Skip to content

Bump super-linter/super-linter from 5 to 8 - #28

Merged
BrandonLWhite merged 5 commits into
mainfrom
dependabot/github_actions/super-linter/super-linter-8
Sep 2, 2026
Merged

BrandonLWhite merged 5 commits into
mainfrom
dependabot/github_actions/super-linter/super-linter-8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 19, 2026

Copy link
Copy Markdown

Bumps super-linter/super-linter from 5 to 8.

Release notes

Sourced from super-linter/super-linter's releases.

v8.0.0

8.0.0 (2025-07-17)

⚠ BREAKING CHANGES

  • migrate to the latest eslint configuration (#6814)
  • remove unmaintained node packages (#6848)
  • remove unmaintained linters and formatters (#6773)

🚀 Features

🐛 Bugfixes

⬆️ Dependency updates

  • bundler: bump rubocop in /dependencies in the rubocop group (#6875) (e0f760c)
  • bundler: bump the rubocop group across 1 directory with 4 updates (#6820) (4cabfd6)
  • docker: bump the docker group across 1 directory with 16 updates (#6864) (1879b46)
  • java: bump the java-gradle group across 2 directories with 2 updates (#6810) (b900e08)
  • java: bump the java-gradle group across 2 directories with 2 updates (#6880) (4d267db)
  • npm: bump @​babel/eslint-parser in /dependencies (#6865) (5a39b53)
  • npm: bump @​typescript-eslint/eslint-plugin (#6872) (4099a2f)
  • npm: bump asl-validator from 3.15.0 to 4.0.0 in /dependencies (#6845) (27e1d3b)
  • npm: bump eslint from 9.29.0 to 9.31.0 in /dependencies (#6878) (c1b79c2)
  • npm: bump markdownlint-cli from 0.44.0 to 0.45.0 in /dependencies (#6796) (cbafd4a)
  • npm: bump next (#6869) (a0f6e7d)
  • npm: bump prettier from 3.5.3 to 3.6.2 in /dependencies (#6857) (53ab6bb)
  • npm: bump react-router-dom (#6871) (4258001)
  • npm: bump renovate from 40.11.8 to 40.28.0 in /dependencies (#6807) (66b6cb3)
  • npm: bump renovate from 40.62.1 to 41.32.2 in /dependencies (#6876) (b67cd44)
  • npm: bump stylelint (#6867) (9572e8f)
  • npm: bump textlint (#6868) (05919fd)
  • npm: bump textlint-rule-terminology (#6877) (e2ac8dd)
  • npm: bump the eslint-plugins-configs group across 1 directory with 4 updates (#6870) (301a807)
  • python: bump the pip group across 1 directory with 4 updates (#6879) (8735a57)
  • python: bump the pip group across 1 directory with 6 updates (#6851) (a659e7d)

... (truncated)

Changelog

Sourced from super-linter/super-linter's changelog.

8.7.0 (2026-06-18)

🚀 Features

🐛 Bugfixes

⬆️ Dependency updates

  • bundler: bump rubocop (#7923) (0738987)
  • bundler: bump rubocop in /dependencies in the rubocop group (#7731) (bf2414c)
  • bundler: bump rubocop-capybara (#7781) (35ef3f6)
  • bundler: bump the rubocop group across 1 directory with 2 updates (#7816) (5a6de32)
  • bundler: bump the rubocop group across 1 directory with 3 updates (#7875) (4d01de2)
  • bundler: bump the rubocop group in /dependencies with 2 updates (#7890) (cd79eea)
  • docker: bump dart in the docker group (#7755) (86c9c54)
  • docker: bump goreleaser/goreleaser in the docker group (#7705) (487d0d8)
  • docker: bump mvdan/shfmt in the docker group (#7718) (a1fc30a)
  • docker: bump python (#7730) (c5fb918)
  • docker: bump the docker group across 1 directory with 10 updates (#7817) (5e3985b)
  • docker: bump the docker group across 1 directory with 11 updates (#7876) (9bc8ec9)
  • docker: bump the docker group across 1 directory with 3 updates (#7765) (d9f1398)
  • docker: bump the docker group across 1 directory with 5 updates (#7786) (b7ba6a5)
  • docker: bump the docker group across 1 directory with 6 updates (#7912) (7b70a50)
  • docker: bump the docker group across 1 directory with 8 updates (#7753) (3fec5a3)
  • java: bump com.puppycrawl.tools:checkstyle (#7788) (4a69c1a)
  • java: bump com.puppycrawl.tools:checkstyle (#7914) (65ad252)
  • npm: bump @​hono/node-server in /dependencies (#7720) (a8c6363)
  • npm: bump @​protobufjs/utf8 from 1.1.0 to 1.1.1 in /dependencies (#7812) (0651d17)
  • npm: bump @​stoplight/spectral-cli in /dependencies (#7743) (fd0d01c)
  • npm: bump @​stoplight/spectral-cli in /dependencies (#7814) (813e4fb)
  • npm: bump brace-expansion (#7840) (f6e64b5)
  • npm: bump fast-uri from 3.0.6 to 3.1.2 in /dependencies (#7803) (9253b88)
  • npm: bump fast-xml-builder from 1.1.4 to 1.2.0 in /dependencies (#7802) (5b044ae)
  • npm: bump hono from 4.12.14 to 4.12.18 in /dependencies (#7801) (b39c4bb)
  • npm: bump hono from 4.12.7 to 4.12.12 in /dependencies (#7721) (ab671c2)
  • npm: bump next from 16.2.2 to 16.2.3 in /dependencies (#7739) (223d8b2)
  • npm: bump next from 16.2.4 to 16.2.6 in /dependencies (#7811) (308a04b)

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 19, 2026
@BrandonLWhite
BrandonLWhite force-pushed the dependabot/github_actions/super-linter/super-linter-8 branch from ab3f530 to 9630cf0 Compare September 1, 2026 21:07
dependabot Bot and others added 4 commits September 1, 2026 16:24
Bumps [super-linter/super-linter](https://github.com/super-linter/super-linter) from 5 to 8.
- [Release notes](https://github.com/super-linter/super-linter/releases)
- [Changelog](https://github.com/super-linter/super-linter/blob/main/CHANGELOG.md)
- [Commits](super-linter/super-linter@v5...v8)

---
updated-dependencies:
- dependency-name: super-linter/super-linter
  dependency-version: '8'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
super-linter v6 and later resolve the default branch by running
`git rev-parse --verify main` (then `origin/main`) inside the workspace.
A shallow PR checkout creates neither ref, so v8 aborted with
"Neither main, nor origin/main exist in /github/workspace".

Also drop JAVASCRIPT_DEFAULT_STYLE, deprecated in super-linter v6.8.0
and now only emitting a warning; JAVASCRIPT_PRETTIER covers it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
v8 enables linters v5 did not run, and ships newer versions of ones it
did. Working through what they found:

zizmor (new in v8), 28 findings, all fixed:
- pinned all 16 action references to commit SHAs with version comments
- added persist-credentials: false to all 7 checkouts
- moved pages/id-token write scopes off the Jekyll workflow and onto the
  deploy job that actually needs them
- added a 7-day Dependabot cooldown so a release settles before we take it

FILTER_REGEX_EXCLUDE held a glob (dist/**/*) in a field super-linter
treats as a regex. Unanchored, it matched any path containing "dist",
so .github/workflows/check-dist.yml was silently excluded from every
linter - which is why zizmor never reported its 4 findings. Anchored to
^dist/.* and fixed the findings that surfaced.

codespell (new in v8): fixed "Converage" in README.md, "pacakge" in
action.yml and "Comfirm" in the act fixture. Added .codespellrc for
thirdParty, which is a rollup-plugin-license option name.

checkov (new in v8) flagged the act fixture for having no top-level
permissions; gave it contents: read rather than suppressing the check.

trivy (new in v8) secret-scans generated dist/index.js and hits the
Azurite emulator's public dev credentials vendored in @azure/storage-blob.
Added trivy.yaml mirroring super-linter's template plus skip-dirs: dist,
keeping the useful package-lock.json vulnerability scan.

Biome is disabled: it wants semicolons and double quotes, while
.prettierrc.yml sets semi: false and singleQuote: true. Prettier and
eslint are this repo's formatter and linter.

textlint in v8 is newer and flags two more terminology errors in the ESM
migration spec.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
super-linter never used this repo's eslint config: JAVASCRIPT_ES_CONFIG_FILE
resolves under LINTER_RULES_PATH (.github/linters), which has markdown and
yaml configs but no eslint one, so it fell back to its own bundled config -
eslint-plugin-react rules and all. That is why it reported a no-unused-vars
error that eslint.config.mjs deliberately sets to off.

Pointing it at our config is not viable: super-linter shares
JAVASCRIPT_ES_LINTER_RULES between the JAVASCRIPT_ES, JSON, JSONC and VUE
linters, and our config has no JSON language support, so an invalid .json
file comes back "File ignored because no matching configuration was
supplied" with exit 0 - JSON linting would silently stop. ci.yml already
runs `npm run lint` with the real eslint and the real config as a required
check, so JS linting defers to it and super-linter keeps its own config for
JSON/JSONC. (eslint 9.39.4 in the container does load our eslint 10 flat
config fine; that was not the obstacle.)

The one real finding it surfaced is fixed rather than dropped: the caught
error in checkForPipxSharedPreExists was unused, so it uses an optional
catch binding now.

Also stop super-linter posting a pull request summary comment. That is new
in v8 and needs pull-requests or issues write, which this workflow
deliberately does not grant; the attempt logged a non-fatal 403 on every
run. Results remain visible as status checks and in the job summary.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@BrandonLWhite
BrandonLWhite force-pushed the dependabot/github_actions/super-linter/super-linter-8 branch from 9630cf0 to a73a4a3 Compare September 1, 2026 21:27
FILTER_REGEX_EXCLUDE is matched against the full path
(/github/workspace/dist/index.js) unless STRIP_DEFAULT_WORKSPACE_FOR_REGEX
is true, so the anchored ^dist/.* from the previous commit never matched and
dist/ stopped being excluded. Gitleaks and codespell then scanned the
generated bundle and reported vendored findings: the Azurite emulator
credentials in @azure/storage-blob and "re-use"/"get's" in dependency code.

Setting the flag is what super-linter's docs recommend for anchored regexes,
and keeps check-dist.yml linted while excluding dist/.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@BrandonLWhite
BrandonLWhite merged commit 9fa2ee9 into main Sep 2, 2026
32 checks passed
@BrandonLWhite
BrandonLWhite deleted the dependabot/github_actions/super-linter/super-linter-8 branch September 2, 2026 14:01
BrandonLWhite added a commit that referenced this pull request Sep 2, 2026
super-linter shares JAVASCRIPT_ES_LINTER_RULES across its JAVASCRIPT_ES,
JSON, JSONC and VUE linters, so a single config has to cover JS and JSON
before super-linter can be pointed at ours. #28 worked around that by
disabling VALIDATE_JAVASCRIPT_ES and letting ci.yml's `npm run lint` be the
authority for JS, which left super-linter using its own bundled config
(eslint-plugin-react rules and all) for JSON.

Added @eslint/json and scoped the JavaScript configs to js/mjs/cjs. None of
js.configs.recommended, eslint-plugin-jest or eslint-plugin-prettier declare
`files` of their own, so without that scoping their rules would be applied to
the JSON files too.

.github/linters/eslint.config.mjs re-exports the root config, because
JAVASCRIPT_ES_CONFIG_FILE resolves under LINTER_RULES_PATH rather than the
repo root. VALIDATE_JAVASCRIPT_ES goes back to its default, so super-linter
and `npm run lint` now enforce the same rules over the same files.

json/no-empty-keys is off for package-lock.json only: npm's `packages` map
uses "" for the root project. The file is still checked by the other three
JSON rules.

Verified `eslint --print-config src/main.js` is unchanged - 82 active rules
before and after, none lost or added. eslint 9.39.4, the version in the
super-linter container, loads this config through the shim and reports real
JS and JSON errors with exit 1, so it is linting rather than silently
matching nothing.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant