Repository navigation
Bump super-linter/super-linter from 5 to 8 - #28
Merged
BrandonLWhite merged 5 commits intoSep 2, 2026
Merged
Conversation
BrandonLWhite
force-pushed
the
dependabot/github_actions/super-linter/super-linter-8
branch
from
September 1, 2026 21:07
ab3f530 to
9630cf0
Compare
Bumps [super-linter/super-linter](https://github.com/super-linter/super-linter) from 5 to 8. - [Release notes](https://github.com/super-linter/super-linter/releases) - [Changelog](https://github.com/super-linter/super-linter/blob/main/CHANGELOG.md) - [Commits](super-linter/super-linter@v5...v8) --- updated-dependencies: - dependency-name: super-linter/super-linter dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
super-linter v6 and later resolve the default branch by running `git rev-parse --verify main` (then `origin/main`) inside the workspace. A shallow PR checkout creates neither ref, so v8 aborted with "Neither main, nor origin/main exist in /github/workspace". Also drop JAVASCRIPT_DEFAULT_STYLE, deprecated in super-linter v6.8.0 and now only emitting a warning; JAVASCRIPT_PRETTIER covers it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
v8 enables linters v5 did not run, and ships newer versions of ones it did. Working through what they found: zizmor (new in v8), 28 findings, all fixed: - pinned all 16 action references to commit SHAs with version comments - added persist-credentials: false to all 7 checkouts - moved pages/id-token write scopes off the Jekyll workflow and onto the deploy job that actually needs them - added a 7-day Dependabot cooldown so a release settles before we take it FILTER_REGEX_EXCLUDE held a glob (dist/**/*) in a field super-linter treats as a regex. Unanchored, it matched any path containing "dist", so .github/workflows/check-dist.yml was silently excluded from every linter - which is why zizmor never reported its 4 findings. Anchored to ^dist/.* and fixed the findings that surfaced. codespell (new in v8): fixed "Converage" in README.md, "pacakge" in action.yml and "Comfirm" in the act fixture. Added .codespellrc for thirdParty, which is a rollup-plugin-license option name. checkov (new in v8) flagged the act fixture for having no top-level permissions; gave it contents: read rather than suppressing the check. trivy (new in v8) secret-scans generated dist/index.js and hits the Azurite emulator's public dev credentials vendored in @azure/storage-blob. Added trivy.yaml mirroring super-linter's template plus skip-dirs: dist, keeping the useful package-lock.json vulnerability scan. Biome is disabled: it wants semicolons and double quotes, while .prettierrc.yml sets semi: false and singleQuote: true. Prettier and eslint are this repo's formatter and linter. textlint in v8 is newer and flags two more terminology errors in the ESM migration spec. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
super-linter never used this repo's eslint config: JAVASCRIPT_ES_CONFIG_FILE resolves under LINTER_RULES_PATH (.github/linters), which has markdown and yaml configs but no eslint one, so it fell back to its own bundled config - eslint-plugin-react rules and all. That is why it reported a no-unused-vars error that eslint.config.mjs deliberately sets to off. Pointing it at our config is not viable: super-linter shares JAVASCRIPT_ES_LINTER_RULES between the JAVASCRIPT_ES, JSON, JSONC and VUE linters, and our config has no JSON language support, so an invalid .json file comes back "File ignored because no matching configuration was supplied" with exit 0 - JSON linting would silently stop. ci.yml already runs `npm run lint` with the real eslint and the real config as a required check, so JS linting defers to it and super-linter keeps its own config for JSON/JSONC. (eslint 9.39.4 in the container does load our eslint 10 flat config fine; that was not the obstacle.) The one real finding it surfaced is fixed rather than dropped: the caught error in checkForPipxSharedPreExists was unused, so it uses an optional catch binding now. Also stop super-linter posting a pull request summary comment. That is new in v8 and needs pull-requests or issues write, which this workflow deliberately does not grant; the attempt logged a non-fatal 403 on every run. Results remain visible as status checks and in the job summary. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
BrandonLWhite
force-pushed
the
dependabot/github_actions/super-linter/super-linter-8
branch
from
September 1, 2026 21:27
9630cf0 to
a73a4a3
Compare
FILTER_REGEX_EXCLUDE is matched against the full path (/github/workspace/dist/index.js) unless STRIP_DEFAULT_WORKSPACE_FOR_REGEX is true, so the anchored ^dist/.* from the previous commit never matched and dist/ stopped being excluded. Gitleaks and codespell then scanned the generated bundle and reported vendored findings: the Azurite emulator credentials in @azure/storage-blob and "re-use"/"get's" in dependency code. Setting the flag is what super-linter's docs recommend for anchored regexes, and keeps check-dist.yml linted while excluding dist/. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
BrandonLWhite
deleted the
dependabot/github_actions/super-linter/super-linter-8
branch
September 2, 2026 14:01
BrandonLWhite
added a commit
that referenced
this pull request
Sep 2, 2026
super-linter shares JAVASCRIPT_ES_LINTER_RULES across its JAVASCRIPT_ES, JSON, JSONC and VUE linters, so a single config has to cover JS and JSON before super-linter can be pointed at ours. #28 worked around that by disabling VALIDATE_JAVASCRIPT_ES and letting ci.yml's `npm run lint` be the authority for JS, which left super-linter using its own bundled config (eslint-plugin-react rules and all) for JSON. Added @eslint/json and scoped the JavaScript configs to js/mjs/cjs. None of js.configs.recommended, eslint-plugin-jest or eslint-plugin-prettier declare `files` of their own, so without that scoping their rules would be applied to the JSON files too. .github/linters/eslint.config.mjs re-exports the root config, because JAVASCRIPT_ES_CONFIG_FILE resolves under LINTER_RULES_PATH rather than the repo root. VALIDATE_JAVASCRIPT_ES goes back to its default, so super-linter and `npm run lint` now enforce the same rules over the same files. json/no-empty-keys is off for package-lock.json only: npm's `packages` map uses "" for the root project. The file is still checked by the other three JSON rules. Verified `eslint --print-config src/main.js` is unchanged - 82 active rules before and after, none lost or added. eslint 9.39.4, the version in the super-linter container, loads this config through the shim and reports real JS and JSON errors with exit 1, so it is linting rather than silently matching nothing. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps super-linter/super-linter from 5 to 8.
Release notes
Sourced from super-linter/super-linter's releases.
... (truncated)
Changelog
Sourced from super-linter/super-linter's changelog.
... (truncated)
Commits
4ce2083chore(main): release 8.7.0 (#7704)b2baf83deps(npm): bump the npm group across 1 directory with 9 updates (#7939)3e6cd30chore: exempt release prs from stale check (#7934)7b70a50deps(docker): bump the docker group across 1 directory with 6 updates (#7912)c5fb918deps(docker): bump python (#7730)3833d50deps(npm): bump protobufjs (#7917)27acb3cdeps(python): bump the pip group across 1 directory with 6 updates (#7932)8d41efeci(dev-docker): bump node (#7846)65ad252deps(java): bump com.puppycrawl.tools:checkstyle (#7914)ef436c3ci(dev-npm): bump release-please (#7892)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)