Deprecate terrascan as the project is discontinued. Will be completely removed in a future version.
SALESFORCE_SFDX_SCANNER_* linters have been deprecated and will be removed in a future version. (they are replaced by SALESFORCE_CODE_ANALYZER_* linters)
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [oxsecurity/megalinter](https://github.com/oxsecurity/megalinter) | action | major | `v7` → `v9` |
---
### Release Notes
<details>
<summary>oxsecurity/megalinter (oxsecurity/megalinter)</summary>
### [`v9`](https://github.com/oxsecurity/megalinter/blob/HEAD/CHANGELOG.md#v920---2025-11-29)
[Compare Source](https://github.com/oxsecurity/megalinter/compare/v8...v9)
- New linters
- [Salesforce Code Analyzer](https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/code-analyzer.html), by [@​abdeslamads](https://github.com/abdeslamads)
- [SALESFORCE\_CODE\_ANALYZER\_APEX](https://megalinter.io/beta/descriptors/salesforce_code_analyzer_apex/)
- [SALESFORCE\_CODE\_ANALYZER\_AURA](https://megalinter.io/beta/descriptors/salesforce_code_analyzer_aura/)
- [SALESFORCE\_CODE\_ANALYZER\_LWC](https://megalinter.io/beta/descriptors/salesforce_code_analyzer_lwc/)
- Disabled linters
- Reactivate [checkov](https://megalinter.io/beta/descriptors/repository_checkov/)
- Deprecated linters
- Deprecate [terrascan](https://megalinter.io/latest/descriptors/terraform_terrascan/) as the project is discontinued. Will be completely removed in a future version.
- `SALESFORCE_SFDX_SCANNER_*` linters have been deprecated and will be removed in a future version. (they are replaced by `SALESFORCE_CODE_ANALYZER_*` linters)
- Media
- [Looking for the best CI/CD Pipeline Linting Tool? Try MegaLinter!](https://medium.com/@​SeasonedDeveloper/looking-for-the-best-ci-cd-pipeline-linting-tool-try-megalinter-d89c9eba850d), by [Seasoned Developer](https://medium.com/@​SeasonedDeveloper)
- [(Brazilian) Qualidade e Segurança em Código com MegaLinter: automatizando análises em MAUI com GitHub Actions](https://www.youtube.com/watch?v=0JGusPYE4zc), by [Canal dotNET](https://www.youtube.com/@​CanaldotNET)
- Linters enhancements
- Install dotenv-linter deterministically, by [@​bdovaz](https://github.com/bdovaz) in [#​6385](https://github.com/oxsecurity/megalinter/pull/6385)
- Fixes
- [#​6544](https://github.com/oxsecurity/megalinter/issues/6544): Add GITHUB\_TOKEN in docker build command for custom flavor
- Hide warning when compiling a regex
- Fix formatting in descriptor files to reduce changes in generated markdown, by [@​echoix](https://github.com/echoix) in [#​6449](https://github.com/oxsecurity/megalinter/pull/6449)
- Reporters
- Add conversion from Jenkins variables to related Git based reporters variables
- Doc
- Keep jsonschema html docs updated when using `build.py --doc`, by [@​echoix](https://github.com/echoix) in [#​6447](https://github.com/oxsecurity/megalinter/pull/6447)
- Commit updated license info generated from build script by [@​echoix](https://github.com/echoix) in [#​6448](https://github.com/oxsecurity/megalinter/pull/6448)
- Recreate docs/descriptors folder, delete old pages by [@​echoix](https://github.com/echoix) in [#​6451](https://github.com/oxsecurity/megalinter/pull/6451)
- Flavors
- Add GITHUB\_TOKEN in docker buildx build command for custom flavor, by [@​davidfevre-gouv-nc](https://github.com/davidfevre-gouv-nc) in [#​6545](https://github.com/oxsecurity/megalinter/pull/6545)
- CI
- Optimize performances of standalone linters releases
- Renovate: Add langchain group for package updates, by [@​echoix](https://github.com/echoix) in [#​6400](https://github.com/oxsecurity/megalinter/pull/6400)
- Refactor file handling in build.py to use pathlib for improved readability, by [@​echoix](https://github.com/echoix) in [#​6450](https://github.com/oxsecurity/megalinter/pull/6450)
- mega-linter-runner
- Handle upgrade of stefanzweifel/git-auto-commit-action to v7
- Linter versions upgrades (53)
- [actionlint](https://rhysd.github.io/actionlint/) from 1.7.7 to **1.7.9**
- [ansible-lint](https://ansible-lint.readthedocs.io/) from 25.9.1 to **25.11.1**
- [bandit](https://bandit.readthedocs.io/en/latest/) from 1.8.6 to **1.9.2**
- [bicep\_linter](https://learn.microsoft.com/en-us/azure/azure-resource-manager/bicep/linter) from 0.38.33 to **0.39.26**
- [black](https://black.readthedocs.io/en/stable/) from 25.9.0 to **25.11.0**
- [cfn-lint](https://github.com/aws-cloudformation/cfn-lint) from 1.40.0 to **1.41.0**
- [checkov](https://www.checkov.io/) from 3.2.413 to **3.2.495**
- [checkstyle](https://checkstyle.org/) from 11.1.0 to **12.1.0**
- [clippy](https://github.com/rust-lang/rust-clippy) from 0.1.90 to **0.1.91**
- [clj-kondo](https://github.com/borkdude/clj-kondo) from 2025.09.22 to **2025.10.23**
- [csharpier](https://csharpier.com/) from 1.1.2 to **1.2.1**
- [cspell](https://github.com/streetsidesoftware/cspell/tree/master/packages/cspell) from 9.2.1 to **9.3.2**
- [dotenv-linter](https://dotenv-linter.github.io/) from 3.3.0 to **4.0.0**
- [dotnet-format](https://docs.microsoft.com/en-us/dotnet/core/tools/dotnet-format) from 9.0.110 to **9.0.111**
- [editorconfig-checker](https://editorconfig-checker.github.io/) from 3.4.0 to **3.6.0**
- [git\_diff](https://git-scm.com) from 2.47.0 to **2.49.1**
- [gitleaks](https://github.com/gitleaks/gitleaks) from 8.28.0 to **8.30.0**
- [golangci-lint](https://golangci-lint.run/) from 2.5.0 to **2.6.2**
- [grype](https://github.com/anchore/grype) from 0.100.0 to **0.104.1**
- [isort](https://pycqa.github.io/isort/) from 6.1.0 to **7.0.0**
- [kics](https://www.kics.io) from 2.1.14 to **2.1.16**
- [ktlint](https://ktlint.github.io) from 1.7.1 to **1.8.0**
- [kubescape](https://github.com/kubescape/kubescape) from 3.0.41 to **3.0.45**
- [php-cs-fixer](https://cs.symfony.com/) from 3.88.2 to **3.90.0**
- [phpcs](https://github.com/PHPCSStandards/PHP_CodeSniffer) from 4.0.0 to **4.0.1**
- [phpstan](https://phpstan.org/) from 2.1.30 to **2.1.32**
- [pmd](https://pmd.github.io/) from 7.17.0 to **7.18.0**
- [powershell](https://github.com/PowerShell/PSScriptAnalyzer) from 7.5.3 to **7.5.4**
- [pylint](https://pylint.readthedocs.io) from 3.3.9 to **4.0.3**
- [pyright](https://github.com/Microsoft/pyright) from 1.1.406 to **1.1.407**
- [raku](https://raku.org/) from 2024.12 to **2025.11**
- [revive](https://revive.run/) from 1.12.0 to **1.13.0**
- [robocop](https://github.com/MarketSquare/robotframework-robocop) from 6.7.2 to **6.11.0**
- [roslynator](https://github.com/dotnet/Roslynator) from 0.10.2.0 to **0.11.0.0**
- [rst-lint](https://github.com/twolfson/restructuredtext-lint) from 1.4.0 to **2.0.2**
- [rubocop](https://rubocop.org/) from 1.81.1 to **1.81.7**
- [ruff-format](https://github.com/astral-sh/ruff) from 0.13.3 to **0.14.6**
- [ruff](https://github.com/astral-sh/ruff) from 0.13.3 to **0.14.6**
- [scalafix](https://scalacenter.github.io/scalafix/) from 0.14.3 to **0.14.4**
- [secretlint](https://github.com/secretlint/secretlint) from 11.2.4 to **11.2.5**
- [snakemake](https://snakemake.github.io/) from 9.11.9 to **9.13.7**
- [sqlfluff](https://www.sqlfluff.com/) from 3.4.2 to **3.5.0**
- [stylelint](https://stylelint.io) from 16.24.0 to **16.26.0**
- [swiftlint](https://github.com/realm/SwiftLint) from 0.61.0 to **0.62.2**
- [syft](https://github.com/anchore/syft) from 1.33.0 to **1.38.0**
- [terraform-fmt](https://developer.hashicorp.com/terraform/cli/commands/fmt) from 1.13.3 to **1.14.0**
- [terragrunt](https://terragrunt.gruntwork.io) from 0.88.1 to **0.93.10**
- [tflint](https://github.com/terraform-linters/tflint) from 0.59.1 to **0.60.0**
- [trivy-sbom](https://aquasecurity.github.io/trivy/) from 0.67.0 to **0.67.2**
- [trivy](https://aquasecurity.github.io/trivy/) from 0.67.0 to **0.67.2**
- [trufflehog](https://github.com/trufflesecurity/trufflehog) from 3.90.11 to **3.91.1**
- [vale](https://vale.sh/) from 3.12.0 to **3.13.0**
- [xmllint](https://gitlab.gnome.org/GNOME/libxml2/-/wikis/home) from 21308 to **21309**
### [`v8`](https://github.com/oxsecurity/megalinter/blob/HEAD/CHANGELOG.md#v880---2024-06-15)
[Compare Source](https://github.com/oxsecurity/megalinter/compare/v7...v8)
- Core
- Retrieve SARIF errors and warnings correctly, by [@​bdovaz](https://github.com/bdovaz) in [#​4837](https://github.com/oxsecurity/megalinter/pull/4837)
- Linters enhancements
- More config file name checks for ansible-lint activation, by [@​nvuillam](https://github.com/nvuillam) in [#​5590](https://github.com/oxsecurity/megalinter/pull/5590)
- Fixes
- Fix crash when the markdown table summary is empty, by [@​nvuillam](https://github.com/nvuillam) in [#​5363](https://github.com/oxsecurity/megalinter/pull/5363)
- Downgrade click to make rstcheck work again, by [@​nvuillam](https://github.com/nvuillam) in [#​5387](https://github.com/oxsecurity/megalinter/pull/5387)
- Doc
- Display hash as plain text in markdown, by [@​johndutchover](https://github.com/johndutchover) in [#​5420](https://github.com/oxsecurity/megalinter/pull/5420)
- Flavors
- Add Gherkin descriptor in java flavor, by [@​nvuillam](https://github.com/nvuillam) in [#​5592](https://github.com/oxsecurity/megalinter/pull/5592)
- CI
- Fix rust setup & disable codecov-cli, by [@​nvuillam](https://github.com/nvuillam) in [#​5579](https://github.com/oxsecurity/megalinter/pull/5579)
- Linter versions upgrades (50)
- [ansible-lint](https://ansible-lint.readthedocs.io/) from 25.4.0 to **25.5.0**
- [bicep\_linter](https://learn.microsoft.com/en-us/azure/azure-resource-manager/bicep/linter) from 0.35.1 to **0.36.1**
- [cfn-lint](https://github.com/aws-cloudformation/cfn-lint) from 1.34.2 to **1.36.0**
- [checkstyle](https://checkstyle.org/) from 10.23.1 to **10.25.0**
- [clippy](https://github.com/rust-lang/rust-clippy) from 0.1.86 to **0.1.87**
- [clj-kondo](https://github.com/borkdude/clj-kondo) from 2025.04.07 to **2025.06.05**
- [csharpier](https://csharpier.com/) from 1.0.1 to **1.0.2**
- [cspell](https://github.com/streetsidesoftware/cspell/tree/master/packages/cspell) from 8.19.4 to **9.1.1**
- [dartanalyzer](https://dart.dev/tools/dart-analyze) from 3.7.3 to **3.8.1**
- [devskim](https://github.com/microsoft/DevSkim) from 1.0.56 to **1.0.59**
- [dotnet-format](https://docs.microsoft.com/en-us/dotnet/core/tools/dotnet-format) from 9.0.105 to **9.0.106**
- [editorconfig-checker](https://editorconfig-checker.github.io/) from 3.2.1 to **3.3.0**
- [gitleaks](https://github.com/gitleaks/gitleaks) from 8.25.1 to **8.27.2**
- [golangci-lint](https://golangci-lint.run/) from 2.1.5 to **2.1.6**
- [grype](https://github.com/anchore/grype) from 0.91.2 to **0.94.0**
- [htmlhint](https://htmlhint.com/) from 1.1.4 to **1.5.1**
- [kics](https://www.kics.io) from 2.1.7 to **2.1.10**
- [ktlint](https://ktlint.github.io) from 1.5.0 to **1.6.0**
- [kubeconform](https://github.com/yannh/kubeconform) from 0.6.7 to **0.7.0**
- [lightning-flow-scanner](https://github.com/Lightning-Flow-Scanner) from 3.8.0 to **3.23.0**
- [ls-lint](https://ls-lint.org/) from 2.3.0 to **2.3.1**
- [markdownlint](https://github.com/DavidAnson/markdownlint) from 0.44.0 to **0.45.0**
- [mypy](https://mypy.readthedocs.io/en/stable/) from 1.15.0 to **1.16.0**
- [npm-groovy-lint](https://nvuillam.github.io/npm-groovy-lint/) from 15.1.0 to **15.2.0**
- [phpcs](https://github.com/PHPCSStandards/PHP_CodeSniffer) from 3.12.2 to **3.13.1**
- [phpstan](https://phpstan.org/) from 2.1.14 to **2.1.17**
- [pmd](https://pmd.github.io/) from 7.13.0 to **7.14.0**
- [protolint](https://github.com/yoheimuta/protolint) from 0.54.1 to **0.55.6**
- [psalm](https://psalm.dev) from Psalm.6.10.2@​ to **Psalm.6.12.0@​**
- [pylint](https://pylint.readthedocs.io) from 3.3.6 to **3.3.7**
- [pyright](https://github.com/Microsoft/pyright) from 1.1.400 to **1.1.402**
- [revive](https://revive.run/) from 1.9.0 to **1.10.0**
- [rstcheck](https://github.com/myint/rstcheck) from 6.2.4 to **6.2.5**
- [rubocop](https://rubocop.org/) from 1.75.4 to **1.76.1**
- [ruff](https://github.com/astral-sh/ruff) from 0.11.8 to **0.11.13**
- [ruff-format](https://github.com/astral-sh/ruff) from 0.11.8 to **0.11.13**
- [scalafix](https://scalacenter.github.io/scalafix/) from 0.14.2 to **0.14.3**
- [secretlint](https://github.com/secretlint/secretlint) from 9.3.2 to **10.1.0**
- [semgrep](https://semgrep.dev/) from 3.12 to **3.13**
- [sfdx-scanner-apex](https://forcedotcom.github.io/sfdx-scanner/) from 4.11.0 to **4.12.0**
- [sfdx-scanner-aura](https://forcedotcom.github.io/sfdx-scanner/) from 4.11.0 to **4.12.0**
- [sfdx-scanner-lwc](https://forcedotcom.github.io/sfdx-scanner/) from 4.11.0 to **4.12.0**
- [snakemake](https://snakemake.readthedocs.io/en/stable/) from 8.27.1 to **9.5.1**
- [sqlfluff](https://www.sqlfluff.com/) from 3.4.0 to **3.4.1**
- [stylelint](https://stylelint.io) from 16.19.1 to **16.20.0**
- [syft](https://github.com/anchore/syft) from 1.23.1 to **1.27.1**
- [terraform-fmt](https://developer.hashicorp.com/terraform/cli/commands/fmt) from 1.11.4 to **1.12.2**
- [terragrunt](https://terragrunt.gruntwork.io) from 0.78.0 to **0.81.6**
- [tflint](https://github.com/terraform-linters/tflint) from 0.57.0 to **0.58.0**
- [trivy](https://aquasecurity.github.io/trivy/) from 0.62.0 to **0.63.0**
- [trivy-sbom](https://aquasecurity.github.io/trivy/) from 0.62.0 to **0.63.0**
- [trufflehog](https://github.com/trufflesecurity/trufflehog) from 3.88.27 to **3.89.1**
- [v8r](https://github.com/chris48s/v8r) from 4.4.0 to **5.0.0**
</details>
---
### Configuration
📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS4xMTkuNSIsInVwZGF0ZWRJblZlciI6IjQyLjYzLjAiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
v7→v9Release Notes
oxsecurity/megalinter (oxsecurity/megalinter)
v9Compare Source
New linters
Disabled linters
Deprecated linters
SALESFORCE_SFDX_SCANNER_*linters have been deprecated and will be removed in a future version. (they are replaced bySALESFORCE_CODE_ANALYZER_*linters)Media
Linters enhancements
Fixes
Reporters
Doc
build.py --doc, by @echoix in #6447Flavors
CI
mega-linter-runner
Linter versions upgrades (53)
v8Compare Source
Core
Linters enhancements
Fixes
Doc
Flavors
CI
Linter versions upgrades (50)
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.
bd11fd2844to3b03c0e15a