Skip to content

Secure PAT_GITHUB_COM and document tflint native host-specific token - #8812

Merged
nvuillam merged 2 commits into
mainfrom
fix/secure-pat-github-com
Aug 28, 2026
Merged

Secure PAT_GITHUB_COM and document tflint native host-specific token#8812
nvuillam merged 2 commits into
mainfrom
fix/secure-pat-github-com

Conversation

@nvuillam

Copy link
Copy Markdown
Member

Fixes #8795

Findings

A - Security: PAT_GITHUB_COM was never redacted. build_env() compares non-regex entries of DEFAULT_SECURED_ENV_VARIABLES with ==, and the list contained the literal PAT. No entry matched PAT_GITHUB_COM, so the GitHub Personal Access Token that the TERRAFORM_TFLINT documentation asks users to create was passed in cleartext to every linter subprocess (and printed in the LOG_LEVEL: DEBUG env dump), unlike GITHUB_TOKEN, SYSTEM_ACCESSTOKEN and the other credential variables.

B - Redundancy: tflint has a native equivalent. getGitHubToken (plugin/install.go) resolves GITHUB_TOKEN_{source_host} (e.g. GITHUB_TOKEN_github_com) with priority over GITHUB_TOKEN. It shipped in tflint v0.51.0, and MegaLinter pins v0.64.0. That variable contains _TOKEN_, so it is secured by default and works with TERRAFORM_TFLINT_UNSECURED_ENV_VARIABLES.

Fix

Both halves of the suggested remediation, without breaking the users who already set PAT_GITHUB_COM.

Secure it (immediate effect, even for existing users)

  • megalinter/config.py: the exact PAT entry becomes the (^|_)(PAT)($|_) pattern, which hides PAT, PAT_* and *_PAT variables (PAT_GITHUB_COM, AZURE_PAT...). Checked against every variable of the configuration JSON schema and against common environment variables: PATH, PATHEXT, GOPATH, NODE_PATH, PYTHONPATH, CLASSPATH, PATTERN, COMPATIBILITY... are not matched (the pattern requires a _ or a boundary right after PAT).
  • megalinter/pre_post_factory.py: the ordering trap described in the issue. replacement_env_vars now resolves var_src from the raw configuration instead of the already secured environment, so tflint --init keeps receiving the real token instead of HIDDEN_BY_MEGALINTER. The environment build moved to build_command_env(), called by run_command(). Nothing new is logged: only the command line is written to the logs, the resolved value never is.

Deprecate it in favor of the native mechanism

  • terraform.megalinter-descriptor.yml: the tflint documentation now recommends GITHUB_TOKEN_github_com + TERRAFORM_TFLINT_UNSECURED_ENV_VARIABLES, and flags PAT_GITHUB_COM as deprecated (also in its variable description).
  • TfLintLinter logs a deprecation warning when PAT_GITHUB_COM is set, following the wording of the linter deprecation warnings in MegaLinter.py. The variable keeps working; it is not removed in this PR.

Adjacent schema gap

  • replacement_env_vars is added to the command_info definition of megalinter-configuration.jsonschema.json (array of {var_src, var_dest}), and documented in the Pre-commands page (example + property table row). It was implemented but validated by nothing.

Verification

  • New config_test.test_config_secure_env_vars_personal_access_tokens: PAT, PAT_GITHUB_COM, AZURE_PAT, MY_PAT_FOR_CI are hidden, PATH, PATH_TO_SOMETHING, COMPATIBILITY_MODE stay visible.
  • New pre_post_test.PrePostReplacementEnvVarsTest: without replacement both GITHUB_TOKEN and PAT_GITHUB_COM are HIDDEN_BY_MEGALINTER in the command environment; with the tflint replacement rule, GITHUB_TOKEN receives the real PAT_GITHUB_COM value while PAT_GITHUB_COM itself stays hidden. This second test fails without the pre_post_factory change.
  • Existing secured-variables tests and black pass. The remaining config_test failures in my environment are the network-dependent remote-config tests (TLS interception), unrelated.
  • build.py run to regenerate the schema and mega-linter-runner/lib/megalinter-vars.json; only the files related to this change are committed.

Not done here

  • Actual removal of PAT_GITHUB_COM, left for a future major release.
  • The generated docs/descriptors/terraform_tflint.md page, owned by the documentation auto-update workflow.
  • The tflint plugin-install behavior with GITHUB_TOKEN=HIDDEN_BY_MEGALINTER (reported separately in tflint doesn't work in megalinter 7.0.x #2699).

@github-actions

github-actions Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

⚠️MegaLinter analysis: Success with warnings

⚠️ PYTHON / bandit - 197 errors
hell_equals_true] subprocess call - check for execution of untrusted input.
   Severity: Low   Confidence: High
   CWE: CWE-78 (https://cwe.mitre.org/data/definitions/78.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b603_subprocess_without_shell_equals_true.html
   Location: ./megalinter/utils_reporter.py:406:18
405	    try:
406	        process = subprocess.run(
407	            sarif_fmt_command,
408	            stdout=subprocess.PIPE,
409	            stderr=subprocess.STDOUT,
410	            text=True,
411	            input=sarif_in + "\n",
412	            env=config.build_env(request_id),
413	        )
414	        return_code = process.returncode

--------------------------------------------------
>> Issue: [B113:request_without_timeout] Call to requests without timeout
   Severity: Medium   Confidence: Low
   CWE: CWE-400 (https://cwe.mitre.org/data/definitions/400.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b113_request_without_timeout.html
   Location: ./megalinter/utils_reporter.py:572:19
571	    try:
572	        response = requests.post(
573	            hook_url,
574	            headers=build_webhook_headers(reporter.master.request_id),
575	            json=payload,
576	        )
577	        if 200 <= response.status_code < 299:

--------------------------------------------------
>> Issue: [B311:blacklist] Standard pseudo-random generators are not suitable for security/cryptographic purposes.
   Severity: Low   Confidence: High
   CWE: CWE-330 (https://cwe.mitre.org/data/definitions/330.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/blacklists/blacklist_calls.html#b311-random
   Location: ./megalinter/utils_sarif.py:156:61
155	                        rule["id"] = (
156	                            rule["id"] + "_DUPLICATE_" + str(random.randint(1, 99999))
157	                        )

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:122:4
121	    )
122	    assert os.path.isdir(config.get(request_id, "DEFAULT_WORKSPACE")), (
123	        "DEFAULT_WORKSPACE "
124	        + config.get(request_id, "DEFAULT_WORKSPACE")
125	        + " is not a valid folder"
126	    )
127	

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:167:4
166	    tmp_report_folder = tempfile.gettempdir() + os.path.sep + str(uuid.uuid4())
167	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
168	    linter_name = linter.linter_name

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:241:4
240	    tmp_report_folder = tempfile.gettempdir() + os.path.sep + str(uuid.uuid4())
241	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
242	    if os.path.isfile(workspace + os.path.sep + "no_test_failure"):

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:490:4
489	    )
490	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
491	    expected_file_name = ""

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:590:4
589	        workspace += os.path.sep + "bad"
590	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
591	    # Call linter

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:690:4
689	        workspace = workspace + os.path.sep + "fix"
690	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
691	

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:796:12
795	            ]
796	            assert (len(list(diffs))) > 0, f"No changes in the {file} file"
797	

--------------------------------------------------
>> Issue: [B108:hardcoded_tmp_directory] Probable insecure usage of temp file/directory.
   Severity: Medium   Confidence: Medium
   CWE: CWE-377 (https://cwe.mitre.org/data/definitions/377.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b108_hardcoded_tmp_directory.html
   Location: ./server/server.py:81:42
80	    if item.fileUploadId:
81	        uploaded_file_path = os.path.join("/tmp/server-files", item.fileUploadId)
82	        if not os.path.isdir(uploaded_file_path):

--------------------------------------------------
>> Issue: [B108:hardcoded_tmp_directory] Probable insecure usage of temp file/directory.
   Severity: Medium   Confidence: Medium
   CWE: CWE-377 (https://cwe.mitre.org/data/definitions/377.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b108_hardcoded_tmp_directory.html
   Location: ./server/server.py:103:38
102	    file_upload_id = "FILE_" + str(uuid1())
103	    uploaded_file_path = os.path.join("/tmp/server-files", file_upload_id)
104	    os.makedirs(uploaded_file_path)

--------------------------------------------------
>> Issue: [B108:hardcoded_tmp_directory] Probable insecure usage of temp file/directory.
   Severity: Medium   Confidence: Medium
   CWE: CWE-377 (https://cwe.mitre.org/data/definitions/377.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b108_hardcoded_tmp_directory.html
   Location: ./server/server_worker.py:102:34
101	        temp_dir = self.create_temp_dir()
102	        upload_dir = os.path.join("/tmp/server-files", file_upload_id)
103	        if os.path.exists(upload_dir):

--------------------------------------------------

Code scanned:
	Total lines of code: 29650
	Total lines skipped (#nosec): 0
	Total potential issues skipped due to specifically being disabled (e.g., #nosec BXXX): 0

Run metrics:
	Total issues (by severity):
		Undefined: 0
		Low: 130
		Medium: 59
		High: 8
	Total issues (by confidence):
		Undefined: 0
		Low: 44
		Medium: 40
		High: 113
Files skipped (0):

(Truncated to last 8000 characters out of 136301)
⚠️ SPELL / lychee - 55 errors
r-descriptor.yml
[403] https://pmd.sourceforge.io/pmd-6.55.0/pmd_userdocs_tools_ci.html (at 136:32) | Error (cached)

Errors in megalinter/descriptors/jsx.megalinter-descriptor.yml
[404] https://eslint-react.xyz/docs/getting-started/installation (at 80:37) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/kotlin.megalinter-descriptor.yml
[404] https://pinterest.github.io/ktlint/latest/api/custom-rule-set/ (at 69:15) | Rejected status code: 404 Not Found
[404] https://pinterest.github.io/ktlint/latest/faq/#how-do-i-suppress-errors-for-a-lineblockfile (at 38:38) | Rejected status code: 404 Not Found
[404] https://pinterest.github.io/ktlint/latest/rules/configuration-ktlint/ (at 37:37) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/kubernetes.megalinter-descriptor.yml
[404] https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/%7B%7B.Group%7D%7D/%7B%7B.ResourceKind%7D%7D_%7B%7B.ResourceAPIVersion%7D%7D.json (at 72:22) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/latex.megalinter-descriptor.yml
[TIMEOUT] https://www.nongnu.org/chktex (at 26:17) | Request timed out
[TIMEOUT] https://www.nongnu.org/chktex/ (at 29:23) | Request timed out
[TIMEOUT] https://www.nongnu.org/chktex/ (at 31:38) | Request timed out

Errors in megalinter/descriptors/markdown.megalinter-descriptor.yml
[404] https://github.com/rvben/rumdl/blob/main/docs/RULES.md (at 166:23) | Rejected status code: 404 Not Found
[403] https://www.npmjs.com/package/markdown-table-formatter (at 103:17) | Rejected status code: 403 Forbidden

Errors in megalinter/descriptors/repository.megalinter-descriptor.yml
[404] https://raw.githubusercontent.com/oxsecurity/megalinter/main/docs/assets/icons/linters/betterleaks.png (at 297:26) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/rst.megalinter-descriptor.yml
[403] https://docutils.sourceforge.io/docs/ref/rst/directives.html#raw-data-pass-through (at 34:38) | Rejected status code: 403 Forbidden

Errors in megalinter/descriptors/salesforce.megalinter-descriptor.yml
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/config.html (at 374:37) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/engine-flow.html (at 371:17) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 176:17) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 276:17) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 74:17) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/rules-flow.html (at 373:23) | Rejected status code: 403 Forbidden

Errors in megalinter/descriptors/shared/biome.megalinter-linter.yml
[404] https://biomejs.dev/linter/rules/ (at 21:19) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/shared/cppcheck.megalinter-linter.yml
[403] https://cppcheck.sourceforge.io/ (at 3:13) | Rejected status code: 403 Forbidden
[403] https://cppcheck.sourceforge.io/ (at 4:14) | Rejected status code: 403 Forbidden
[403] https://cppcheck.sourceforge.io/manual.html#configuration (at 8:33) | Rejected status code: 403 Forbidden

Errors in megalinter/descriptors/shared/eslint.megalinter-linter.yml
[TIMEOUT] https://eslint.org/docs/latest/use/integrations#source-control (at 7:28) | Request timed out

Errors in megalinter/descriptors/spell.megalinter-descriptor.yml
[404] https://vale.sh/docs/topics/vocab/ (at 190:38) | Rejected status code: 404 Not Found | Followed 2 redirects. Redirects: https://vale.sh/docs/topics/vocab/ --[301]--> https://docs.vale.sh/topics/vocab/ --[302]--> https://docs.vale.sh/topics/vocab
[404] https://vale.sh/docs/vale-cli/structure/ (at 183:95) | Rejected status code: 404 Not Found | Followed 2 redirects. Redirects: https://vale.sh/docs/vale-cli/structure/ --[301]--> https://docs.vale.sh/vale-cli/structure/ --[302]--> https://docs.vale.sh/vale-cli/structure

Errors in megalinter/descriptors/tsx.megalinter-descriptor.yml
[404] https://eslint-react.xyz/docs/getting-started/installation (at 81:37) | Error (cached)

Errors in megalinter/descriptors/xml.megalinter-descriptor.yml
[406] https://gitlab.gnome.org/GNOME/libxml2/-/wikis/home (at 38:17) | Rejected status code: 406 Not Acceptable

Errors in README.md
[ERROR] https://ampcode.com/ (at 248:1) | HTTP/2 protocol error. Server may not support HTTP/2 properly
[ERROR] https://eslint.org/docs/latest/use/integrations#source-control (at 2090:3) | Error (cached)
[301] https://future-architect.github.io/authors/%E5%AE%AE%E6%B0%B8%E5%B4%87%E5%8F%B2 (at 2033:104) | Rejected status code: 301 Moved Permanently
[TIMEOUT] https://generated.at/ (at 1369:301) | Request timed out
[404] https://github.com/oxsecurity/megalinter/stargazers (at 2199:3) | Rejected status code: 404 Not Found
[404] https://github.com/oxsecurity/megalinter/stargazers/ (at 23:1) | Rejected status code: 404 Not Found
[403] https://javascript.plainenglish.io/node-js-coding-standard-tools-with-megalinter-on-gitlab-ci-a43b55915811 (at 2016:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/@caodanju/30-seconds-to-setup-megalinter-your-go-to-tool-for-automated-code-quality-and-iac-security-969d90a5a99c (at 2001:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/@RunningMattress (at 2010:255) | Rejected status code: 403 Forbidden
[403] https://medium.com/@RunningMattress/level-up-your-unity-packages-with-ci-cd-9498d2791211 (at 2010:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/@SeasonedDeveloper (at 1997:255) | Rejected status code: 403 Forbidden
[403] https://medium.com/@SeasonedDeveloper/looking-for-the-best-ci-cd-pipeline-linting-tool-try-megalinter-d89c9eba850d (at 1997:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/datamindedbe/integrating-megalinter-to-automate-linting-across-multiple-codebases-a-technical-description-a200bb235b71 (at 1998:3) | Rejected status code: 403 Forbidden
[403] https://nicolas.vuillamy.fr/improve-uniformize-and-secure-your-code-base-with-megalinter-62ebab422c1 (at 2019:3) | Rejected status code: 403 Forbidden
[403] https://nicolas.vuillamy.fr/megalinter-sells-his-soul-and-joins-ox-security-2a91a0027628 (at 2018:3) | Rejected status code: 403 Forbidden
[403] https://nklya.medium.com/ (at 2015:255) | Rejected status code: 403 Forbidden
[403] https://nklya.medium.com/hot-to-linter-basic-things-like-trailing-whitespaces-and-newlines-7b40da8f688d (at 2015:3) | Rejected status code: 403 Forbidden
[403] https://npmjs.org/package/mega-linter-runner (at 1284:1) | Error (cached)
[403] https://npmjs.org/package/mega-linter-runner (at 1285:1) | Error (cached)
[403] https://npmjs.org/package/mega-linter-runner (at 1286:1) | Error (cached)
[403] https://npmjs.org/package/mega-linter-runner (at 21:1) | Rejected status code: 403 Forbidden | Followed 1 redirect. Redirects: https://npmjs.org/package/mega-linter-runner --[301]--> https://www.npmjs.com/package/mega-linter-runner
[403] https://openai.com/codex/ (at 240:1) | Rejected status code: 403 Forbidden
[403] https://pmd.sourceforge.io/pmd-6.55.0/pmd_userdocs_tools_ci.html (at 2104:3) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@downatthebottomofthemolehole/megalinter-mcp-server (at 1975:354) | Rejected status code: 403 Forbidden

Hint: Followed 762 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: Rejected redirectional status codes. This means some redirects were not followed. You might want to increase the limit for `-m`/`--max-redirects`.

(Truncated to last 8000 characters out of 32554)
⚠️ MARKDOWN / markdownlint - 346 errors
in the same document [Context: "Docker container"]
docs/install-drone.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Drone CI"]
docs/install-github.md:10 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "GitHub Action"]
docs/install-gitlab.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "GitLab CI"]
docs/install-jenkins.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Jenkins"]
docs/install-jenkins.md:40 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "PR Comment Reporting from Jenk..."]
docs/install-locally.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Run MegaLinter locally"]
docs/install-version.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Which version to use ?"]
docs/license-explanations.md:7 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Why AGPL V3 License ?"]
docs/mega-linter-vs-super-linter.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "MegaLinter vs Super-Linter"]
docs/plugins.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Plugins"]
docs/quick-start.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Quick Start"]
docs/removed-linters.md:9 error MD024/no-duplicate-heading Multiple headings with the same content [Context: "Removed linters"]
docs/reporters.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Reporters"]
docs/reporters/AzureCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Azure Comment Reporter"]
docs/reporters/BitbucketCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Bitbucket Comment Reporter"]
docs/reporters/ConfigReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "IDE Configuration Reporter"]
docs/reporters/ConsoleReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Console Reporter"]
docs/reporters/EmailReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "E-mail Reporter"]
docs/reporters/FileIoReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "File.io Reporter"]
docs/reporters/GitHubCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "GitHub Comment Reporter"]
docs/reporters/GitHubCommentReporter.md:27:196 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:27:46 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:27:174 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:27:196 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:28:179 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:28:46 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:28:160 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:28:179 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:29:159 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:29:48 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:29:143 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:29:159 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:30:171 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:30:46 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:30:152 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:30:171 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubStatusReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "GitHub Status Reporter"]
docs/reporters/GitlabCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Gitlab Comment Reporter"]
docs/reporters/JsonReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "JSON Reporter"]
docs/reporters/MarkdownSummaryReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Markdown Summary Reporter"]
docs/reporters/SarifReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "SARIF Reporter (beta)"]
docs/reporters/TapReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "TAP Reporter"]
docs/reporters/TextReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Text Reporter"]
docs/reporters/UpdatedSourcesReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Updated Sources Reporter"]
docs/special-thanks.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Special thanks"]
docs/special-thanks.md:23:3 error MD045/no-alt-text Images should have alternate text (alt text)
docs/sponsor.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Sponsoring"]
docs/supported-linters.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Supported Linters"]
mega-linter-runner/README.md:27:274 error MD051/link-fragments Link fragments should be valid [Context: "[**apply formatting and auto-fixes**](#apply-fixes)"]
mega-linter-runner/README.md:27:217 error MD051/link-fragments Link fragments should be valid [Context: "[**reports in several formats**](#reports)"]
README.md:220:127 error MD051/link-fragments Link fragments should be valid [Context: "[many additional features](#mega-linter-vs-super-linter)"]
README.md:2226:3 error MD045/no-alt-text Images should have alternate text (alt text)
skills/megalinter-check/performance.md:27:601 error MD013/line-length Line length [Expected: 600; Actual: 713]
skills/megalinter-setup/agents/megalinter-runner.md:33:601 error MD013/line-length Line length [Expected: 600; Actual: 620]

(Truncated to last 8000 characters out of 45990)
⚠️ YAML / prettier - 14 errors
yles/proselint/Hedging.yml 2ms (unchanged)
.github/linters/valestyles/proselint/Hyperbole.yml 2ms (unchanged)
.github/linters/valestyles/proselint/Jargon.yml 2ms (unchanged)
.github/linters/valestyles/proselint/LGBTOffensive.yml 1ms (unchanged)
.github/linters/valestyles/proselint/LGBTTerms.yml 2ms (unchanged)
.github/linters/valestyles/proselint/Malapropisms.yml 2ms (unchanged)
.github/linters/valestyles/proselint/Needless.yml 35ms (unchanged)
.github/linters/valestyles/proselint/Nonwords.yml 5ms (unchanged)
.github/linters/valestyles/proselint/Oxymorons.yml 2ms (unchanged)
.github/linters/valestyles/proselint/P-Value.yml 1ms (unchanged)
.github/linters/valestyles/proselint/RASSyndrome.yml 4ms (unchanged)
.github/linters/valestyles/proselint/Skunked.yml 2ms (unchanged)
.github/linters/valestyles/proselint/Spelling.yml 2ms (unchanged)
.github/linters/valestyles/proselint/Typography.yml 3ms (unchanged)
.github/linters/valestyles/proselint/Uncomparables.yml 3ms (unchanged)
.github/linters/valestyles/proselint/Very.yml 2ms (unchanged)
.github/release-drafter.yml 11ms (unchanged)
.grype.yaml 5ms (unchanged)
.mega-linter.yml 8ms (unchanged)
.pre-commit-hooks.yaml 6ms (unchanged)
action.yml 3ms (unchanged)
codecov.yml 1ms (unchanged)
mega-linter-runner/.eslintrc.yml 3ms (unchanged)
mega-linter-runner/.mega-linter.yml 4ms (unchanged)
mega-linter-runner/generators/mega-linter-custom-flavor/templates/action.yml 2ms (unchanged)
mega-linter-runner/generators/mega-linter-custom-flavor/templates/check-new-megalinter-version.yml 12ms (unchanged)
mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor-builder.yml 11ms (unchanged)
[error] mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor.yml: SyntaxError: Implicit map keys need to be followed by map values (6:1)
[error]   4 | label: <%= CUSTOM_FLAVOR_LABEL %>
[error]   5 | linters:
[error] > 6 | <%= CUSTOM_FLAVOR_LINTERS %>
[error]     | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[error]   7 |
mega-linter-runner/generators/mega-linter-custom-flavor/templates/zizmor.yml 2ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/.drone.yml 3ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/.gitlab-ci.yml 5ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/azure-pipelines.yml 4ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/bitbucket-pipelines.yml 4ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/concourse-task.yml 3ms (unchanged)
[error] mega-linter-runner/generators/mega-linter/templates/mega-linter.yml: SyntaxError: Implicit map keys need to be followed by map values (67:11)
[error]   65 |           # Only define `secrets.PAT` if you fully understand the trade-off.
[error]   66 |           token: ${{ secrets.PAT || secrets.GITHUB_TOKEN }}
[error] > 67 |           <%- PERSIST_CREDENTIALS %>
[error]      |           ^^^^^^^^^^^^^^^^^^^^^^^^^^
[error]   68 |
[error]   69 |           # If you use VALIDATE_ALL_CODEBASE = true, you can remove this line to
[error]   70 |           # improve performance
megalinter/descriptors/action.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/ansible.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/api.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/arm.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/bash.megalinter-descriptor.yml 14ms (unchanged)
megalinter/descriptors/bicep.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/c.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/clojure.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/cloudformation.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/coffee.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/copypaste.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/cpp.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/csharp.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/css.megalinter-descriptor.yml 9ms (unchanged)
megalinter/descriptors/dart.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/dockerfile.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/editorconfig.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/env.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/gherkin.megalinter-descriptor.yml 9ms (unchanged)
megalinter/descriptors/go.megalinter-descriptor.yml 9ms (unchanged)
megalinter/descriptors/graphql.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/groovy.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/html.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/java.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/javascript.megalinter-descriptor.yml 11ms (unchanged)
megalinter/descriptors/json.megalinter-descriptor.yml 11ms (unchanged)
megalinter/descriptors/jsx.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/kotlin.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/kubernetes.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/latex.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/lua.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/markdown.megalinter-descriptor.yml 9ms (unchanged)
megalinter/descriptors/perl.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/php.megalinter-descriptor.yml 22ms (unchanged)
megalinter/descriptors/powershell.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/protobuf.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/python.megalinter-descriptor.yml 66ms (unchanged)
megalinter/descriptors/r.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/raku.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/repository.megalinter-descriptor.yml 78ms (unchanged)
megalinter/descriptors/robotframework.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/rst.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/ruby.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/rust.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/salesforce.megalinter-descriptor.yml 19ms (unchanged)
megalinter/descriptors/scala.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/shared/biome.megalinter-linter.yml 4ms (unchanged)
megalinter/descriptors/shared/clang-format.megalinter-linter.yml 3ms (unchanged)
megalinter/descriptors/shared/cppcheck.megalinter-linter.yml 3ms (unchanged)
megalinter/descriptors/shared/cpplint.megalinter-linter.yml 2ms (unchanged)
megalinter/descriptors/shared/dotnet-format.megalinter-linter.yml 2ms (unchanged)
megalinter/descriptors/shared/eslint.megalinter-linter.yml 8ms (unchanged)
megalinter/descriptors/shared/prettier.megalinter-linter.yml 4ms (unchanged)
megalinter/descriptors/shared/v8r.megalinter-linter.yml 3ms (unchanged)
megalinter/descriptors/snakemake.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/spell.megalinter-descriptor.yml 17ms (unchanged)
megalinter/descriptors/sql.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/swift.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/tekton.megalinter-descriptor.yml 3ms (unchanged)
megalinter/descriptors/terraform.megalinter-descriptor.yml 14ms (unchanged)
megalinter/descriptors/tsx.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/typescript.megalinter-descriptor.yml 13ms (unchanged)
megalinter/descriptors/vbdotnet.megalinter-descriptor.yml 2ms (unchanged)
megalinter/descriptors/xml.megalinter-descriptor.yml 4ms (unchanged)
megalinter/descriptors/yaml.megalinter-descriptor.yml 9ms (unchanged)
server/docker-compose-dev.yml 3ms (unchanged)
server/docker-compose.yml 3ms (unchanged)
trivy-secret.yaml 1ms (unchanged)
zizmor.yml 2ms (unchanged)

(Truncated to last 8000 characters out of 12547)
⚠️ YAML / yamllint - 45 errors
.grype.yaml
  6:1       warning  missing document start "---"  (document-start)

mega-linter-runner/.eslintrc.yml
  11:9      warning  too few spaces inside empty braces  (braces)

mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor-builder.yml
  48:15     warning  too few spaces inside empty braces  (braces)

mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor.yml
  7:1       error    syntax error: could not find expected ':' (syntax)

mega-linter-runner/generators/mega-linter/templates/mega-linter.yml
  38:15     warning  too few spaces inside empty braces  (braces)
  69:11     error    syntax error: could not find expected ':' (syntax)

megalinter/descriptors/copypaste.megalinter-descriptor.yml
  19:301    warning  line too long (313 > 300 characters)  (line-length)
  25:301    warning  line too long (384 > 300 characters)  (line-length)

megalinter/descriptors/javascript.megalinter-descriptor.yml
  52:301    warning  line too long (475 > 300 characters)  (line-length)
  328:301   warning  line too long (307 > 300 characters)  (line-length)
  354:301   warning  line too long (315 > 300 characters)  (line-length)

megalinter/descriptors/json.megalinter-descriptor.yml
  112:301   warning  line too long (315 > 300 characters)  (line-length)

megalinter/descriptors/jsx.megalinter-descriptor.yml
  29:301    warning  line too long (475 > 300 characters)  (line-length)

megalinter/descriptors/perl.megalinter-descriptor.yml
  25:301    warning  line too long (310 > 300 characters)  (line-length)

megalinter/descriptors/php.megalinter-descriptor.yml
  200:301   warning  line too long (389 > 300 characters)  (line-length)
  214:301   warning  line too long (302 > 300 characters)  (line-length)

megalinter/descriptors/repository.megalinter-descriptor.yml
  27:301    warning  line too long (666 > 300 characters)  (line-length)
  193:301   warning  line too long (408 > 300 characters)  (line-length)
  299:301   warning  line too long (345 > 300 characters)  (line-length)
  537:301   warning  line too long (306 > 300 characters)  (line-length)
  616:301   warning  line too long (374 > 300 characters)  (line-length)
  701:301   warning  line too long (316 > 300 characters)  (line-length)
  1038:301  warning  line too long (1263 > 300 characters)  (line-length)
  1135:301  warning  line too long (879 > 300 characters)  (line-length)
  1149:301  warning  line too long (358 > 300 characters)  (line-length)
  1212:301  warning  line too long (346 > 300 characters)  (line-length)
  1219:301  warning  line too long (307 > 300 characters)  (line-length)

megalinter/descriptors/salesforce.megalinter-descriptor.yml
  54:301    warning  line too long (359 > 300 characters)  (line-length)

megalinter/descriptors/spell.megalinter-descriptor.yml
  181:301   warning  line too long (315 > 300 characters)  (line-length)

megalinter/descriptors/sql.megalinter-descriptor.yml
  27:301    warning  line too long (403 > 300 characters)  (line-length)

megalinter/descriptors/terraform.megalinter-descriptor.yml
  28:301    warning  line too long (330 > 300 characters)  (line-length)
  43:301    warning  line too long (330 > 300 characters)  (line-length)
  97:301    warning  line too long (346 > 300 characters)  (line-length)
  164:301   warning  line too long (328 > 300 characters)  (line-length)
  239:301   warning  line too long (307 > 300 characters)  (line-length)
  250:301   warning  line too long (386 > 300 characters)  (line-length)

megalinter/descriptors/tsx.megalinter-descriptor.yml
  29:301    warning  line too long (475 > 300 characters)  (line-length)

megalinter/descriptors/typescript.megalinter-descriptor.yml
  39:301    warning  line too long (475 > 300 characters)  (line-length)
  318:301   warning  line too long (314 > 300 characters)  (line-length)
  344:301   warning  line too long (315 > 300 characters)  (line-length)

megalinter/descriptors/yaml.megalinter-descriptor.yml
  38:301    warning  line too long (315 > 300 characters)  (line-length)

mkdocs.yml
  8:301     warning  line too long (590 > 300 characters)  (line-length)
  72:5      warning  wrong indentation: expected 6 but found 4  (indentation)
  86:5      warning  wrong indentation: expected 6 but found 4  (indentation)

zizmor.yml
  1:1       warning  missing document start "---"  (document-start)

✅ Linters with no issues

actionlint, bash-exec, betterleaks, black, checkov, cspell, flake8, git_diff, grype, hadolint, isort, jscpd, jsonlint, markdown-table-formatter, mypy, npm-groovy-lint, osv-scanner, pylint, ruff, secretlint, shellcheck, shfmt, spectral, syft, trivy, trivy-sbom, trufflehog, v8r, v8r, xmllint, zizmor

See detailed reports in MegaLinter artifacts

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

nvuillam and others added 2 commits August 27, 2026 10:28
PAT_GITHUB_COM matched no entry of DEFAULT_SECURED_ENV_VARIABLES, so the
GitHub Personal Access Token asked by the TERRAFORM_TFLINT documentation
was sent in cleartext to every linter subprocess.

- Replace the exact "PAT" entry of DEFAULT_SECURED_ENV_VARIABLES by the
  (^|_)(PAT)($|_) pattern, hiding PAT, PAT_* and *_PAT variables
- Resolve replacement_env_vars var_src from the raw configuration instead
  of the already secured environment, so securing the source variable
  does not send HIDDEN_BY_MEGALINTER to tflint --init. Env build extracted
  in pre_post_factory.build_command_env()
- Deprecate PAT_GITHUB_COM (warning logged when set) and document the
  tflint native GITHUB_TOKEN_github_com variable, used with
  TERRAFORM_TFLINT_UNSECURED_ENV_VARIABLES, as the recommended approach
- Declare replacement_env_vars in the configuration JSON schema
  (command_info definition) and in the pre-commands documentation
- Unit tests for the redaction and for the replacement resolution

Fixes #8795
@nvuillam
nvuillam force-pushed the fix/secure-pat-github-com branch from e3dafbe to de74ffd Compare August 27, 2026 08:28
@nvuillam
nvuillam merged commit b04d586 into main Aug 28, 2026
147 checks passed
@nvuillam
nvuillam deleted the fix/secure-pat-github-com branch August 28, 2026 22:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

PAT_GITHUB_COM bypasses secret redaction and duplicates a native tflint feature

1 participant