Skip to content

build: Bump the patch-minor-action-updates group across 1 directory with 3 updates - #1

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/patch-minor-action-updates-934814c251
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/patch-minor-action-updates-934814c251

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 20, 2026 •

Copy link
Copy Markdown

Bumps the patch-minor-action-updates group with 3 updates in the / directory: oxsecurity/megalinter/flavors/c_cpp, github/codeql-action/upload-sarif and reviewdog/action-suggester.

Updates oxsecurity/megalinter/flavors/c_cpp from 10.0.0 to 10.1.0

Release notes

Sourced from oxsecurity/megalinter/flavors/c_cpp's releases.

v10.1.0

What's Changed

  • Core

    • MegaLinter now prints a crash traceback when it is killed by a fatal signal (SIGSEGV, SIGBUS…), instead of exiting silently with no clue about what happened (#8779)
    • The LLM Advisor supports a new provider, OrcaRouter, an OpenAI-compatible AI gateway: set LLM_PROVIDER: orcarouter and ORCAROUTER_API_KEY in your environment to get fix suggestions routed through OrcaRouter (see the OrcaRouter provider page) (#8826)
  • New linters

    • biome, one fast toolchain linting, formatting and sorting imports of JavaScript, TypeScript, JSX, TSX, JSON, CSS and GraphQL files, available as JAVASCRIPT_BIOME, TYPESCRIPT_BIOME, JSX_BIOME, TSX_BIOME, JSON_BIOME, CSS_BIOME and GRAPHQL_BIOME (#8706)
      • Activated only when a biome.json or biome.jsonc configuration file is found in the repository
      • Supports APPLY_FIXES (safe fixes with --write) and native SARIF output
      • EXCLUDED_DIRECTORIES are forwarded in project lint mode through a generated configuration extending the workspace one
    • ApexGuru, the AI-driven engine of Salesforce Code Analyzer, available as SALESFORCE_CODE_ANALYZER_APEXGURU (#8820)
      • Detects SOQL inefficiencies, critical anti-patterns and scalability hotspots in your .cls and .trigger files, with line-level highlights, severity ratings and suggested fixes
      • The analysis runs in a connected Salesforce org, not locally: store the auth url of the target org in a CI secret named SFDX_AUTH_URL, and MegaLinter logs in to that org before the scan
      • The scan is sent to that org explicitly, so a .sfdx/sfdx-config.json left at the root of the repository, usually naming a long gone scratch org, can not hijack it
      • Inactive by default: it activates only when SFDX_AUTH_URL is defined, so nothing changes for existing Salesforce projects
      • Requires ApexGuru to be enabled on the org: it needs Scale Center, and is available for Unlimited Edition production orgs, full copy sandboxes, Signature orgs and Scale Test customers
      • A run where the engine could not analyze anything is reported as an error rather than a silent success, together with the reason and how to fix it
      • Supports native SARIF output, like the other Code Analyzer engines
    • tofu fmt, the built-in formatter of OpenTofu (the MPL-2.0 licensed fork of Terraform), available as TERRAFORM_TOFU_FMT (#8729)
      • Analyzes .tofu files only, the OpenTofu specific extension, so it never doubles up with TERRAFORM_TERRAFORM_FMT which keeps .tf
      • To format your .tf files with OpenTofu instead, set TERRAFORM_TOFU_FMT_FILE_EXTENSIONS: [".tofu", ".tf", ".tfvars"] and DISABLE_LINTERS: [TERRAFORM_TERRAFORM_FMT]
      • Supports APPLY_FIXES to rewrite files in the canonical OpenTofu style
    • tofu validate, the built-in validator of OpenTofu, available as TERRAFORM_TOFU_VALIDATE (#8793)
      • Reports what formatters and rule-based linters can not see: unsupported or missing arguments, wrong attribute types, references to undeclared variables, locals or outputs, and broken module input contracts
      • Analyzes .tofu files only, like TERRAFORM_TOFU_FMT, leaving .tf free for a future terraform validate linter. To validate .tf files, set TERRAFORM_TOFU_VALIDATE_FILE_EXTENSIONS: [".tofu", ".tf"]
      • Validates one whole module per directory, so every .tf and .tofu file of a selected directory is parsed and can produce diagnostics
      • Every directory is initialized with tofu init -backend=false beforehand, so no state is read, no state lock is taken and no cloud credentials are needed
      • Set TERRAFORM_TOFU_VALIDATE_INIT_ARGUMENTS to change those initialization arguments, for example adding -lockfile=readonly to have an out-of-sync .terraform.lock.hcl reported as an error instead of being updated
  • Disabled linters

    • COFFEE_COFFEELINT is disabled: CoffeeScript tooling is discontinued, and coffeelint can not receive EXCLUDED_DIRECTORIES in project lint mode (it has no exclusion option and reads .coffeelintignore only from its working directory). The linter will be removed in a future version (#8720)
    • GRAPHQL_GRAPHQL_SCHEMA_LINTER is disabled: graphql-schema-linter is unmaintained, with no release or commit since May 2022, and its peer dependency range pins graphql to ^15 || ^16, which held the whole GraphQL install back from graphql v17. Use GRAPHQL_BIOME to lint your GraphQL files. The linter will be removed in a future version (#8894)
  • Re-enabled linters

    • spectral is back as API_SPECTRAL, together with the API descriptor, to lint your OpenAPI, AsyncAPI and Arazzo specifications (#8717)
      • It was removed in v10.0.0 because it crashed at startup on every run: the cause has been found and fixed
      • Nothing to change in your configuration: API_SPECTRAL works again in ENABLE_LINTERS / DISABLE_LINTERS, and the default ruleset file is still .spectral.yaml
  • Linters enhancements

    • TERRAFORM_TFLINT now documents the tflint native GITHUB_TOKEN_github_com variable to authenticate plugin downloads on github.com, which is the recommended way to fix tflint --init failures when your GITHUB_TOKEN targets a GitHub Enterprise instance (#8795)
      • Set your github.com token in GITHUB_TOKEN_github_com, then list it in TERRAFORM_TFLINT_UNSECURED_ENV_VARIABLES: tflint gives it priority over GITHUB_TOKEN, which other linters and reporters keep using
      • PAT_GITHUB_COM is deprecated: it still works and now logs a warning, and will be removed in a future major release
    • CLOJURE_CLJSTYLE now forwards EXCLUDED_DIRECTORIES through its native repeatable --ignore argument, instead of a temporary .cljstyle written in your repository. Exclusions are now also applied when your repository already has a .cljstyle config, whose own ignore patterns are preserved (#8720)
    • SQL_SQLFLUFF does not receive EXCLUDED_DIRECTORIES in project lint mode anymore: sqlfluff reads path exclusions only from a .sqlfluffignore, .sqlfluff or pyproject.toml located inside the analyzed sources, where MegaLinter used to write a temporary file. List the directories to skip in your own .sqlfluffignore, or keep the default list_of_files lint mode where MegaLinter filters the files itself (#8720)
    • SARIF output is now available for 13 more linters: zizmor, bicep_linter, cppcheck, clj-kondo, roslynator, htmlhint, protolint, sqlfluff, swiftlint, osv-scanner, trufflehog, jscpd and lintr. Enable it the same way as any other SARIF-capable linter, with SARIF_REPORTER: true (optionally scoped with SARIF_REPORTER_LINTERS) (#8715)
      • The 4 Salesforce Code Analyzer engines (SALESFORCE_CODE_ANALYZER_APEX, _AURA, _LWC, _FLOW) also gained SARIF output: their report switches from CSV to SARIF automatically when SARIF reporting is requested
      • csharp_roslynator is bumped from 0.12.0 to 0.13.0, the first release including its SARIF output support

... (truncated)

Changelog

Sourced from oxsecurity/megalinter/flavors/c_cpp's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased] (beta, main branch content)

Note: Can be used with oxsecurity/megalinter@beta in your GitHub Action mega-linter.yml file, or with oxsecurity/megalinter:beta docker image

  • Breaking changes

  • Core

  • New linters

  • Disabled linters

  • Re-enabled linters

  • Deprecated linters

  • Removed linters

  • Media

  • Linters enhancements

  • Fixes

  • Reporters

  • Flavors

  • Doc

  • mega-linter-runner

    • --container-engine container: run MegaLinter with Apple's native macOS container engine (Apple Silicon only, no Docker Desktop needed): https://github.com/apple/container
  • Agent Skills

  • Dev

  • CI

    • ApexGuru rate limits no longer fail CI test jobs: when Salesforce's ApexGuru service answers 429 Too Many Requests, the SALESFORCE_CODE_ANALYZER_APEXGURU success, failure and SARIF tests are skipped instead of failed
      • Only in CI (utils.is_ci()): local test runs still fail, so a real regression stays visible
      • Per-linter test jobs (deploy-DEV-linters.yml, deploy-BETA-linters.yml) now pass GITHUB_ACTIONS to the test container
    • test-agent-plugins.yml validation script now accepts both the {"plugins": [...], "errors": [...]} wrapper and the bare-array shape the GitHub Copilot CLI's plugins list --json can return, fixing a crash of the "Validate agent plugins manifests" check
  • Linter versions upgrades (N)

... (truncated)

Commits
  • 9949bad Release MegaLinter v10.1.0
  • 4270990 fix release workflow
  • 4d8bf14 [automation] Auto-update linters version, help and documentation (#8902)
  • 98bcce2 fix(ci): install zensical in the auto-update linters container (#8901)
  • b63dee7 fix(deps): update langchain (minor) (#8878)
  • 4d17aee fix(renovate-rebase): force UTF-8 console output in tick_dashboard (#8900)
  • b034be4 Disable the unmaintained graphql-schema-linter (#8894)
  • e00d096 chore(deps): update dependency snakemake to v9.26.1 (#8897)
  • 9591933 chore(deps): update dependency langsmith to v0.11.2 (#8896)
  • e87989e chore(deps): update dependency golangci/golangci-lint to v2.13.2 (#8895)
  • Additional commits viewable in compare view

Updates github/codeql-action/upload-sarif from 4.37.9 to 4.38.2

Release notes

Sourced from github/codeql-action/upload-sarif's releases.

v4.38.2

  • Update default CodeQL bundle version to 2.27.1. #4160

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

v4.38.0

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129
Changelog

Sourced from github/codeql-action/upload-sarif's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 2892aa5 Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f
  • 8ad03a3 Trigger workflows
  • 98af865 Update changelog for v4.38.2
  • a6ef2c9 Merge pull request #4156 from github/mario-campos/fix-validate-cmd
  • 1ef28a1 Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...
  • 26cb08b Merge pull request #4163 from github/mbg/fix-getCommitOid-stubs
  • f035ce3 Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...
  • 5e4e255 Rebuild
  • b13f5f4 Bump ruby/setup-ruby
  • c87fe57 Rebuild
  • Additional commits viewable in compare view

Updates reviewdog/action-suggester from 1.24.3 to 1.26.1

Release notes

Sourced from reviewdog/action-suggester's releases.

Release v1.26.1

What's Changed

Full Changelog: reviewdog/action-suggester@v1.26.0...v1.26.1

Release v1.26.0

What's Changed

Full Changelog: reviewdog/action-suggester@v1.25.0...v1.26.0

Release v1.25.0

What's Changed

Full Changelog: reviewdog/action-suggester@v1.24.3...v1.25.0

Commits
  • c387862 Merge pull request #137 from reviewdog/fix-path-input-does-not-work
  • 8d62657 Merge pull request #139 from reviewdog/renovate/reviewdog-action-shellcheck-1.x
  • f15af1b Merge pull request #138 from reviewdog/renovate/reviewdog-action-misspell-1.x
  • 67b551b update README.md to add the path input
  • 32f7902 chore(deps): update reviewdog/action-shellcheck action to v1.34.0
  • ce32542 chore(deps): update reviewdog/action-misspell action to v1.30.0
  • f1cc1db fix path input doesn't work. close #132
  • a435ab6 Merge pull request #136 from reviewdog/renovate/reviewdog-action-alex-1.x
  • 62fe6f1 Merge pull request #135 from reviewdog/renovate/reviewdog-action-actionlint-1.x
  • adef167 chore(deps): update reviewdog/action-alex action to v1.19.0
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 20, 2026
@github-actions

github-actions Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

✅⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ ACTION actionlint 7 0 0 0.55s
✅ CPP clang-format 158 0 0 0 2.19s
✅ CPP cppcheck 158 0 0 2.04s
✅ DOCKERFILE hadolint 1 0 0 0.66s
✅ JSON jsonlint 8 0 0 0.13s
✅ JSON prettier 8 2 0 0 0.5s
✅ MARKDOWN markdownlint 14 0 0 0 0.87s
✅ MARKDOWN markdown-table-formatter 14 0 0 0 0.18s
⚠️ SPELL lychee 60 1 0 1.17s
✅ YAML prettier 11 0 0 0 0.58s
✅ YAML yamllint 11 0 0 0.6s

Detailed Issues

⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total...........23
🔗 Unique...........9
✅ Successful......15
⏳ Timeouts.........0
🔀 Redirected.......1
👻 Excluded.........7
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1

Errors in .github/workflows/static-analysis.yml
[403] https://binaries.sonarsource.com/Distribution/sonar-scanner-cli/sonar-scanner-cli-$ (at 37:21) | Rejected status code: 403 Forbidden

Hint: Followed 1 redirect. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_GITLEAKS, REPOSITORY_KICS. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.1.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,CPP_CPPCHECK,CPP_CLANG_FORMAT,DOCKERFILE_HADOLINT,JSON_JSONLINT,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@dependabot
dependabot Bot changed the base branch from claude/focused-faraday-fpdj6z to main September 20, 2026 17:31
…ith 3 updates

Bumps the patch-minor-action-updates group with 3 updates in the / directory: [oxsecurity/megalinter/flavors/c_cpp](https://github.com/oxsecurity/megalinter), [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) and [reviewdog/action-suggester](https://github.com/reviewdog/action-suggester).


Updates `oxsecurity/megalinter/flavors/c_cpp` from 10.0.0 to 10.1.0
- [Release notes](https://github.com/oxsecurity/megalinter/releases)
- [Changelog](https://github.com/oxsecurity/megalinter/blob/main/CHANGELOG.md)
- [Commits](oxsecurity/megalinter@15e5b45...9949bad)

Updates `github/codeql-action/upload-sarif` from 4.37.9 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@cdf488f...2892aa5)

Updates `reviewdog/action-suggester` from 1.24.3 to 1.26.1
- [Release notes](https://github.com/reviewdog/action-suggester/releases)
- [Commits](reviewdog/action-suggester@2558ba1...c387862)

---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.38.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-minor-action-updates
- dependency-name: oxsecurity/megalinter/flavors/c_cpp
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-minor-action-updates
- dependency-name: reviewdog/action-suggester
  dependency-version: 1.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-minor-action-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build: Bump the patch-minor-action-updates group with 3 updates build: Bump the patch-minor-action-updates group across 1 directory with 3 updates Sep 27, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/patch-minor-action-updates-934814c251 branch from 8c3b9bc to 3ca665b Compare September 27, 2026 03:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant