Skip to content

Never write inside the analyzed sources: fix the random project-mode linter crashes - #8720

Merged
nvuillam merged 2 commits into
mainfrom
fix-workspace-writes-race
Aug 12, 2026
Merged

Never write inside the analyzed sources: fix the random project-mode linter crashes#8720
nvuillam merged 2 commits into
mainfrom
fix-workspace-writes-race

Conversation

@nvuillam

@nvuillam nvuillam commented Aug 11, 2026

Copy link
Copy Markdown
Member

Follow-up of #8718, where the CI turned red on an unrelated trivy crash.

The bug

Four linters generated a temporary ignore file at the root of the linted repository and deleted it after their run. Any project-mode linter walking the tree at that moment sees a file that vanishes under it:

FATAL  Fatal error  run error: fs scan error: scan error: scan failed: failed analysis:
       analyze with traversal: walk dir error: unknown error with .megalinter-secretlintignore:
       file info error: lstat ./.megalinter-secretlintignore: no such file or directory

Being a race between two linters running in parallel, it turns random builds red — and it can hit any repository, not just this one.

The invariant

MegaLinter never creates, modifies or deletes anything inside the analyzed sources; everything it generates goes to REPORT_OUTPUT_FOLDER. (APPLY_FIXES rewriting the sources stays the one deliberate exception.)

Each of the four linters was checked against its upstream capabilities rather than being special-cased:

Linter Before After Evidence
REPOSITORY_SECRETLINT .megalinter-secretlintignore at workspace root generic ignore-file forwarding, whose generated file already lands in the report folder --secretlintignore accepts a workspace-relative path
SQL_SQLFLUFF .sqlfluffignore at workspace root no forwarding in project mode, documented in the descriptor discovery.py reads ignore_paths only from config files found by _iter_config_files(), i.e. between the working directory and the analyzed path: a config passed with --config is never consulted for path exclusions
CLOJURE_CLJSTYLE .cljstyle at workspace root, written by a custom class native repeatable --ignore argument — the custom class is deleted main.clj: --ignore PATTERN, :assoc-fn conj; config/ignored? config (u/option :ignore) file shows CLI patterns add to the user's .cljstyle ignore set instead of replacing it
COFFEE_COFFEELINT .coffeelintignore at workspace root disabled (removal planned) the installed 5.2.11 --help has no exclusion option at all, and .coffeelintignore is read from process.cwd() only

sqlfluff loses exclusion forwarding in project lint mode (its default list_of_files mode is unaffected, as MegaLinter filters the files itself there). It was already conditional before: MegaLinter only wrote the ignore file when the repository had none.

cljstyle on the contrary gains behavior: exclusions used to be skipped entirely when the repository already had a .cljstyle, they are now always applied and the user's own ignore patterns are kept.

Preventing a comeback

  • cli_lint_mode_project_exclude_workspace_file_name and write_workspace_generated_file() / cleanup_workspace_generated_files() are gone, including from the descriptor JSON schema, so a descriptor reintroducing a write in the sources now fails build validation
  • .claude/rules/descriptors.md documents the invariant and lists three mechanisms instead of four (native flag, ignore file in the report folder, generated config)

Also fixed

  • REPORT_OUTPUT_FOLDER is always excluded, even when the user overrides EXCLUDED_DIRECTORIES (it used to be only a default value, silently dropped by an override)
  • It is forwarded to project-mode linters even when it does not exist yet when their command line is built: reporters write into it while linters run, so a linter started before the first report file appears could otherwise walk into it and hit the very same vanishing-file problem

Tests

  • linter_test.py: the report folder is forwarded even when absent, other directories only when they exist
  • utils_test.py: the report folder survives an EXCLUDED_DIRECTORIES override
  • The .wireit poison fixtures of clojure-style and credentials keep guarding the two remaining forwardings: test_success_project_lint_mode fails if either regresses. The sql one is removed, since sqlfluff no longer receives exclusions

Relation to #8633

#8633 fixes the same class of problem for secretlint and jscpd with a deeper rework of the secretlint ignore model. Both converge on "generated files live in the report folder"; they overlap on repository.megalinter-descriptor.yml, Linter.py and utils.py, so whichever merges second needs a rebase.

Four linters generated a temporary ignore file at the root of the linted
repository and deleted it after their run (secretlint, sqlfluff, cljstyle,
coffeelint). A file appearing then disappearing there aborts the project-mode
linters walking the tree at the same moment: trivy fails the whole run with
"walk dir error: unknown error with .megalinter-secretlintignore: no such file
or directory". Being a race, it turns random builds red.

MegaLinter now writes only in REPORT_OUTPUT_FOLDER:

- secretlint uses the generic ignore-file forwarding, whose generated file
  already lands in the report folder
- sqlfluff receives excluded directories through the ignore_paths key of a
  generated configuration copied to the report folder, its user configuration
  being preserved
- cljstyle uses its native repeatable --ignore argument, which adds patterns to
  the ignore set of the user .cljstyle instead of replacing it, so the custom
  CljstyleLinter class is not needed anymore
- coffeelint is disabled: CoffeeScript tooling is discontinued and the tool has
  no exclusion option at all, reading .coffeelintignore from its working
  directory only

The cli_lint_mode_project_exclude_workspace_file_name property and the
write_workspace_generated_file helper are removed, including from the descriptor
JSON schema so that a descriptor reintroducing a write in the sources fails
build validation.

REPORT_OUTPUT_FOLDER is also always excluded now, even when EXCLUDED_DIRECTORIES
is overridden, and it is forwarded to project-mode linters even when it does not
exist yet when their command line is built: reporters keep writing into it while
linters run.
@github-actions

github-actions Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

⚠️MegaLinter analysis: Success with warnings

⚠️ PYTHON / bandit - 177 errors
---------------------
>> Issue: [B311:blacklist] Standard pseudo-random generators are not suitable for security/cryptographic purposes.
   Severity: Low   Confidence: High
   CWE: CWE-330 (https://cwe.mitre.org/data/definitions/330.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/blacklists/blacklist_calls.html#b311-random
   Location: ./megalinter/utils_sarif.py:156:61
155	                        rule["id"] = (
156	                            rule["id"] + "_DUPLICATE_" + str(random.randint(1, 99999))
157	                        )

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:122:4
121	    )
122	    assert os.path.isdir(config.get(request_id, "DEFAULT_WORKSPACE")), (
123	        "DEFAULT_WORKSPACE "
124	        + config.get(request_id, "DEFAULT_WORKSPACE")
125	        + " is not a valid folder"
126	    )
127	

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:167:4
166	    tmp_report_folder = tempfile.gettempdir() + os.path.sep + str(uuid.uuid4())
167	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
168	    linter_name = linter.linter_name

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:241:4
240	    tmp_report_folder = tempfile.gettempdir() + os.path.sep + str(uuid.uuid4())
241	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
242	    if os.path.isfile(workspace + os.path.sep + "no_test_failure"):

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:490:4
489	    )
490	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
491	    expected_file_name = ""

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:590:4
589	        workspace += os.path.sep + "bad"
590	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
591	    # Call linter

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:690:4
689	        workspace = workspace + os.path.sep + "fix"
690	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
691	

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:796:12
795	            ]
796	            assert (len(list(diffs))) > 0, f"No changes in the {file} file"
797	

--------------------------------------------------
>> Issue: [B108:hardcoded_tmp_directory] Probable insecure usage of temp file/directory.
   Severity: Medium   Confidence: Medium
   CWE: CWE-377 (https://cwe.mitre.org/data/definitions/377.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b108_hardcoded_tmp_directory.html
   Location: ./server/server.py:81:42
80	    if item.fileUploadId:
81	        uploaded_file_path = os.path.join("/tmp/server-files", item.fileUploadId)
82	        if not os.path.isdir(uploaded_file_path):

--------------------------------------------------
>> Issue: [B108:hardcoded_tmp_directory] Probable insecure usage of temp file/directory.
   Severity: Medium   Confidence: Medium
   CWE: CWE-377 (https://cwe.mitre.org/data/definitions/377.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b108_hardcoded_tmp_directory.html
   Location: ./server/server.py:103:38
102	    file_upload_id = "FILE_" + str(uuid1())
103	    uploaded_file_path = os.path.join("/tmp/server-files", file_upload_id)
104	    os.makedirs(uploaded_file_path)

--------------------------------------------------
>> Issue: [B108:hardcoded_tmp_directory] Probable insecure usage of temp file/directory.
   Severity: Medium   Confidence: Medium
   CWE: CWE-377 (https://cwe.mitre.org/data/definitions/377.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b108_hardcoded_tmp_directory.html
   Location: ./server/server_worker.py:98:34
97	        temp_dir = self.create_temp_dir()
98	        upload_dir = os.path.join("/tmp/server-files", file_upload_id)
99	        if os.path.exists(upload_dir):

--------------------------------------------------

Code scanned:
	Total lines of code: 28307
	Total lines skipped (#nosec): 0
	Total potential issues skipped due to specifically being disabled (e.g., #nosec BXXX): 0

Run metrics:
	Total issues (by severity):
		Undefined: 0
		Low: 115
		Medium: 54
		High: 8
	Total issues (by confidence):
		Undefined: 0
		Low: 44
		Medium: 24
		High: 109
Files skipped (0):

(Truncated to last 6666 characters out of 125127)
⚠️ BASH / bash-exec - 1 error
Results of bash-exec linter (version 5.3.9)
See documentation on https://megalinter.io/beta/descriptors/bash_bash_exec/
-----------------------------------------------

✅ [SUCCESS] .automation/build_schemas_doc.sh
✅ [SUCCESS] .automation/format-tables.sh
✅ [SUCCESS] .vscode/testlinter.sh
✅ [SUCCESS] build.sh
✅ [SUCCESS] entrypoint.sh
❌ [ERROR] sh/megalinter_exec.sh
    Error: File:[sh/megalinter_exec.sh] is not executable

✅ [SUCCESS] sh/setup-runtime-user.sh
⚠️ SPELL / lychee - 54 errors
r.yml
[404] https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/%7B%7B.Group%7D%7D/%7B%7B.ResourceKind%7D%7D_%7B%7B.ResourceAPIVersion%7D%7D.json (at 72:22) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/latex.megalinter-descriptor.yml
[TIMEOUT] https://www.nongnu.org/chktex (at 26:17) | Request timed out
[TIMEOUT] https://www.nongnu.org/chktex/ (at 29:23) | Request timed out
[TIMEOUT] https://www.nongnu.org/chktex/ (at 31:38) | Request timed out

Errors in megalinter/descriptors/markdown.megalinter-descriptor.yml
[404] https://github.com/rvben/rumdl/blob/main/docs/RULES.md (at 166:23) | Rejected status code: 404 Not Found
[403] https://www.npmjs.com/package/markdown-table-formatter (at 103:17) | Rejected status code: 403 Forbidden

Errors in megalinter/descriptors/repository.megalinter-descriptor.yml
[404] https://raw.githubusercontent.com/oxsecurity/megalinter/main/docs/assets/icons/linters/betterleaks.png (at 297:26) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/rst.megalinter-descriptor.yml
[403] https://docutils.sourceforge.io/docs/ref/rst/directives.html#raw-data-pass-through (at 34:38) | Rejected status code: 403 Forbidden

Errors in megalinter/descriptors/salesforce.megalinter-descriptor.yml
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/config.html (at 374:37) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/engine-flow.html (at 371:17) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 176:17) | Error (cached)
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 276:17) | Error (cached)
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 74:17) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/rules-flow.html (at 373:23) | Rejected status code: 403 Forbidden

Errors in megalinter/descriptors/shared/biome.megalinter-linter.yml
[404] https://biomejs.dev/linter/rules/ (at 21:19) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/shared/cppcheck.megalinter-linter.yml
[403] https://cppcheck.sourceforge.io/ (at 3:13) | Rejected status code: 403 Forbidden
[403] https://cppcheck.sourceforge.io/ (at 4:14) | Rejected status code: 403 Forbidden
[403] https://cppcheck.sourceforge.io/manual.html#configuration (at 8:33) | Rejected status code: 403 Forbidden

Errors in megalinter/descriptors/spell.megalinter-descriptor.yml
[404] https://vale.sh/docs/topics/vocab/ (at 190:38) | Rejected status code: 404 Not Found | Followed 2 redirects. Redirects: https://vale.sh/docs/topics/vocab/ --[301]--> https://docs.vale.sh/topics/vocab/ --[302]--> https://docs.vale.sh/topics/vocab
[404] https://vale.sh/docs/vale-cli/structure/ (at 183:95) | Rejected status code: 404 Not Found | Followed 2 redirects. Redirects: https://vale.sh/docs/vale-cli/structure/ --[301]--> https://docs.vale.sh/vale-cli/structure/ --[302]--> https://docs.vale.sh/vale-cli/structure

Errors in megalinter/descriptors/tsx.megalinter-descriptor.yml
[404] https://eslint-react.xyz/docs/getting-started/installation (at 81:37) | Error (cached)

Errors in megalinter/descriptors/xml.megalinter-descriptor.yml
[406] https://gitlab.gnome.org/GNOME/libxml2/-/wikis/home (at 38:17) | Rejected status code: 406 Not Acceptable

Errors in README.md
[ERROR] https://ampcode.com/ (at 247:1) | HTTP/2 protocol error. Server may not support HTTP/2 properly
[301] https://future-architect.github.io/authors/%E5%AE%AE%E6%B0%B8%E5%B4%87%E5%8F%B2 (at 1973:104) | Rejected status code: 301 Moved Permanently
[TIMEOUT] https://generated.at/ (at 1314:301) | Request timed out
[404] https://github.com/oxsecurity/megalinter/stargazers (at 2119:3) | Rejected status code: 404 Not Found
[404] https://github.com/oxsecurity/megalinter/stargazers/ (at 23:1) | Error (cached)
[403] https://javascript.plainenglish.io/node-js-coding-standard-tools-with-megalinter-on-gitlab-ci-a43b55915811 (at 1956:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/@caodanju/30-seconds-to-setup-megalinter-your-go-to-tool-for-automated-code-quality-and-iac-security-969d90a5a99c (at 1941:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/@RunningMattress (at 1950:255) | Rejected status code: 403 Forbidden
[403] https://medium.com/@RunningMattress/level-up-your-unity-packages-with-ci-cd-9498d2791211 (at 1950:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/@SeasonedDeveloper (at 1937:255) | Rejected status code: 403 Forbidden
[403] https://medium.com/@SeasonedDeveloper/looking-for-the-best-ci-cd-pipeline-linting-tool-try-megalinter-d89c9eba850d (at 1937:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/datamindedbe/integrating-megalinter-to-automate-linting-across-multiple-codebases-a-technical-description-a200bb235b71 (at 1938:3) | Rejected status code: 403 Forbidden
[403] https://nicolas.vuillamy.fr/improve-uniformize-and-secure-your-code-base-with-megalinter-62ebab422c1 (at 1959:3) | Rejected status code: 403 Forbidden
[403] https://nicolas.vuillamy.fr/megalinter-sells-his-soul-and-joins-ox-security-2a91a0027628 (at 1958:3) | Rejected status code: 403 Forbidden
[403] https://nklya.medium.com/ (at 1955:255) | Rejected status code: 403 Forbidden
[403] https://nklya.medium.com/hot-to-linter-basic-things-like-trailing-whitespaces-and-newlines-7b40da8f688d (at 1955:3) | Rejected status code: 403 Forbidden
[403] https://npmjs.org/package/mega-linter-runner (at 1229:1) | Error (cached)
[403] https://npmjs.org/package/mega-linter-runner (at 1230:1) | Error (cached)
[403] https://npmjs.org/package/mega-linter-runner (at 1231:1) | Error (cached)
[403] https://npmjs.org/package/mega-linter-runner (at 21:1) | Error (cached)
[403] https://openai.com/codex/ (at 239:1) | Rejected status code: 403 Forbidden
[403] https://pmd.sourceforge.io/pmd-6.55.0/pmd_userdocs_tools_ci.html (at 2040:3) | Error (cached)
[403] https://www.npmjs.com/package/@downatthebottomofthemolehole/megalinter-mcp-server (at 1915:354) | Rejected status code: 403 Forbidden

Hint: Followed 778 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: Rejected redirectional status codes. This means some redirects were not followed. You might want to increase the limit for `-m`/`--max-redirects`.

(Truncated to last 6666 characters out of 32020)
⚠️ MARKDOWN / markdownlint - 337 errors
-Linter"]
docs/plugins.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Plugins"]
docs/quick-start.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Quick Start"]
docs/removed-linters.md:9 error MD024/no-duplicate-heading Multiple headings with the same content [Context: "Removed linters"]
docs/reporters.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Reporters"]
docs/reporters/AzureCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Azure Comment Reporter"]
docs/reporters/BitbucketCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Bitbucket Comment Reporter"]
docs/reporters/ConfigReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "IDE Configuration Reporter"]
docs/reporters/ConsoleReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Console Reporter"]
docs/reporters/EmailReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "E-mail Reporter"]
docs/reporters/FileIoReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "File.io Reporter"]
docs/reporters/GitHubCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "GitHub Comment Reporter"]
docs/reporters/GitHubCommentReporter.md:27:196 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:27:46 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:27:174 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:27:196 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:28:179 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:28:46 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:28:160 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:28:179 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:29:159 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:29:48 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:29:143 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:29:159 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:30:171 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:30:46 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:30:152 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:30:171 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubStatusReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "GitHub Status Reporter"]
docs/reporters/GitlabCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Gitlab Comment Reporter"]
docs/reporters/JsonReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "JSON Reporter"]
docs/reporters/MarkdownSummaryReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Markdown Summary Reporter"]
docs/reporters/SarifReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "SARIF Reporter (beta)"]
docs/reporters/TapReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "TAP Reporter"]
docs/reporters/TextReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Text Reporter"]
docs/reporters/UpdatedSourcesReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Updated Sources Reporter"]
docs/special-thanks.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Special thanks"]
docs/special-thanks.md:23:3 error MD045/no-alt-text Images should have alternate text (alt text)
docs/sponsor.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Sponsoring"]
docs/supported-linters.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Supported Linters"]
mega-linter-runner/README.md:27:274 error MD051/link-fragments Link fragments should be valid [Context: "[**apply formatting and auto-fixes**](#apply-fixes)"]
mega-linter-runner/README.md:27:217 error MD051/link-fragments Link fragments should be valid [Context: "[**reports in several formats**](#reports)"]
README.md:219:127 error MD051/link-fragments Link fragments should be valid [Context: "[many additional features](#mega-linter-vs-super-linter)"]
README.md:2146:3 error MD045/no-alt-text Images should have alternate text (alt text)
skills/megalinter-check/performance.md:27:601 error MD013/line-length Line length [Expected: 600; Actual: 713]
skills/megalinter-setup/agents/megalinter-runner.md:33:601 error MD013/line-length Line length [Expected: 600; Actual: 620]

(Truncated to last 6666 characters out of 44977)
⚠️ YAML / prettier - 14 errors
ged)
mega-linter-runner/generators/mega-linter-custom-flavor/templates/action.yml 2ms (unchanged)
mega-linter-runner/generators/mega-linter-custom-flavor/templates/check-new-megalinter-version.yml 12ms (unchanged)
mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor-builder.yml 14ms (unchanged)
[error] mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor.yml: SyntaxError: Implicit map keys need to be followed by map values (6:1)
[error]   4 | label: <%= CUSTOM_FLAVOR_LABEL %>
[error]   5 | linters:
[error] > 6 | <%= CUSTOM_FLAVOR_LINTERS %>
[error]     | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[error]   7 |
mega-linter-runner/generators/mega-linter-custom-flavor/templates/zizmor.yml 2ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/.drone.yml 4ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/.gitlab-ci.yml 6ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/azure-pipelines.yml 7ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/bitbucket-pipelines.yml 3ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/concourse-task.yml 3ms (unchanged)
[error] mega-linter-runner/generators/mega-linter/templates/mega-linter.yml: SyntaxError: Implicit map keys need to be followed by map values (67:11)
[error]   65 |           # Only define `secrets.PAT` if you fully understand the trade-off.
[error]   66 |           token: ${{ secrets.PAT || secrets.GITHUB_TOKEN }}
[error] > 67 |           <%- PERSIST_CREDENTIALS %>
[error]      |           ^^^^^^^^^^^^^^^^^^^^^^^^^^
[error]   68 |
[error]   69 |           # If you use VALIDATE_ALL_CODEBASE = true, you can remove this line to
[error]   70 |           # improve performance
megalinter/descriptors/action.megalinter-descriptor.yml 12ms (unchanged)
megalinter/descriptors/ansible.megalinter-descriptor.yml 11ms (unchanged)
megalinter/descriptors/api.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/arm.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/bash.megalinter-descriptor.yml 22ms (unchanged)
megalinter/descriptors/bicep.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/c.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/clojure.megalinter-descriptor.yml 12ms (unchanged)
megalinter/descriptors/cloudformation.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/coffee.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/copypaste.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/cpp.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/csharp.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/css.megalinter-descriptor.yml 12ms (unchanged)
megalinter/descriptors/dart.megalinter-descriptor.yml 12ms (unchanged)
megalinter/descriptors/dockerfile.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/editorconfig.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/env.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/gherkin.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/go.megalinter-descriptor.yml 11ms (unchanged)
megalinter/descriptors/graphql.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/groovy.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/html.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/java.megalinter-descriptor.yml 12ms (unchanged)
megalinter/descriptors/javascript.megalinter-descriptor.yml 17ms (unchanged)
megalinter/descriptors/json.megalinter-descriptor.yml 9ms (unchanged)
megalinter/descriptors/jsx.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/kotlin.megalinter-descriptor.yml 9ms (unchanged)
megalinter/descriptors/kubernetes.megalinter-descriptor.yml 15ms (unchanged)
megalinter/descriptors/latex.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/lua.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/markdown.megalinter-descriptor.yml 11ms (unchanged)
megalinter/descriptors/perl.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/php.megalinter-descriptor.yml 33ms (unchanged)
megalinter/descriptors/powershell.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/protobuf.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/python.megalinter-descriptor.yml 81ms (unchanged)
megalinter/descriptors/r.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/raku.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/repository.megalinter-descriptor.yml 89ms (unchanged)
megalinter/descriptors/robotframework.megalinter-descriptor.yml 21ms (unchanged)
megalinter/descriptors/rst.megalinter-descriptor.yml 17ms (unchanged)
megalinter/descriptors/ruby.megalinter-descriptor.yml 13ms (unchanged)
megalinter/descriptors/rust.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/salesforce.megalinter-descriptor.yml 18ms (unchanged)
megalinter/descriptors/scala.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/shared/biome.megalinter-linter.yml 5ms (unchanged)
megalinter/descriptors/shared/clang-format.megalinter-linter.yml 3ms (unchanged)
megalinter/descriptors/shared/cppcheck.megalinter-linter.yml 3ms (unchanged)
megalinter/descriptors/shared/cpplint.megalinter-linter.yml 2ms (unchanged)
megalinter/descriptors/shared/dotnet-format.megalinter-linter.yml 3ms (unchanged)
megalinter/descriptors/shared/eslint.megalinter-linter.yml 5ms (unchanged)
megalinter/descriptors/shared/prettier.megalinter-linter.yml 3ms (unchanged)
megalinter/descriptors/shared/v8r.megalinter-linter.yml 4ms (unchanged)
megalinter/descriptors/snakemake.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/spell.megalinter-descriptor.yml 40ms (unchanged)
megalinter/descriptors/sql.megalinter-descriptor.yml 12ms (unchanged)
megalinter/descriptors/swift.megalinter-descriptor.yml 9ms (unchanged)
megalinter/descriptors/tekton.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/terraform.megalinter-descriptor.yml 12ms (unchanged)
megalinter/descriptors/tsx.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/typescript.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/vbdotnet.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/xml.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/yaml.megalinter-descriptor.yml 6ms (unchanged)
server/docker-compose-dev.yml 5ms (unchanged)
server/docker-compose.yml 4ms (unchanged)
trivy-secret.yaml 1ms (unchanged)
zizmor.yml 4ms (unchanged)

(Truncated to last 6666 characters out of 12563)
⚠️ YAML / yamllint - 38 errors
.grype.yaml
  6:1       warning  missing document start "---"  (document-start)

mega-linter-runner/.eslintrc.yml
  11:9      warning  too few spaces inside empty braces  (braces)

mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor-builder.yml
  48:15     warning  too few spaces inside empty braces  (braces)

mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor.yml
  7:1       error    syntax error: could not find expected ':' (syntax)

mega-linter-runner/generators/mega-linter/templates/mega-linter.yml
  38:15     warning  too few spaces inside empty braces  (braces)
  69:11     error    syntax error: could not find expected ':' (syntax)

megalinter/descriptors/copypaste.megalinter-descriptor.yml
  19:301    warning  line too long (313 > 300 characters)  (line-length)
  25:301    warning  line too long (384 > 300 characters)  (line-length)

megalinter/descriptors/javascript.megalinter-descriptor.yml
  52:301    warning  line too long (475 > 300 characters)  (line-length)
  328:301   warning  line too long (307 > 300 characters)  (line-length)

megalinter/descriptors/jsx.megalinter-descriptor.yml
  29:301    warning  line too long (475 > 300 characters)  (line-length)

megalinter/descriptors/perl.megalinter-descriptor.yml
  25:301    warning  line too long (310 > 300 characters)  (line-length)

megalinter/descriptors/php.megalinter-descriptor.yml
  200:301   warning  line too long (389 > 300 characters)  (line-length)
  214:301   warning  line too long (302 > 300 characters)  (line-length)

megalinter/descriptors/repository.megalinter-descriptor.yml
  27:301    warning  line too long (666 > 300 characters)  (line-length)
  193:301   warning  line too long (408 > 300 characters)  (line-length)
  299:301   warning  line too long (345 > 300 characters)  (line-length)
  478:301   warning  line too long (306 > 300 characters)  (line-length)
  557:301   warning  line too long (374 > 300 characters)  (line-length)
  642:301   warning  line too long (316 > 300 characters)  (line-length)
  979:301   warning  line too long (1263 > 300 characters)  (line-length)
  1076:301  warning  line too long (879 > 300 characters)  (line-length)
  1090:301  warning  line too long (358 > 300 characters)  (line-length)
  1153:301  warning  line too long (346 > 300 characters)  (line-length)
  1160:301  warning  line too long (307 > 300 characters)  (line-length)

megalinter/descriptors/salesforce.megalinter-descriptor.yml
  54:301    warning  line too long (359 > 300 characters)  (line-length)

megalinter/descriptors/spell.megalinter-descriptor.yml
  181:301   warning  line too long (315 > 300 characters)  (line-length)

megalinter/descriptors/sql.megalinter-descriptor.yml
  27:301    warning  line too long (403 > 300 characters)  (line-length)

megalinter/descriptors/terraform.megalinter-descriptor.yml
  28:301    warning  line too long (330 > 300 characters)  (line-length)
  88:301    warning  line too long (346 > 300 characters)  (line-length)
  155:301   warning  line too long (328 > 300 characters)  (line-length)

megalinter/descriptors/tsx.megalinter-descriptor.yml
  29:301    warning  line too long (475 > 300 characters)  (line-length)

megalinter/descriptors/typescript.megalinter-descriptor.yml
  39:301    warning  line too long (475 > 300 characters)  (line-length)
  318:301   warning  line too long (314 > 300 characters)  (line-length)

mkdocs.yml
  8:301     warning  line too long (590 > 300 characters)  (line-length)
  72:5      warning  wrong indentation: expected 6 but found 4  (indentation)
  85:5      warning  wrong indentation: expected 6 but found 4  (indentation)

zizmor.yml
  1:1       warning  missing document start "---"  (document-start)

✅ Linters with no issues

actionlint, betterleaks, black, checkov, cspell, flake8, git_diff, grype, hadolint, isort, jscpd, jsonlint, markdown-table-formatter, mypy, npm-groovy-lint, osv-scanner, pylint, ruff, secretlint, shellcheck, shfmt, spectral, syft, trivy, trivy-sbom, trufflehog, v8r, v8r, xmllint, zizmor

See detailed reports in MegaLinter artifacts

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

…rding

sqlfluff reads ignore_paths only from a config file discovered between the
working directory and the analyzed path (core/linter/discovery.py
_iter_config_files), so a generated configuration passed with --config is never
consulted for path exclusions and the .wireit poison fixture was still linted.
Like coffeelint, sqlfluff simply gets no forwarding: its poison fixture is
removed and the limitation is documented in the descriptor.
@nvuillam
nvuillam merged commit 7b5f617 into main Aug 12, 2026
145 checks passed
@nvuillam
nvuillam deleted the fix-workspace-writes-race branch August 12, 2026 23:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant