],"columnKind":"utf16CodeUnits"}]}

(Truncated to last 6666 characters out of 920579)
❌ COPYPASTE / jscpd - 3755 errors
──┼──────────────┼──────────────────┼───────────────────┤
│ fsharp     │ 5              │ 277         │ 1434         │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ gdscript   │ 2              │ 88          │ 151          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ julia      │ 1              │ 24          │ 108          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ latex      │ 3              │ 96          │ 555          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ log        │ 26             │ 4000        │ 25334        │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ lua        │ 91             │ 8909        │ 42707        │ 94           │ 2562 (28.76%)    │ 12925 (30.26%)    │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ nsis       │ 6              │ 4419        │ 30952        │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ objectivec │ 6              │ 8155        │ 65627        │ 21           │ 187 (2.29%)      │ 2717 (4.14%)      │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ ocaml      │ 1              │ 49          │ 219          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ pascal     │ 6              │ 329         │ 1348         │ 1            │ 6 (1.82%)        │ 50 (3.71%)        │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ perl       │ 4              │ 491         │ 2116         │ 1            │ 12 (2.44%)       │ 51 (2.41%)        │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ php        │ 5              │ 113         │ 567          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ powershell │ 2              │ 97          │ 133          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ prolog     │ 4              │ 289         │ 2719         │ 2            │ 40 (13.84%)      │ 488 (17.95%)      │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ properties │ 40             │ 838         │ 7695         │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ python     │ 88             │ 11882       │ 76001        │ 83           │ 814 (6.85%)      │ 12810 (16.86%)    │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ r          │ 1              │ 51          │ 97           │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ ruby       │ 5              │ 301         │ 1007         │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ rust       │ 2              │ 47          │ 214          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ smalltalk  │ 1              │ 52          │ 314          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ sql        │ 3              │ 354         │ 1886         │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ toml       │ 1              │ 193         │ 765          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ txt        │ 35             │ 4379        │ 37441        │ 13           │ 456 (10.41%)     │ 6588 (17.60%)     │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ typescript │ 19             │ 40760       │ 418848       │ 2113         │ 19564 (48.00%)   │ 199191 (47.56%)   │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ vbnet      │ 2              │ 65          │ 138          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ vhdl       │ 1              │ 57          │ 252          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ zig        │ 1              │ 294         │ 1368         │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ Total:     │ 1003           │ 347730      │ 2965194      │ 3755         │ 65611 (18.87%)   │ 696011 (23.47%)   │
└────────────┴────────────────┴─────────────┴──────────────┴──────────────┴──────────────────┴───────────────────┘
Found 3755 clones.
HTML report saved to megalinter-reports/copy-paste/jscpd-report.html
ERROR: jscpd found too many duplicates (18.9%) over threshold (0.0%)
time: 7.91s

(Truncated to last 6666 characters out of 558009)
❌ REPOSITORY / osv-scanner - 1 error
Scanning dir .
Starting filesystem walk for root: /
Scanned thirdparty/lexilla file and found 0 packages
Scanned thirdparty/scintilla file and found 0 packages
Scanned thirdparty/lua file and found 1 package
Scanned thirdparty/uchardet file and found 0 packages
End status: 214 dirs visited, 2184 inodes visited, 4 Extract calls, 1.774943966s elapsed, 1.774944267s wall time

Total 1 package affected by 2 known vulnerabilities (1 Critical, 1 High, 0 Medium, 0 Low, 0 Unknown) from 1 ecosystem.
0 vulnerabilities can be fixed.

+--------------------------------+------+-----------+---------+---------+---------------+----------------+
| OSV URL                        | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE         |
+--------------------------------+------+-----------+---------+---------+---------------+----------------+
| https://osv.dev/CVE-2020-27304 | 9.8  | GIT       |         |         | --            | thirdparty/lua |
| https://osv.dev/CVE-2025-9648  | 8.7  | GIT       |         |         | --            | thirdparty/lua |
+--------------------------------+------+-----------+---------+---------+---------------+----------------+
❌ ACTION / zizmor - 1 error
INFO zizmor: 🌈 zizmor v1.25.0
fatal: no audit was performed
'artipacked' audit failed on file://.github/workflows/devskim.yml

Caused by:
    0: error in 'artipacked' audit
    1: couldn't list tags for actions/checkout
    2: request error while accessing GitHub API
    3: HTTP status client error (401 Unauthorized) for url (https://github.com/actions/checkout.git/git-upload-pack)

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants