Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
46 commits
Select commit Hold shift + click to select a range
2b5418e
chore: add format targets (#7829)
github-actions[bot] Jul 6, 2026
d75fbdd
chore: add format targets (#7829)
github-actions[bot] Jul 6, 2026
3484318
chore: fix versions script (#7830)
github-actions[bot] Jul 6, 2026
f9afc69
feat: update existing pr summary comment (#7848)
github-actions[bot] Jul 6, 2026
f8f9237
feat: update existing pr summary comment (#7848)
github-actions[bot] Jul 6, 2026
cc5d7a7
feat: update existing pr summary comment (#7848)
github-actions[bot] Jul 6, 2026
2942caf
deps(bundler): bump the rubocop group across 1 directory with 3 updat…
github-actions[bot] Jul 6, 2026
040410f
deps(bundler): bump the rubocop group across 1 directory with 3 updat…
github-actions[bot] Jul 6, 2026
78cec1e
deps(python): bump the pip group across 1 directory with 6 updates (#…
github-actions[bot] Jul 6, 2026
0a74ed7
deps(python): bump the pip group across 1 directory with 6 updates (#…
github-actions[bot] Jul 6, 2026
c96c677
deps(python): bump the pip group across 1 directory with 6 updates (#…
github-actions[bot] Jul 6, 2026
41f5cfa
deps(python): bump the pip group across 1 directory with 6 updates (#…
github-actions[bot] Jul 6, 2026
4aa3303
deps(python): bump the pip group across 1 directory with 6 updates (#…
github-actions[bot] Jul 6, 2026
29b50e0
deps(python): bump the pip group across 1 directory with 6 updates (#…
github-actions[bot] Jul 6, 2026
8149b3d
deps(npm): bump the npm-security-updates group across 1 directory wit…
github-actions[bot] Jul 6, 2026
f54c76f
deps(bundler): bump the rubocop group in /dependencies with 2 updates…
github-actions[bot] Jul 6, 2026
c05a998
deps(bundler): bump the rubocop group in /dependencies with 2 updates…
github-actions[bot] Jul 6, 2026
73345b3
fix: remove debug statement when calling gh api (#7889)
github-actions[bot] Jul 6, 2026
dda126b
fix: enable_github_actions_step_summary ref in debug log (#7853)
github-actions[bot] Jul 6, 2026
79a5d23
chore(npm): update overrides (#7903)
github-actions[bot] Jul 6, 2026
31a7ab2
fix: terragrunt version lookup (#7918)
github-actions[bot] Jul 6, 2026
e69e55b
chore: linter version format test (#7926)
github-actions[bot] Jul 6, 2026
cb36b18
fix(output): pass comment payload via stdin to jq and curl (#7928)
github-actions[bot] Jul 6, 2026
b8ccc4e
fix(output): pass comment payload via stdin to jq and curl (#7928)
github-actions[bot] Jul 6, 2026
8a15630
chore(trivy): move audit to dedicated workflow (#7933)
github-actions[bot] Jul 6, 2026
88dac7f
chore(trivy): move audit to dedicated workflow (#7933)
github-actions[bot] Jul 6, 2026
0118e45
chore(trivy): move audit to dedicated workflow (#7933)
github-actions[bot] Jul 6, 2026
8fc4601
chore(trivy): move audit to dedicated workflow (#7933)
github-actions[bot] Jul 6, 2026
f0c28d8
deps(bundler): bump rubocop (#7923)
github-actions[bot] Jul 6, 2026
4d58605
deps(bundler): bump rubocop (#7923)
github-actions[bot] Jul 6, 2026
2dc95cd
deps(java): bump com.puppycrawl.tools:checkstyle (#7914)
github-actions[bot] Jul 6, 2026
35dc603
deps(python): bump the pip group across 1 directory with 6 updates (#…
github-actions[bot] Jul 6, 2026
ccf4c04
deps(python): bump the pip group across 1 directory with 6 updates (#…
github-actions[bot] Jul 6, 2026
17e86c0
deps(python): bump the pip group across 1 directory with 6 updates (#…
github-actions[bot] Jul 6, 2026
2b5ee12
deps(python): bump the pip group across 1 directory with 6 updates (#…
github-actions[bot] Jul 6, 2026
f1277f3
deps(python): bump the pip group across 1 directory with 6 updates (#…
github-actions[bot] Jul 6, 2026
bebdeca
deps(python): bump the pip group across 1 directory with 6 updates (#…
github-actions[bot] Jul 6, 2026
017dac8
deps(npm): bump protobufjs (#7917)
github-actions[bot] Jul 6, 2026
1195f07
deps(npm): bump the npm group across 1 directory with 9 updates (#7939)
github-actions[bot] Jul 6, 2026
189bca0
deps(npm): bump the npm group across 1 directory with 9 updates (#7939)
github-actions[bot] Jul 6, 2026
bafec07
deps(npm): bump the npm group across 1 directory with 9 updates (#7939)
github-actions[bot] Jul 6, 2026
d1f1cfb
chore(main): release 8.7.0 (#7704)
github-actions[bot] Jul 6, 2026
4882fb4
conflicted commits cherry-picked manually
Raj-StepSecurity Jul 6, 2026
4dc1fdc
image updated to use current main code
Raj-StepSecurity Jul 13, 2026
00d56a9
dockerfile images pinned
Raj-StepSecurity Jul 13, 2026
c09608f
comments addrssed
Raj-StepSecurity Jul 13, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 4 additions & 42 deletions .github/linters/.jscpd.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,50 +4,12 @@
"**/ISSUE_TEMPLATE/bug_report.yml",
"**/ISSUE_TEMPLATE/feature_request.yml",
"**/github-step-summary.md",
"**/README.md",
"**/node_modules/**",
"**/package.json",
"**/package-lock.json",
"**/test/data/**",
"**/test/linters/ansible/**",
"**/test/linters/clojure",
"**/test/linters/cloudformation",
"**/test/linters/coffeescript",
"**/test/linters/css",
"**/test/linters/css_prettier",
"**/test/linters/dotnet_sln_format_analyzers",
"**/test/linters/dotnet_sln_format_style",
"**/test/linters/dotnet_sln_format_whitespace",
"**/test/linters/github_actions",
"**/test/linters/github_actions_zizmor",
"**/test/linters/go_modules",
"**/test/linters/html",
"**/test/linters/javascript_es",
"**/test/linters/javascript_prettier",
"**/test/linters/jscpd/bad",
"**/test/linters/latex",
"**/test/linters/perl",
"**/test/linters/php_builtin",
"**/test/linters/php_phpcs",
"**/test/linters/php_phpstan",
"**/test/linters/php_psalm",
"**/test/linters/prettier",
"**/test/linters/protobuf",
"**/test/linters/python_black",
"**/test/linters/python_flake8",
"**/test/linters/python_isort",
"**/test/linters/python_mypy",
"**/test/linters/python_pylint",
"**/test/linters/python_ruff",
"**/test/linters/r",
"**/test/linters/renovate",
"**/test/linters/ruby",
"**/test/linters/rust_2015",
"**/test/linters/rust_2018",
"**/test/linters/rust_2021",
"**/test/linters/rust_2024",
"**/test/linters/scalafmt",
"**/test/linters/typescript_es/**",
"**/test/linters/typescript_prettier/**",
"**/test/linters/vue",
"**/test/linters/vue_prettier",
"**/test/linters/**",
"**/test/linters-config/**",
"**/github_conf/**",
"**/workflows/cd.yml",
Expand Down
2 changes: 1 addition & 1 deletion .github/linters/trivy.yaml
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
---
debug: true
disable-telemetry: true
exit-code: 1
exit-on-eol: 2
ignorefile: .github/linters/.trivyignore.yaml
quiet: true
scan:
scanners:
- vuln
Expand Down
8 changes: 8 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -295,6 +295,10 @@ jobs:
CREATE_LOG_FILE: true
REMOVE_ANSI_COLOR_CODES_FROM_OUTPUT: true
VALIDATE_ALL_CODEBASE: false
# Disable dependency security audits because we have dedicated jobs for those,
# and we don't want to fail the whole linting job because vulnerabilities
# might not necessarily be fixable until patches are out.
VALIDATE_TRIVY: false
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITLEAKS_CONFIG_FILE: .gitleaks-ignore-tests.toml
FILTER_REGEX_EXCLUDE: ".*(/test/linters/|CHANGELOG.md|/test/data/detect-files-scripts/|/test/data/test-repository-contents/).*"
Expand All @@ -312,6 +316,10 @@ jobs:
env:
REMOVE_ANSI_COLOR_CODES_FROM_OUTPUT: true
VALIDATE_ALL_CODEBASE: false
# Disable dependency security audits because we have dedicated jobs for those,
# and we don't want to fail the whole linting job because vulnerabilities
# might not necessarily be fixable until patches are out.
VALIDATE_TRIVY: false
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITLEAKS_CONFIG_FILE: .gitleaks-ignore-tests.toml
FILTER_REGEX_EXCLUDE: ".*(/test/linters/|CHANGELOG.md|/test/data/detect-files-scripts/|/test/data/test-repository-contents/).*"
Expand Down
26 changes: 13 additions & 13 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -7,31 +7,31 @@
#########################################
# Get dependency images as build stages #
#########################################
FROM alpine/terragrunt:1.15.5@sha256:bcd08d0d8424ddf385b2942643fff1f9d5975af35021a6ec6664ac69e5a27a0a AS terragrunt
FROM alpine/terragrunt:1.15.6@sha256:13b651dfaa030b96e2916b51183449475626275fa302a46763d1e914fb2ddf90 AS terragrunt
FROM dotenvlinter/dotenv-linter:4.0.0@sha256:49a3c89203aeabb814e7fc028c4bcaf569c6ead29e58dbad5e348324d042d120 AS dotenv-linter
FROM ghcr.io/terraform-linters/tflint:v0.63.1@sha256:890e37827d7b5e400f26137c5189c7efa581365fe9299b5b9814e5148d5978b9 AS tflint
FROM alpine/helm:4.2.0@sha256:af08f75a3130d666a50b9fc150f40987ef20b885cf67659aabf4b83a5f2c5501 AS helm
FROM golang:1.26-alpine@sha256:f23e8b227fb4493eabe03bede4d5a32d04092da71962f1fb79b5f7d1e6c2a17f AS golang
FROM alpine/helm:4.2.1@sha256:f48dee30f194256463e61bf127acb2d50e9f46968c4fdb1243e67d96d9aba164 AS helm
FROM golang:1.26.4-alpine@sha256:0648ddfa35769070197ba1cdf22a16dc452caf9315e66b91791308a543baf229 AS golang
FROM golangci/golangci-lint:v2.12.2@sha256:5cceeef04e53efe1470638d4b4b4f5ceefd574955ab3941b2d9a68a8c9ad5240 AS golangci-lint
FROM goreleaser/goreleaser:v2.15.4@sha256:f5ce92e9a38fb9406ccd638b95e43402cd3f4c567cb677eb06af9fd161278c12 AS goreleaser
FROM goreleaser/goreleaser:v2.16.0@sha256:bc18394563e9d064f7fd62c1ef02ccbe5fcbdd384dd118052a17e635e58f0f75 AS goreleaser
FROM hadolint/hadolint:v2.14.0-alpine@sha256:7aba693c1442eb31c0b015c129697cb3b6cb7da589d85c7562f9deb435a6657c AS dockerfile-lint
FROM registry.k8s.io/kustomize/kustomize:v5.8.1@sha256:899fcd3bc898160e62bcaf82932b0cb29ba38d16272353db2e7acbba82129429 AS kustomize
FROM hashicorp/terraform:1.15.6@sha256:adae45661e45d3c88beef071ee1277b4621cea73517aae7f0844657c8e85f641 AS terraform
FROM koalaman/shellcheck:v0.11.0@sha256:bb596a0d169b85ddd81d8b6d3a2ff6d5baf5fca10b97f575ebc647c3dff62b3d AS shellcheck
FROM mstruebing/editorconfig-checker:v3.6.1@sha256:ca20e3960d1bca908443ac2ddc900e5d10192fd68756dda962b14f8f04c22289 AS editorconfig-checker
FROM mstruebing/editorconfig-checker:v3.7.0@sha256:96cb221f9dc3ce944589995fddf2274145a6c4afd468f110de080f19bcce0f56 AS editorconfig-checker
FROM mvdan/shfmt:v3.13.1@sha256:f22f3936140be1ba02d493b5d2b91d0e8b4af93fd903e7f46c477822bca4a3be AS shfmt
FROM rhysd/actionlint:1.7.12@sha256:b1934ee5f1c509618f2508e6eb47ee0d3520686341fec936f3b79331f9315667 AS actionlint
FROM scalameta/scalafmt:v3.11.1@sha256:18a6c10f00920077e425b96301e365268332caf17d32cd19d0f63e845414e192 AS scalafmt
FROM zricethezav/gitleaks:v8.30.1@sha256:c00b6bd0aeb3071cbcb79009cb16a60dd9e0a7c60e2be9ab65d25e6bc8abbb7f AS gitleaks
FROM yoheimuta/protolint:0.56.4@sha256:c462eb6acd1327efc455e32a440c25dff78a7fe73ae40b364a4a59c11b234485 AS protolint
FROM ghcr.io/clj-kondo/clj-kondo:2026.04.15-alpine@sha256:b142ebccd72a3f980fccac2ba7553d928c00da2d6611ad4e3f2454d50f7f3fa8 AS clj-kondo
FROM dart:3.12.0-sdk@sha256:1bc3667e7e5d647bf0f00d62673790b06719ba39e108776a7cc3529887e81fb7 AS dart
FROM mcr.microsoft.com/dotnet/sdk:10.0-alpine3.23@sha256:fac7cce841f78faa4bca416fb4c636d1a129c09abd9b50e9b45664b95fd008a0 AS dotnet-sdk
FROM composer/composer:2.9.8@sha256:a250c6759909bd7abe2090457e9dc68aa7b11bc19078a3d1a7f0be1294332377 AS php-composer
FROM ghcr.io/aquasecurity/trivy:0.71.0@sha256:016eae51fdcf989332a5404af7e8f625cd5d95d7c0907a221d080a996f556500 AS trivy
FROM ghcr.io/yannh/kubeconform:v0.7.0@sha256:faffaf43f95aa6425306e1ab8d6fcad72acb9049158f38e574c085ea1ec0f64e AS kubeconform

FROM python:3.14-alpine3.23@sha256:5a824eb82cc75361f98611f3cfc5091ea33f10a6ccea4d4ebdabbc523b9a1614 AS python-base
FROM ghcr.io/clj-kondo/clj-kondo:2026.05.25-alpine@sha256:1c2a46e4156331e2953862ad7c6c7df9e07bb87157beb650de182bdb5450d0b3 AS clj-kondo
FROM dart:3.12.2-sdk@sha256:694cae58388079971a64f07258f719a2d8a8dcce42e6581b37a155ce852f2dbe AS dart
FROM mcr.microsoft.com/dotnet/sdk:10.0.301-alpine3.23@sha256:4f9e72be70a2346fe3ac95bf97374dd51e988eb66fc798dbbe56281607f4d0c0 AS dotnet-sdk
FROM composer/composer:2.10.1@sha256:43606cba7350acef196aef46795a47d65b559d39933feb92c702be1dfe51c1fc AS php-composer
FROM ghcr.io/aquasecurity/trivy:0.71.1@sha256:b5d1b07e61c375597a6e2086bc110257348bba9f9f9a3b30e6e67f3ba0b1aa06 AS trivy
FROM ghcr.io/yannh/kubeconform:v0.8.0@sha256:5103f6f5e89061728aad4ad5a250627dd0fc9b2a92eb876f3762677a4222f9e0 AS kubeconform

FROM python:3.14.6-alpine3.23@sha256:e10f6e0f219a81c65c518e339e7e9bf2f8c63b6ba1bf112e1bb2d1e395ed0c17 AS python-base

FROM python-base AS clang-format

Expand Down
37 changes: 32 additions & 5 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,6 @@ test: \
info \
validate-container-image-labels \
docker-build-check \
composer-audit \
npm-audit \
pip-audit \
test-lib \
inspec \
lint-codebase \
Expand Down Expand Up @@ -49,6 +46,13 @@ test: \
test-linters-expect-success-suppress-output-on-success-log-level-notice \
test-linters-fix-mode

.PHONY: audit ## Run dependency audits
audit: \
composer-audit \
npm-audit \
pip-audit \
trivy

SHELL := /bin/bash

# if this session isn't interactive, then we don't want to allocate a
Expand Down Expand Up @@ -246,6 +250,19 @@ pip-audit: ## Run pip-audit to check for known vulnerable dependencies
--workdir / \
$(SUPER_LINTER_TEST_CONTAINER_URL)

.PHONY: trivy
trivy: ## Run trivy to check for known vulnerable dependencies
docker run \
-e RUN_LOCAL=true \
-e DEFAULT_BRANCH=main \
-e FILTER_REGEX_EXCLUDE=".*(/test/linters/|CHANGELOG.md|/test/data/test-repository-contents/).*" \
-e SAVE_SUPER_LINTER_SUMMARY=true \
-e VALIDATE_ALL_CODEBASE=true \
-e VALIDATE_TRIVY=true \
-v "$(CURDIR):/tmp/lint" \
--rm \
$(SUPER_LINTER_TEST_CONTAINER_URL)

.PHONY: lint-codebase
lint-codebase: ## Lint the entire codebase
$(CURDIR)/test/run-super-linter-tests.sh \
Expand All @@ -263,7 +280,8 @@ fix-codebase: ## Fix and format the entire codebase

.PHONY: format-codebase ## Format the codebase
format-codebase: \
format-prettier
format-prettier \
format-shfmt

FILES_TO_FORMAT ?= .

Expand All @@ -277,6 +295,16 @@ format-prettier: ## Run prettier to format the codebase
$(SUPER_LINTER_TEST_CONTAINER_URL) \
-c "prettier --write $(FILES_TO_FORMAT) '!test/linters/**/*bad*' '!test/linters/**/*bad*/**'"

.PHONY: format-shfmt
format-shfmt: ## Run shfmt to format shell scripts in the codebase
docker run $(DOCKER_FLAGS) \
--entrypoint /bin/bash \
--rm \
-v "$(CURDIR):/tmp/lint" \
--workdir "/tmp/lint" \
$(SUPER_LINTER_TEST_CONTAINER_URL) \
-c "shfmt --write $(FILES_TO_FORMAT)"

# This is a smoke test to check how much time it takes to lint only a small
# subset of files, compared to linting the whole codebase.
.PHONY: lint-subset-files
Expand Down Expand Up @@ -688,4 +716,3 @@ test-git-valid-worktree: ## Run super-linter against a Git repository with workt
$(SUPER_LINTER_TEST_CONTAINER_URL) \
"run_test_case_git_valid_worktree" \
"$(IMAGE)"

2 changes: 1 addition & 1 deletion action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ author: "step-security"
description: "Super-linter is a ready-to-run collection of linters and code analyzers, to help validate your source code."
runs:
using: 'docker'
image: 'docker://ghcr.io/step-security/super-linter:v8.6.0@sha256:8275e6c14c43db836dbcaf6991bd67911b8a7f3ef1b88fd5e2691ac40dcc865f' #v8.6.0
image: 'docker://ghcr.io/step-security/super-linter:v8.7.0' #v8.7.0
branding:
icon: "check-square"
color: "white"
Expand Down
4 changes: 2 additions & 2 deletions dependencies/Gemfile
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,13 @@ source "https://rubygems.org"

git_source(:github) { |repo_name| "https://github.com/#{repo_name}" }

gem "rubocop", "~> 1.86.2"
gem "rubocop", "~> 1.88.0"
gem "rubocop-github", "~> 0.27.0"
gem "rubocop-minitest", "~> 0.39.1"
gem "rubocop-performance", "~>1.26.1"
gem "rubocop-rails", "~> 2.35"
gem "rubocop-rake", "~> 0.7.1"
gem "rubocop-rspec", "~> 3.9.0"
gem "rubocop-rspec", "~> 3.10.2"
gem "rubocop-capybara", "~> 2.23"
gem "rubocop-factory_bot", "~> 2.28"
gem "rubocop-rspec_rails", "~> 2.32"
15 changes: 8 additions & 7 deletions dependencies/Gemfile.lock
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ GEM
drb (2.2.3)
i18n (1.14.8)
concurrent-ruby (~> 1.0)
json (2.19.5)
json (2.19.9)
language_server-protocol (3.17.0.5)
lint_roller (1.1.0)
logger (1.7.0)
Expand All @@ -38,7 +38,7 @@ GEM
rack (3.2.6)
rainbow (3.1.1)
regexp_parser (2.12.0)
rubocop (1.86.2)
rubocop (1.88.0)
json (~> 2.3)
language_server-protocol (~> 3.17.0.2)
lint_roller (~> 1.1.0)
Expand Down Expand Up @@ -70,7 +70,7 @@ GEM
lint_roller (~> 1.1)
rubocop (>= 1.75.0, < 2.0)
rubocop-ast (>= 1.47.1, < 2.0)
rubocop-rails (2.35.1)
rubocop-rails (2.35.4)
activesupport (>= 4.2.0)
lint_roller (~> 1.1)
rack (>= 1.1)
Expand All @@ -79,9 +79,10 @@ GEM
rubocop-rake (0.7.1)
lint_roller (~> 1.1)
rubocop (>= 1.72.1)
rubocop-rspec (3.9.0)
rubocop-rspec (3.10.2)
lint_roller (~> 1.1)
rubocop (~> 1.81)
regexp_parser (>= 2.0)
rubocop (~> 1.86, >= 1.86.2)
rubocop-rspec_rails (2.32.0)
lint_roller (~> 1.1)
rubocop (~> 1.72, >= 1.72.1)
Expand All @@ -100,15 +101,15 @@ PLATFORMS
x86_64-linux-musl

DEPENDENCIES
rubocop (~> 1.86.2)
rubocop (~> 1.88.0)
rubocop-capybara (~> 2.23)
rubocop-factory_bot (~> 2.28)
rubocop-github (~> 0.27.0)
rubocop-minitest (~> 0.39.1)
rubocop-performance (~> 1.26.1)
rubocop-rails (~> 2.35)
rubocop-rake (~> 0.7.1)
rubocop-rspec (~> 3.9.0)
rubocop-rspec (~> 3.10.2)
rubocop-rspec_rails (~> 2.32)

BUNDLED WITH
Expand Down
2 changes: 1 addition & 1 deletion dependencies/checkstyle/build.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ repositories {

// Hold this dependency here so we can get automated updates using DependaBot
dependencies {
implementation 'com.puppycrawl.tools:checkstyle:13.4.2'
implementation 'com.puppycrawl.tools:checkstyle:13.6.0'
}

group 'com.github.super-linter'
Expand Down
Loading
Loading