Skip to content

chore(deps): bump devantler-tech/actions/.github/workflows/update-agent-skills.yaml from 10.1.4 to 10.2.1 - #2770

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/devantler-tech/actions/dot-github/workflows/update-agent-skills.yaml-10.2.1
Open

chore(deps): bump devantler-tech/actions/.github/workflows/update-agent-skills.yaml from 10.1.4 to 10.2.1#2770
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/devantler-tech/actions/dot-github/workflows/update-agent-skills.yaml-10.2.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 21, 2026

Copy link
Copy Markdown
Contributor

Bumps devantler-tech/actions/.github/workflows/update-agent-skills.yaml from 10.1.4 to 10.2.1.

Release notes

Sourced from devantler-tech/actions/.github/workflows/update-agent-skills.yaml's releases.

v10.2.1

10.2.1 (2026-07-21)

Continuous Integration

  • coderabbit: keep docstring coverage advisory instead of merge-blocking (#661) (6b063f9)

v10.2.0

10.2.0 (2026-07-20)

Features

  • add a repo-wide MegaLinter reusable workflow for non-Go-module repos (#663) (92201ce)
Changelog

Sourced from devantler-tech/actions/.github/workflows/update-agent-skills.yaml's changelog.

Changelog

10.2.1 (2026-07-21)

Continuous Integration

  • coderabbit: keep docstring coverage advisory instead of merge-blocking (#661) (6b063f9)

10.2.0 (2026-07-20)

Features

  • add a repo-wide MegaLinter reusable workflow for non-Go-module repos (#663) (92201ce)

10.1.4 (2026-07-18)

Bug Fixes

  • enable-auto-merge: arm auto-merge on workflow-touching PRs (#626) (b11c728)

10.1.3 (2026-07-18)

Continuous Integration

  • zizmor: deduplicate full repository scans (#640) (8ff24af)

10.1.2 (2026-07-18)

Continuous Integration

  • agent-skills: seed update tests without live setup fetches (#633) (679720e)

10.1.1 (2026-07-17)

Bug Fixes

  • validate-go-project: make the concurrency group invocation-aware (#628) (79aeb16), closes #587

10.1.0 (2026-07-17)

Features

  • setup-agent-skills: add opt-in widened retry envelope for rate-limit bursts (#617) (56fe62e)

... (truncated)

Commits
  • 9705e47 chore(main): release 10.2.1 (#699)
  • 6b063f9 ci(coderabbit): keep docstring coverage advisory instead of merge-blocking (#...
  • 5c284fd chore(main): release 10.2.0 (#696)
  • 92201ce feat: add a repo-wide MegaLinter reusable workflow for non-Go-module repos (#...
  • 7390aef chore(deps): bump ruby/setup-ruby from 1.316.0 to 1.317.0 (#689)
  • 32cd938 chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (#687)
  • 73f96c2 chore(deps): bump fluxcd/flux2/action from 2.9.1 to 2.9.2 (#685)
  • 6d79881 docs: give the README an entry point and unpack the auto-merge policy prose (...
  • 8156a3c docs(enable-auto-merge): correct the gate-lookup mint's failure-mode comment ...
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…nt-skills.yaml

Bumps [devantler-tech/actions/.github/workflows/update-agent-skills.yaml](https://github.com/devantler-tech/actions) from 10.1.4 to 10.2.1.
- [Release notes](https://github.com/devantler-tech/actions/releases)
- [Changelog](https://github.com/devantler-tech/actions/blob/main/CHANGELOG.md)
- [Commits](devantler-tech/actions@8436c4a...9705e47)

---
updated-dependencies:
- dependency-name: devantler-tech/actions/.github/workflows/update-agent-skills.yaml
  dependency-version: 10.2.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@botantler-1
botantler-1 Bot enabled auto-merge July 21, 2026 08:23
@github-actions

Copy link
Copy Markdown
Contributor

MegaLinter analysis: Error

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 8 0 0 0.63s
❌ ACTION zizmor 8 0 1 0 0.49s
⚠️ BASH bash-exec 7 4 0 0.07s
✅ BASH shellcheck 7 0 0 2.6s
✅ BASH shfmt 7 7 0 0 0.27s
❌ COPYPASTE jscpd yes 24 no 0.72s
✅ GO golangci-lint yes yes no no 21.37s
❌ GO revive 6 1 0 1.09s
✅ JSON jsonlint 62 0 0 0.53s
✅ JSON prettier 62 60 0 0 2.08s
✅ JSON v8r 62 0 0 15.98s
⚠️ MARKDOWN markdownlint 90 55 169 0 9.42s
✅ MARKDOWN markdown-table-formatter 90 68 0 0 1.2s
✅ REPOSITORY betterleaks yes no no 1.17s
❌ REPOSITORY checkov yes 287 no 56.16s
❌ REPOSITORY gitleaks yes 2 no 3.8s
✅ REPOSITORY git_diff yes no no 0.14s
✅ REPOSITORY grype yes no no 115.22s
✅ REPOSITORY osv-scanner yes no no 0.3s
✅ REPOSITORY secretlint yes no no 9.32s
✅ REPOSITORY syft yes no no 1.85s
❌ REPOSITORY trivy yes 1 no 63.49s
✅ REPOSITORY trivy-sbom yes no no 1.46s
✅ REPOSITORY trufflehog yes no no 4.32s
❌ SPELL cspell 913 8040 0 210.29s
❌ SPELL lychee 887 166 0 48.18s
✅ YAML prettier 735 26 0 0 15.75s
❌ YAML v8r 735 1 0 127.55s
✅ YAML yamllint 735 0 0 13.93s

Detailed Issues

❌ REPOSITORY / checkov - 287 errors
ecretKey: oauth2**********

Check: CKV_SECRET_6: "Base64 High Entropy String"
	FAILED for resource: HIDDEN_BY_MEGALINTER	File: /k8s/bases/infrastructure/vault-seed/push-secret-seed-r2-credentials.yaml:44-45
	Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/secrets-policies/secrets-policy-index/git-secrets-6

		44 |         secretKey: r2_a**********

Check: CKV_SECRET_6: "Base64 High Entropy String"
	FAILED for resource: HIDDEN_BY_MEGALINTER	File: /k8s/bases/infrastructure/vault-seed/push-secret-seed-r2-credentials.yaml:49-50
	Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/secrets-policies/secrets-policy-index/git-secrets-6

		49 |         secretKey: r2_se**********

Check: CKV_SECRET_6: "Base64 High Entropy String"
	FAILED for resource: HIDDEN_BY_MEGALINTER	File: /k8s/bases/infrastructure/vault-seed/push-secret-seed-velero-repo-credentials.yaml:36-37
	Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/secrets-policies/secrets-policy-index/git-secrets-6

		36 |         secretKey: repo**********

Check: CKV_SECRET_6: "Base64 High Entropy String"
	FAILED for resource: HIDDEN_BY_MEGALINTER	File: /k8s/bases/infrastructure/vault-seed/secret-actual-budget-encryption-placeholder.yaml:25-26
	Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/secrets-policies/secrets-policy-index/git-secrets-6

		25 |   password: PL**********

Check: CKV_SECRET_6: "Base64 High Entropy String"
	FAILED for resource: HIDDEN_BY_MEGALINTER	File: /k8s/providers/hetzner/apps/unifi/external-secret-wireguard.yaml:26-27
	Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/secrets-policies/secrets-policy-index/git-secrets-6

		26 |     - secretKey: pr**********

Check: CKV_SECRET_6: "Base64 High Entropy String"
	FAILED for resource: HIDDEN_BY_MEGALINTER	File: /k8s/providers/hetzner/apps/unifi/external-secret-wireguard.yaml:30-31
	Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/secrets-policies/secrets-policy-index/git-secrets-6

		30 |     - secretKey: pee**********

Check: CKV_SECRET_6: "Base64 High Entropy String"
	FAILED for resource: HIDDEN_BY_MEGALINTER	File: /k8s/providers/hetzner/infrastructure/cluster-issuers/cloudflare-api-token-external-secret.yaml:15-16
	Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/secrets-policies/secrets-policy-index/git-secrets-6

		15 |     - secretKey: ap**********

Check: CKV_SECRET_6: "Base64 High Entropy String"
	FAILED for resource: HIDDEN_BY_MEGALINTER	File: /k8s/providers/hetzner/infrastructure/external-dns/external-secret.yaml:24-25
	Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/secrets-policies/secrets-policy-index/git-secrets-6

		24 |     - secretKey: ap**********

github_actions scan results:

Passed checks: 131, Failed checks: 1, Skipped checks: 0

Check: CKV_GHA_7: "The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. "
	FAILED for resource: on(DR - Rebuild Prod)
	File: /.github/workflows/dr-rebuild.yaml:34-45

		34 |       confirm:
		35 |         description: "Type REBUILD-PROD to confirm a from-zero rebuild of the production cluster"
		36 |         required: true
		37 |         type: string
		38 |       restore:
		39 |         description: "Restore data after the rebuild (Velero resources + OpenBao raft snapshot)"
		40 |         required: false
		41 |         type: boolean
		42 |         default: true
		43 | 
		44 | permissions: {}
		45 |

(Truncated to last 3636 characters out of 182358)
❌ SPELL / cspell - 8040 errors
"spiffe",
        "spotfleet",
        "sshpub",
        "sslmode",
        "stakater",
        "standbyok",
        "statefulset",
        "statemanager",
        "stdlib",
        "stefanprodan",
        "stepsecurity",
        "storageclass",
        "storageclasses",
        "storageprofiles",
        "stylesheet",
        "subchart",
        "subcharts",
        "subfolders",
        "subjectaccessreviews",
        "subresource",
        "switchovers",
        "syft",
        "syft's",
        "synthesised",
        "syscall",
        "syscalls",
        "sysctls",
        "tagless",
        "talosconfig",
        "talosctl",
        "tanzu",
        "tcproutes",
        "teammemberships",
        "teamrepositories",
        "templatesyncignore",
        "tfyx",
        "tini",
        "tlsinterception",
        "tlsroutes",
        "tokenreviews",
        "tolerations",
        "tracefs",
        "tracepoints",
        "trafficroutes",
        "trixie",
        "trustd",
        "ubiquiti",
        "udmrepo",
        "udproutes",
        "umami",
        "umami's",
        "unbypassable",
        "uncertifiable",
        "undercommits",
        "undrainable",
        "unevictable",
        "unexecutable",
        "unifi",
        "uninitcode",
        "unmarshal",
        "unmarshals",
        "unparseable",
        "unreachability",
        "unrecognised",
        "unrequested",
        "unreviewed",
        "unroutable",
        "unsealer",
        "unshippable",
        "untrackable",
        "unvalidated",
        "upbound",
        "updatekeys",
        "upjet",
        "uploadproxy",
        "upstack",
        "upstreaming",
        "uptodate",
        "urlencode",
        "usbredir",
        "userlist",
        "userns",
        "ushfn",
        "uwsgi",
        "validatable",
        "validatingadmissionpolicies",
        "validatingadmissionpolicybindings",
        "validatingwebhookconfigurations",
        "vaner",
        "vcunav",
        "velero",
        "velero's",
        "verticalpodautoscalers",
        "virt",
        "virtiofs",
        "virtualisation",
        "virtualmachinebackups",
        "virtualmachinebackuptrackers",
        "virtualmachineclones",
        "virtualmachineclusterinstancetypes",
        "virtualmachineclusterpreferences",
        "virtualmachineexports",
        "virtualmachineinstancemigrations",
        "virtualmachineinstancepresets",
        "virtualmachineinstancereplicasets",
        "virtualmachineinstances",
        "virtualmachineinstancetypes",
        "virtualmachinepools",
        "virtualmachinepreferences",
        "virtualmachinerestores",
        "virtualmachines",
        "virtualmachinesnapshotcontents",
        "virtualmachinesnapshots",
        "virtualmachinetemplaterequests",
        "virtualmachinetemplates",
        "visualises",
        "vmlinux",
        "volumeclonesources",
        "volumepopulators",
        "volumesnapshot",
        "volumesnapshotclasses",
        "volumesnapshotcontents",
        "volumesnapshots",
        "vsock",
        "vulnprocessing",
        "vxlan",
        "webapps",
        "wffc",
        "wgpolicyk",
        "wildcarded",
        "winget",
        "wmem",
        "workloadconfigurationscan",
        "workloadconfigurationscansummaries",
        "workstreams",
        "worktrees",
        "xpkg",
        "xunit",
        "yamldecode",
        "yamlencode",
        "yamls",
        "yannh",
        "yubikey",
        "yzwvjjmcyfnl",
        "zizmor",
        "zulip"
    ]
}


You can also copy-paste megalinter-reports/.cspell.json at the root of your repository

(Truncated to last 3636 characters out of 1532562)
❌ REPOSITORY / gitleaks - 2 errors
○
    │╲
    │ ○
    ○ ░
    ░    gitleaks

Finding:     key: REDACTED
Secret:      REDACTED
RuleID:      generic-api-key
Entropy:     3.749868
File:        k8s/bases/apps/umami/external-secret-ascoachingogvaner.yaml
Line:        29
Commit:      HIDDEN_BY_MEGALINTERAuthor:      dependabot[bot]
Email:       49699333+dependabot[bot]@users.noreply.github.com
Date:        2026-07-21T08:22:42Z
Fingerprint: ff5a79eb38402810f5c0b6351894f676a8046287:k8s/bases/apps/umami/external-secret-ascoachingogvaner.yaml:generic-api-key:29
Link:        https://github.com/devantler-tech/platform/blob/ff5a79eb38402810f5c0b6351894f676a8046287/k8s/bases/apps/umami/external-secret-ascoachingogvaner.yaml#L29

Finding:     remoteKey: REDACTED
Secret:      REDACTED
RuleID:      generic-api-key
Entropy:     3.749868
File:        k8s/bases/infrastructure/vault-seed/push-secret-push-umami-ascoachingogvaner-password.yaml
Line:        19
Commit:      HIDDEN_BY_MEGALINTERAuthor:      dependabot[bot]
Email:       49699333+dependabot[bot]@users.noreply.github.com
Date:        2026-07-21T08:22:42Z
Fingerprint: ff5a79eb38402810f5c0b6351894f676a8046287:k8s/bases/infrastructure/vault-seed/push-secret-push-umami-ascoachingogvaner-password.yaml:generic-api-key:19
Link:        https://github.com/devantler-tech/platform/blob/ff5a79eb38402810f5c0b6351894f676a8046287/k8s/bases/infrastructure/vault-seed/push-secret-push-umami-ascoachingogvaner-password.yaml#L19

8:27AM INF 1 commits scanned.
8:27AM INF scanned ~4518700 bytes (4.52 MB) in 3.69s
8:27AM WRN leaks found: 2
❌ COPYPASTE / jscpd - 24 errors
-policy/main_test.go [503:2 - 509:33] (7 lines, 103 tokens)
   scripts/validate-eks-ci-role-policy/main_test.go [943:58 - 949:33]
Clone found (go)
 - scripts/validate-eks-ci-role-policy/main_test.go [503:1 - 509:4] (7 lines, 75 tokens)
   scripts/validate-eks-ci-role-policy/main_test.go [1063:1 - 1069:4]
Clone found (go)
 - scripts/validate-eks-ci-role-policy/main_test.go [596:30 - 601:8] (6 lines, 50 tokens)
   scripts/validate-eks-ci-role-policy/main_test.go [623:44 - 628:8]
Clone found (go)
 - scripts/validate-eks-ci-role-policy/main_test.go [881:33 - 889:11] (9 lines, 118 tokens)
   scripts/validate-eks-ci-role-policy/main_test.go [893:130 - 901:11]
Clone found (go)
 - scripts/validate-eks-ci-role-policy/main_test.go [966:44 - 971:16] (6 lines, 99 tokens)
   scripts/validate-eks-ci-role-policy/main_test.go [984:31 - 989:9]
Clone found (go)
 - scripts/validate-eks-ci-role-policy/main_test.go [966:44 - 978:11] (13 lines, 233 tokens)
   scripts/validate-eks-ci-role-policy/main_test.go [1001:40 - 1013:11]
Clone found (go)
 - scripts/validate-eks-ci-role-policy/main_test.go [966:44 - 976:29] (11 lines, 213 tokens)
   scripts/validate-eks-ci-role-policy/main_test.go [1018:42 - 1029:11]
Clone found (go)
 - scripts/validate-eks-ci-role-policy/main_test.go [972:20 - 979:10] (8 lines, 135 tokens)
   scripts/validate-eks-ci-role-policy/main_test.go [989:12 - 996:11]
Clone found (go)
 - scripts/validate-eks-ci-role-policy/main_test.go [977:1 - 984:11] (8 lines, 83 tokens)
   scripts/validate-eks-ci-role-policy/main_test.go [994:1 - 1001:11]
Clone found (go)
 - scripts/validate-eks-ci-role-policy/main_test.go [1018:36 - 1030:33] (13 lines, 256 tokens)
   scripts/validate-eks-ci-role-policy/main_test.go [1034:31 - 1046:33]
Clone found (go)
 - scripts/validate-eks-ci-role-policy/main_test.go [1034:30 - 1046:18] (13 lines, 242 tokens)
   scripts/validate-eks-ci-role-policy/main_test.go [1050:38 - 1062:18]
Clone found (go)
 - scripts/validate-eks-ci-role-policy/main_test.go [1095:47 - 1100:2] (6 lines, 166 tokens)
   scripts/validate-eks-ci-role-policy/main_test.go [1149:46 - 1154:2]
Clone found (python)
 - scripts/validate-naming.py [126:52 - 132:25] (7 lines, 53 tokens)
   scripts/validate-naming.py [171:82 - 177:29]
┌────────┬────────────────┬─────────────┬──────────────┬──────────────┬──────────────────┬───────────────────┐
│ Format │ Files analyzed │ Total lines │ Total tokens │ Clones found │ Duplicated lines │ Duplicated tokens │
├────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ bash   │ 7              │ 1522        │ 5580         │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ go     │ 6              │ 3675        │ 40029        │ 19           │ 149 (4.05%)      │ 2831 (7.07%)      │
├────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ python │ 5              │ 2551        │ 14243        │ 5            │ 38 (1.49%)       │ 310 (2.18%)       │
├────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ Total: │ 18             │ 7748        │ 59852        │ 24           │ 187 (2.41%)      │ 3141 (5.25%)      │
└────────┴────────────────┴─────────────┴──────────────┴──────────────┴──────────────────┴───────────────────┘
Found 24 clones.
HTML report saved to megalinter-reports/copy-paste/jscpd-report.html
ERROR: jscpd found too many duplicates (2.4%) over threshold (0.0%)
time: 306.882ms

(Truncated to last 3636 characters out of 5687)
❌ SPELL / lychee - 166 errors
o/v2/upbound/provider-aws-iam/blobs/ (at 31:11) | Rejected status code: 404 Not Found

Errors in k8s/providers/hetzner/infrastructure/controllers/crossplane/helm-repository.yaml
[404] https://charts.crossplane.io/stable (at 7:8) | Rejected status code: 404 Not Found

Errors in k8s/providers/hetzner/infrastructure/controllers/descheduler/helm-repository.yaml
[404] https://kubernetes-sigs.github.io/descheduler/ (at 9:8) | Rejected status code: 404 Not Found

Errors in k8s/providers/hetzner/infrastructure/controllers/hcloud-csi/helm-repository.yaml
[404] https://charts.hetzner.cloud/ (at 8:8) | Rejected status code: 404 Not Found

Errors in k8s/providers/hetzner/infrastructure/controllers/ksail-operator/patches/enable-oidc.yaml
[ERROR] https://dex/ (at 23:20) | Error (cached)
[ERROR] https://ksail/ (at 26:22) | Connection failed. Check network connectivity and firewall settings

Errors in k8s/providers/hetzner/infrastructure/controllers/longhorn/helm-repository.yaml
[404] https://charts.longhorn.io/ (at 8:8) | Rejected status code: 404 Not Found

Errors in k8s/providers/hetzner/infrastructure/controllers/longhorn/http-route.yaml
[ERROR] https://longhorn/ (at 35:24) | Connection failed. Check network connectivity and firewall settings

Errors in k8s/providers/hetzner/infrastructure/controllers/simply-dns-webhook/helm-repository.yaml
[404] https://runnerm.github.io/simply-dns-webhook/ (at 7:8) | Rejected status code: 404 Not Found | Followed 1 redirect. Redirects: https://runnerm.github.io/simply-dns-webhook/ --[301]--> https://marton.pentek.dk/simply-dns-webhook/

Errors in k8s/providers/hetzner/infrastructure/coroot/cron-job-alert-autosuppressor.yaml
[ERROR] http://coroot-coroot.observability.svc.cluster.local:8080/ (at 118:25) | Connection failed. Check network connectivity and firewall settings

Errors in k8s/providers/hetzner/infrastructure/coroot/cron-job-custom-cloud-pricing.yaml
[ERROR] http://coroot-coroot.observability.svc.cluster.local:8080/ (at 116:25) | Error (cached)

Errors in k8s/providers/hetzner/infrastructure/coroot/patches/enable-ha.yaml
[ERROR] https://observability/ (at 192:18) | Connection failed. Check network connectivity and firewall settings

Errors in ksail.prod.yaml
[ERROR] https://github/ (at 179:22) | Error (cached)
[ERROR] https://github/ (at 182:22) | Error (cached)
[ERROR] https://token/ (at 178:21) | Error (cached)
[ERROR] https://token/ (at 181:21) | Error (cached)

Errors in README.md
[500] https://api.star-history.com/svg?repos=devantler-tech/platform&type=Date (at 242:2) | Rejected status code: 500 Internal Server Error

Errors in talos-local/cluster/enable-dex-oidc.yaml
[ERROR] https://dex.platform.lan/ (at 9:24) | Connection failed. Check network connectivity and firewall settings

Errors in talos/cluster/enable-dex-oidc.yaml
[ERROR] https://dex.dev.platform.devantler.tech/ (at 14:3) | Connection failed. Check network connectivity and firewall settings

Errors in talos/cluster/verify-first-party-images.yaml
[ERROR] https://github/ (at 53:22) | Error (cached)
[ERROR] https://github/ (at 64:22) | Error (cached)
[ERROR] https://github/ (at 77:22) | Error (cached)
[404] https://token.actions.githubusercontent.com/ (at 52:15) | Error (cached)
[404] https://token.actions.githubusercontent.com/ (at 63:15) | Error (cached)
[404] https://token.actions.githubusercontent.com/ (at 76:15) | Error (cached)

Hint: Followed 47 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`

(Truncated to last 3636 characters out of 22489)
❌ GO / revive - 1 error
scripts/validate-merge-group-heal/main.go:1:1: should have a package comment
scripts/validate-eks-ci-role-policy/main.go:1:1: should have a package comment
❌ REPOSITORY / trivy - 1 error
t security context may expose vulnerabilities to potential attacks that rely on privileged access.

See https://avd.aquasec.com/misconfig/ksv-0118
────────────────────────────────────────
 tests/validate-replica-floor/resources.yaml:91-94
────────────────────────────────────────
  91 ┌   template:
  92 │     metadata:
  93 │       labels:
  94 └         app: namespace-exempt
────────────────────────────────────────


KSV-0118 (HIGH): deployment normal-ha in test namespace is using the default security context, which allows root privileges
════════════════════════════════════════
Security context controls the allocation of security parameters for the pod/container/volume, ensuring the appropriate level of protection. Relying on default security context may expose vulnerabilities to potential attacks that rely on privileged access.

See https://avd.aquasec.com/misconfig/ksv-0118
────────────────────────────────────────
 tests/validate-replica-floor/resources.yaml:34-37
────────────────────────────────────────
  34 ┌         app: normal-ha
  35 │     spec:
  36 │       containers:
  37 └         - name: app
────────────────────────────────────────


KSV-0118 (HIGH): deployment normal-singleton in test namespace is using the default security context, which allows root privileges
════════════════════════════════════════
Security context controls the allocation of security parameters for the pod/container/volume, ensuring the appropriate level of protection. Relying on default security context may expose vulnerabilities to potential attacks that rely on privileged access.

See https://avd.aquasec.com/misconfig/ksv-0118
────────────────────────────────────────
 tests/validate-replica-floor/resources.yaml:16-19
────────────────────────────────────────
  16 ┌     spec:
  17 │       containers:
  18 │         - name: app
  19 └           image: nginx:1.29.0
────────────────────────────────────────


KSV-0118 (HIGH): deployment pod-label-exempt in test namespace is using the default security context, which allows root privileges
════════════════════════════════════════
Security context controls the allocation of security parameters for the pod/container/volume, ensuring the appropriate level of protection. Relying on default security context may expose vulnerabilities to potential attacks that rely on privileged access.

See https://avd.aquasec.com/misconfig/ksv-0118
────────────────────────────────────────
 tests/validate-replica-floor/resources.yaml:73-76
────────────────────────────────────────
  73 ┌       labels:
  74 │         app: pod-label-exempt
  75 │         platform.devantler.tech/replica-floor: exempt
  76 └     spec:
────────────────────────────────────────


KSV-0118 (HIGH): deployment workload-label-exempt in test namespace is using the default security context, which allows root privileges
════════════════════════════════════════
Security context controls the allocation of security parameters for the pod/container/volume, ensuring the appropriate level of protection. Relying on default security context may expose vulnerabilities to potential attacks that rely on privileged access.

See https://avd.aquasec.com/misconfig/ksv-0118
────────────────────────────────────────
 tests/validate-replica-floor/resources.yaml:54-57
────────────────────────────────────────
  54 ┌       labels:
  55 │         app: workload-label-exempt
  56 │     spec:
  57 └       containers:
────────────────────────────────────────



📣 Notices:
  - Version 0.72.0 of Trivy is now available, current version is 0.71.2

To suppress version checks, run Trivy scans with the --skip-version-check flag

(Truncated to last 3636 characters out of 912561)
❌ YAML / v8r - 1 error
✖ k8s/bases/apps/backstage/cluster.yaml is invalid

k8s/bases/apps/backstage/cluster.yaml# must NOT have additional properties, found additional property 'apiVersion'
k8s/bases/apps/backstage/cluster.yaml# must NOT have additional properties, found additional property 'kind'
k8s/bases/apps/backstage/cluster.yaml# must NOT have additional properties, found additional property 'metadata'
k8s/bases/apps/backstage/cluster.yaml# must NOT have additional properties, found additional property 'spec'

✖ k8s/bases/apps/umami/cluster.yaml is invalid

k8s/bases/apps/umami/cluster.yaml# must NOT have additional properties, found additional property 'apiVersion'
k8s/bases/apps/umami/cluster.yaml# must NOT have additional properties, found additional property 'kind'
k8s/bases/apps/umami/cluster.yaml# must NOT have additional properties, found additional property 'metadata'
k8s/bases/apps/umami/cluster.yaml# must NOT have additional properties, found additional property 'spec'

✖ k8s/providers/hetzner/infrastructure/coroot/cluster.yaml is invalid

k8s/providers/hetzner/infrastructure/coroot/cluster.yaml# must NOT have additional properties, found additional property 'apiVersion'
k8s/providers/hetzner/infrastructure/coroot/cluster.yaml# must NOT have additional properties, found additional property 'kind'
k8s/providers/hetzner/infrastructure/coroot/cluster.yaml# must NOT have additional properties, found additional property 'metadata'
k8s/providers/hetzner/infrastructure/coroot/cluster.yaml# must NOT have additional properties, found additional property 'spec'

✖ ksail.prod.yaml is invalid

ksail.prod.yaml#/spec/cluster must NOT have additional properties, found additional property 'verify'
ksail.prod.yaml#/spec/cluster/autoscaler/node/enabled must be string
ksail.prod.yaml#/spec/cluster/autoscaler/node/enabled must be equal to one of the allowed values
❌ ACTION / zizmor - 1 error
INFO zizmor: 🌈 zizmor v1.25.0
fatal: no audit was performed
'artipacked' audit failed on file://.github/workflows/cd.yaml

Caused by:
    0: error in 'artipacked' audit
    1: couldn't list tags for actions/checkout
    2: request error while accessing GitHub API
    3: HTTP status client error (401 Unauthorized) for url (https://github.com/actions/checkout.git/git-upload-pack)
⚠️ BASH / bash-exec - 4 errors
Results of bash-exec linter (version 5.3.9)
See documentation on https://megalinter.io/9.6.0/descriptors/bash_bash_exec/
-----------------------------------------------

❌ [ERROR] .agents/skills/gitops-repo-audit/scripts/check-deprecated.sh
    Error: File:[.agents/skills/gitops-repo-audit/scripts/check-deprecated.sh] is not executable

❌ [ERROR] .agents/skills/gitops-repo-audit/scripts/discover.sh
    Error: File:[.agents/skills/gitops-repo-audit/scripts/discover.sh] is not executable

❌ [ERROR] .agents/skills/gitops-repo-audit/scripts/validate.sh
    Error: File:[.agents/skills/gitops-repo-audit/scripts/validate.sh] is not executable

❌ [ERROR] scripts/ghcr-auth-lib.sh
    Error: File:[scripts/ghcr-auth-lib.sh] is not executable

✅ [SUCCESS] scripts/refresh-flux-ghcr-auth.sh
✅ [SUCCESS] scripts/run-ksail-prod-with-pull-auth.sh
✅ [SUCCESS] scripts/tests/test-cilium-bandwidth-manager-component.sh
⚠️ MARKDOWN / markdownlint - 169 errors
th the same content [Context: "Custody recommendations"]
docs/dr/crypto-custody.md:245 error MD024/no-duplicate-heading Multiple headings with the same content [Context: "Custody recommendations"]
docs/dr/crypto-custody.md:251 error MD024/no-duplicate-heading Multiple headings with the same content [Context: "What to do if it leaks"]
docs/dr/crypto-custody.md:258 error MD024/no-duplicate-heading Multiple headings with the same content [Context: "What to do if it is *lost* (no..."]
docs/dr/restore-drill.md:42 error MD028/no-blanks-blockquote Blank line inside blockquote
docs/dr/runbook.md:23:102 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/dr/runbook.md:23:487 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/dr/runbook.md:34 error MD028/no-blanks-blockquote Blank line inside blockquote
docs/dr/runbook.md:41 error MD028/no-blanks-blockquote Blank line inside blockquote
docs/dr/runbook.md:50 error MD028/no-blanks-blockquote Blank line inside blockquote
docs/dr/runbook.md:474:92 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/dr/spire-server-ha.md:93 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
docs/dr/velero-cnpg.md:11 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
docs/dr/velero-cnpg.md:56:78 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/dr/velero-cnpg.md:56:166 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/dr/velero-cnpg.md:57:78 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/dr/velero-cnpg.md:57:227 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/dr/velero-cnpg.md:58:78 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/dr/velero-cnpg.md:58:166 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/github-management.md:38:401 error MD013/line-length Line length [Expected: 400; Actual: 419]
docs/github-management.md:40:401 error MD013/line-length Line length [Expected: 400; Actual: 522]
docs/node-autoscaling.md:14 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
docs/oidc-kubectl.md:95 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
docs/runtime-security.md:114 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
docs/rwx-storage.md:9 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
docs/unifi-management.md:14 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
docs/unifi-management.md:62 error MD040/fenced-code-language Fenced code blocks should have a language specified [Context: "```"]
README.md:116:401 error MD013/line-length Line length [Expected: 400; Actual: 540]
README.md:237:32 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
README.md:237:36 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]

(Truncated to last 3636 characters out of 23139)

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,ACTION_ZIZMOR,BASH_EXEC,BASH_SHELLCHECK,BASH_SHFMT,COPYPASTE_JSCPD,GO_GOLANGCI_LINT,GO_REVIVE,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_CSPELL,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: 🫴 Ready

Development

Successfully merging this pull request may close these issues.

0 participants