tyriis / home-ops

IaC for my HomeLab kubernetes cluster resources with Flux
https://github.com/tyriis/home-ops/blob/main/README.md
40 stars 2 forks source link

ci(github-action): update oxsecurity/megalinter ( v8.2.0 β†’ v8.3.0 ) #4029

Closed tyriis-automation[bot] closed 6 days ago

tyriis-automation[bot] commented 6 days ago

This PR contains the following updates:

Package Type Update Change OpenSSF
oxsecurity/megalinter action minor v8.2.0 -> v8.3.0 OpenSSF Scorecard

Release Notes

oxsecurity/megalinter (oxsecurity/megalinter) ### [`v8.3.0`](https://redirect.github.com/oxsecurity/megalinter/blob/HEAD/CHANGELOG.md#v830---2024-11-23) [Compare Source](https://redirect.github.com/oxsecurity/megalinter/compare/v8.2.0...v8.3.0) - Core - Display command log (truncated to 250 chars) even when LOG_LEVEL is not DEBUG - Allow to replace an ENV var value with the value of another ENV var before calling a PRE_COMMAND (helps for tflint run from GitHub Enterprise) - Fix handling of git submodule paths - Fixes - [trivy](https://megalinter.io/latest/descriptors/repository_trivy/): retry in case of BLOB_UNKNOWN while downloading vulnerability list - Reporters - Fix UpdatedSourcesReporter when `APPLY_FIXES` is list (array) - Fix AzureCommentReporter when the repo is not found: fallback using BUILD_REPOSITORY_ID. (+ disable space replacement in repo name with `AZURE_COMMENT_REPORTER_REPLACE_WITH_SPACES: false`) - CI - Fix Docker mirroring job for release context - Remove max parallel jobs for release linters workflow - Linter versions upgrades (13) - [cfn-lint](https://redirect.github.com/aws-cloudformation/cfn-lint) from 1.19.0 to **1.20.0** - [checkov](https://www.checkov.io/) from 3.2.298 to **3.2.311** - [csharpier](https://csharpier.com/) from 0.29.2 to **0.30.2** - [markdownlint](https://redirect.github.com/DavidAnson/markdownlint) from 0.42.0 to **0.43.0** - [phpstan](https://phpstan.org/) from 2.0.1 to **2.0.2** - [ruff](https://redirect.github.com/astral-sh/ruff) from 0.7.4 to **0.8.0** - [spectral](https://docs.stoplight.io/docs/spectral/674b27b261c3c-overview) from 6.14.1 to **6.14.2** - [stylua](https://redirect.github.com/JohnnyMorganz/StyLua) from 0.20.0 to **2.0.0** - [syft](https://redirect.github.com/anchore/syft) from 1.16.0 to **1.17.0** - [trivy-sbom](https://aquasecurity.github.io/trivy/) from 0.57.0 to **0.57.1** - [trivy](https://aquasecurity.github.io/trivy/) from 0.57.0 to **0.57.1** - [trufflehog](https://redirect.github.com/trufflesecurity/trufflehog) from 3.83.7 to **3.84.1** - [vale](https://vale.sh/) from 3.9.0 to **3.9.1**

Configuration

πŸ“… Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

β™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

πŸ”• Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Renovate Bot.

sonarcloud[bot] commented 6 days ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

tyriis-automation[bot] commented 6 days ago

πŸ¦™ MegaLinter status: βœ… SUCCESS

Descriptor Linter Files Fixed Errors Elapsed time
βœ… REPOSITORY gitleaks yes no 3.34s

See detailed report in MegaLinter reports _Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff_

MegaLinter is graciously provided by OX Security