Skip to content

feat(salesforce): add SALESFORCE_CODE_ANALYZER_FLOW linter (Flow Scanner engine) - #8408

Merged
nvuillam merged 6 commits into
mainfrom
add-salesforce-code-analyzer-flow
Jul 14, 2026
Merged

feat(salesforce): add SALESFORCE_CODE_ANALYZER_FLOW linter (Flow Scanner engine)#8408
nvuillam merged 6 commits into
mainfrom
add-salesforce-code-analyzer-flow

Conversation

@nvuillam

Copy link
Copy Markdown
Member

What

Adds a new linter SALESFORCE_CODE_ANALYZER_FLOW to the SALESFORCE descriptor, exposing the Flow Scanner (flow) engine of Salesforce Code Analyzer v5. It audits Salesforce Flows (*.flow-meta.xml) for security issues.

How

  • Runs sf code-analyzer run --rule-selector flow --target "**/*.flow-meta.xml", mirroring the existing code-analyzer-apex/aura/lwc entries.
  • Reuses the already-installed @salesforce/plugin-code-analyzerno new dependency.
  • Ships common_linter_errors guidance for invalid config, no target flows, and the engine's Python 3.10+ requirement.
  • amd64 only, matching the sibling Code Analyzer engines.

Notes

  • Graph Engine (sfge) was intentionally left out — it is still a Salesforce Developer Preview.
  • The legacy standalone lightning-flow-scanner entry (disabled, repo archived) is untouched; this engine is its maintained successor inside Code Analyzer v5.
  • Reuses the existing salesforce-lfs test fixtures. CI will confirm the flow engine flags the bad fixtures; a security-focused bad flow can be added if needed.

…ner engine)

Add the Salesforce Code Analyzer v5 Flow Scanner engine as a new linter in
the SALESFORCE descriptor. It runs `sf code-analyzer run --rule-selector flow`
against `**/*.flow-meta.xml` files to audit Salesforce Flows for security
issues, reusing the already-installed @salesforce/plugin-code-analyzer.

- New linter entry code-analyzer-flow / SALESFORCE_CODE_ANALYZER_FLOW
- Reuses the shared code-analyzer plugin install (no new dependency)
- Known-error guidance for invalid config, no target flows, and the
  engine's Python 3.10+ requirement
- amd64 only, matching the sibling Code Analyzer engines
@github-actions

github-actions Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

⚠️MegaLinter analysis: Success with warnings

⚠️ PYTHON / bandit - 135 errors
---------------------
>> Issue: [B311:blacklist] Standard pseudo-random generators are not suitable for security/cryptographic purposes.
   Severity: Low   Confidence: High
   CWE: CWE-330 (https://cwe.mitre.org/data/definitions/330.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/blacklists/blacklist_calls.html#b311-random
   Location: ./megalinter/utils_sarif.py:156:61
155	                        rule["id"] = (
156	                            rule["id"] + "_DUPLICATE_" + str(random.randint(1, 99999))
157	                        )

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:124:4
123	    )
124	    assert os.path.isdir(config.get(request_id, "DEFAULT_WORKSPACE")), (
125	        "DEFAULT_WORKSPACE "
126	        + config.get(request_id, "DEFAULT_WORKSPACE")
127	        + " is not a valid folder"
128	    )
129	

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:172:4
171	    tmp_report_folder = tempfile.gettempdir() + os.path.sep + str(uuid.uuid4())
172	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
173	    linter_name = linter.linter_name

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:246:4
245	    tmp_report_folder = tempfile.gettempdir() + os.path.sep + str(uuid.uuid4())
246	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
247	    if os.path.isfile(workspace + os.path.sep + "no_test_failure"):

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:501:4
500	    )
501	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
502	    expected_file_name = ""

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:601:4
600	        workspace += os.path.sep + "bad"
601	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
602	    # Call linter

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:695:4
694	        workspace = workspace + os.path.sep + "fix"
695	    assert os.path.isdir(workspace), f"Test folder {workspace} is not existing"
696	

--------------------------------------------------
>> Issue: [B101:assert_used] Use of assert detected. The enclosed code will be removed when compiling to optimised byte code.
   Severity: Low   Confidence: High
   CWE: CWE-703 (https://cwe.mitre.org/data/definitions/703.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b101_assert_used.html
   Location: ./megalinter/utilstest.py:801:12
800	            ]
801	            assert (len(list(diffs))) > 0, f"No changes in the {file} file"
802	

--------------------------------------------------
>> Issue: [B108:hardcoded_tmp_directory] Probable insecure usage of temp file/directory.
   Severity: Medium   Confidence: Medium
   CWE: CWE-377 (https://cwe.mitre.org/data/definitions/377.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b108_hardcoded_tmp_directory.html
   Location: ./server/server.py:81:42
80	    if item.fileUploadId:
81	        uploaded_file_path = os.path.join("/tmp/server-files", item.fileUploadId)
82	        if not os.path.isdir(uploaded_file_path):

--------------------------------------------------
>> Issue: [B108:hardcoded_tmp_directory] Probable insecure usage of temp file/directory.
   Severity: Medium   Confidence: Medium
   CWE: CWE-377 (https://cwe.mitre.org/data/definitions/377.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b108_hardcoded_tmp_directory.html
   Location: ./server/server.py:103:38
102	    file_upload_id = "FILE_" + str(uuid1())
103	    uploaded_file_path = os.path.join("/tmp/server-files", file_upload_id)
104	    os.makedirs(uploaded_file_path)

--------------------------------------------------
>> Issue: [B108:hardcoded_tmp_directory] Probable insecure usage of temp file/directory.
   Severity: Medium   Confidence: Medium
   CWE: CWE-377 (https://cwe.mitre.org/data/definitions/377.html)
   More Info: https://bandit.readthedocs.io/en/1.9.4/plugins/b108_hardcoded_tmp_directory.html
   Location: ./server/server_worker.py:98:34
97	        temp_dir = self.create_temp_dir()
98	        upload_dir = os.path.join("/tmp/server-files", file_upload_id)
99	        if os.path.exists(upload_dir):

--------------------------------------------------

Code scanned:
	Total lines of code: 20027
	Total lines skipped (#nosec): 0
	Total potential issues skipped due to specifically being disabled (e.g., #nosec BXXX): 0

Run metrics:
	Total issues (by severity):
		Undefined: 0
		Low: 104
		Medium: 22
		High: 9
	Total issues (by confidence):
		Undefined: 0
		Low: 14
		Medium: 20
		High: 101
Files skipped (0):

(Truncated to last 6666 characters out of 91273)
⚠️ BASH / bash-exec - 1 error
Results of bash-exec linter (version 5.3.9)
See documentation on https://megalinter.io/beta/descriptors/bash_bash_exec/
-----------------------------------------------

✅ [SUCCESS] .automation/build_schemas_doc.sh
✅ [SUCCESS] .automation/format-tables.sh
✅ [SUCCESS] .vscode/testlinter.sh
✅ [SUCCESS] build.sh
✅ [SUCCESS] entrypoint.sh
❌ [ERROR] sh/megalinter_exec.sh
    Error: File:[sh/megalinter_exec.sh] is not executable

✅ [SUCCESS] sh/setup-runtime-user.sh
⚠️ SPELL / lychee - 52 errors
e.io/pmd-6.55.0/pmd_userdocs_tools_ci.html (at 134:32) | Error (cached)

Errors in megalinter/descriptors/jsx.megalinter-descriptor.yml
[404] https://eslint-react.xyz/docs/getting-started/installation (at 82:37) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/kotlin.megalinter-descriptor.yml
[404] https://pinterest.github.io/ktlint/latest/api/custom-rule-set/ (at 67:15) | Rejected status code: 404 Not Found
[404] https://pinterest.github.io/ktlint/latest/faq/#how-do-i-suppress-errors-for-a-lineblockfile (at 38:38) | Rejected status code: 404 Not Found
[404] https://pinterest.github.io/ktlint/latest/rules/configuration-ktlint/ (at 37:37) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/kubernetes.megalinter-descriptor.yml
[404] https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/%7B%7B.Group%7D%7D/%7B%7B.ResourceKind%7D%7D_%7B%7B.ResourceAPIVersion%7D%7D.json (at 69:22) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/latex.megalinter-descriptor.yml
[TIMEOUT] https://www.nongnu.org/chktex (at 26:17) | Request timed out
[TIMEOUT] https://www.nongnu.org/chktex/ (at 29:23) | Request timed out
[TIMEOUT] https://www.nongnu.org/chktex/ (at 31:38) | Request timed out

Errors in megalinter/descriptors/markdown.megalinter-descriptor.yml
[404] https://github.com/rvben/rumdl/blob/main/docs/RULES.md (at 251:23) | Rejected status code: 404 Not Found
[403] https://www.npmjs.com/package/markdown-table-formatter (at 190:17) | Rejected status code: 403 Forbidden

Errors in megalinter/descriptors/repository.megalinter-descriptor.yml
[404] https://raw.githubusercontent.com/oxsecurity/megalinter/main/docs/assets/icons/linters/betterleaks.png (at 448:26) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/rst.megalinter-descriptor.yml
[403] https://docutils.sourceforge.io/docs/ref/rst/directives.html#raw-data-pass-through (at 34:38) | Rejected status code: 403 Forbidden

Errors in megalinter/descriptors/salesforce.megalinter-descriptor.yml
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/config.html (at 366:37) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/engine-flow.html (at 363:17) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 172:17) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 270:17) | Error (cached)
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 466:17) | Error (cached)
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 568:17) | Error (cached)
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 661:17) | Error (cached)
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/get-started.html (at 72:17) | Rejected status code: 403 Forbidden
[403] https://developer.salesforce.com/docs/platform/salesforce-code-analyzer/guide/rules-flow.html (at 365:23) | Rejected status code: 403 Forbidden
[404] https://github.com/Lightning-Flow-Scanner/lightning-flow-scanner-core#rules (at 746:23) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/terraform.megalinter-descriptor.yml
[404] https://github.com/gruntwork-io/terragrunt/blob/master/docs/assets/img/favicon/ms-icon-310x310.png (at 176:23) | Rejected status code: 404 Not Found | Followed 1 redirect. Redirects: https://github.com/gruntwork-io/terragrunt/blob/master/docs/assets/img/favicon/ms-icon-310x310.png --[302]--> https://github.com/gruntwork-io/terragrunt/blob/main/docs/assets/img/favicon/ms-icon-310x310.png

Errors in megalinter/descriptors/tsx.megalinter-descriptor.yml
[404] https://eslint-react.xyz/docs/getting-started/installation (at 82:37) | Rejected status code: 404 Not Found

Errors in megalinter/descriptors/xml.megalinter-descriptor.yml
[406] https://gitlab.gnome.org/GNOME/libxml2/-/wikis/home (at 38:17) | Rejected status code: 406 Not Acceptable

Errors in README.md
[301] https://future-architect.github.io/authors/%E5%AE%AE%E6%B0%B8%E5%B4%87%E5%8F%B2 (at 1791:104) | Rejected status code: 301 Moved Permanently
[TIMEOUT] https://generated.at/ (at 1147:301) | Request timed out
[404] https://github.com/oxsecurity/megalinter/stargazers (at 1926:3) | Rejected status code: 404 Not Found
[404] https://github.com/oxsecurity/megalinter/stargazers/ (at 22:1) | Rejected status code: 404 Not Found
[403] https://medium.com/@caodanju/30-seconds-to-setup-megalinter-your-go-to-tool-for-automated-code-quality-and-iac-security-969d90a5a99c (at 1759:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/@RunningMattress (at 1768:255) | Rejected status code: 403 Forbidden
[403] https://medium.com/@RunningMattress/level-up-your-unity-packages-with-ci-cd-9498d2791211 (at 1768:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/@SeasonedDeveloper (at 1755:255) | Rejected status code: 403 Forbidden
[403] https://medium.com/@SeasonedDeveloper/looking-for-the-best-ci-cd-pipeline-linting-tool-try-megalinter-d89c9eba850d (at 1755:3) | Rejected status code: 403 Forbidden
[403] https://medium.com/datamindedbe/integrating-megalinter-to-automate-linting-across-multiple-codebases-a-technical-description-a200bb235b71 (at 1756:3) | Rejected status code: 403 Forbidden
[403] https://npmjs.org/package/mega-linter-runner (at 1062:1) | Error (cached)
[403] https://npmjs.org/package/mega-linter-runner (at 1063:1) | Error (cached)
[403] https://npmjs.org/package/mega-linter-runner (at 1064:1) | Error (cached)
[403] https://npmjs.org/package/mega-linter-runner (at 21:1) | Rejected status code: 403 Forbidden | Followed 1 redirect. Redirects: https://npmjs.org/package/mega-linter-runner --[301]--> https://www.npmjs.com/package/mega-linter-runner
[403] https://pmd.sourceforge.io/pmd-6.55.0/pmd_userdocs_tools_ci.html (at 1858:3) | Rejected status code: 403 Forbidden
[403] https://www.npmjs.com/package/@downatthebottomofthemolehole/megalinter-mcp-server (at 1733:354) | Rejected status code: 403 Forbidden

Hint: Followed 731 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: Rejected redirectional status codes. This means some redirects were not followed. You might want to increase the limit for `-m`/`--max-redirects`.

(Truncated to last 6666 characters out of 31115)
⚠️ MARKDOWN / markdownlint - 361 errors
uld have alternate text (alt text)
docs/reporters/ApiReporter.md:330:1 error MD045/no-alt-text Images should have alternate text (alt text)
docs/reporters/ApiReporter.md:338:1 error MD045/no-alt-text Images should have alternate text (alt text)
docs/reporters/ApiReporter.md:344:1 error MD045/no-alt-text Images should have alternate text (alt text)
docs/reporters/ApiReporter.md:354:1 error MD045/no-alt-text Images should have alternate text (alt text)
docs/reporters/ApiReporter.md:360:1 error MD045/no-alt-text Images should have alternate text (alt text)
docs/reporters/AzureCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Azure Comment Reporter"]
docs/reporters/BitbucketCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Bitbucket Comment Reporter"]
docs/reporters/ConfigReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "IDE Configuration Reporter"]
docs/reporters/ConsoleReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Console Reporter"]
docs/reporters/EmailReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "E-mail Reporter"]
docs/reporters/FileIoReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "File.io Reporter"]
docs/reporters/GitHubCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "GitHub Comment Reporter"]
docs/reporters/GitHubCommentReporter.md:27:196 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:27:46 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:27:174 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:27:196 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:28:179 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:28:46 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:28:160 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:28:179 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:29:159 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:29:48 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:29:143 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:29:159 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:30:171 error MD056/table-column-count Table column count [Expected: 4; Actual: 3; Too few cells, row will be missing data]
docs/reporters/GitHubCommentReporter.md:30:46 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:30:152 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubCommentReporter.md:30:171 error MD060/table-column-style Table column style [Table pipe does not align with header for style "aligned"]
docs/reporters/GitHubStatusReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "GitHub Status Reporter"]
docs/reporters/GitlabCommentReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Gitlab Comment Reporter"]
docs/reporters/JsonReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "JSON Reporter"]
docs/reporters/MarkdownSummaryReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Markdown Summary Reporter"]
docs/reporters/SarifReporter.md:6 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "SARIF Reporter (beta)"]
docs/reporters/TapReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "TAP Reporter"]
docs/reporters/TextReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Text Reporter"]
docs/reporters/UpdatedSourcesReporter.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Updated Sources Reporter"]
docs/special-thanks.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Special thanks"]
docs/special-thanks.md:23:3 error MD045/no-alt-text Images should have alternate text (alt text)
docs/sponsor.md:5 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Sponsoring"]
docs/supported-linters.md:9 error MD025/single-title/single-h1 Multiple top-level headings in the same document [Context: "Supported Linters"]
mega-linter-runner/generators/mega-linter-custom-flavor/templates/README.md:69 error MD024/no-duplicate-heading Multiple headings with the same content [Context: "How to use the custom flavor"]
mega-linter-runner/README.md:27:274 error MD051/link-fragments Link fragments should be valid [Context: "[**apply formatting and auto-fixes**](#apply-fixes)"]
mega-linter-runner/README.md:27:217 error MD051/link-fragments Link fragments should be valid [Context: "[**reports in several formats**](#reports)"]
README.md:190:127 error MD051/link-fragments Link fragments should be valid [Context: "[many additional features](#mega-linter-vs-super-linter)"]
README.md:1953:3 error MD045/no-alt-text Images should have alternate text (alt text)

(Truncated to last 6666 characters out of 47606)
⚠️ YAML / prettier - 14 errors
selint/Spelling.yml 2ms (unchanged)
.github/linters/valestyles/proselint/Typography.yml 5ms (unchanged)
.github/linters/valestyles/proselint/Uncomparables.yml 8ms (unchanged)
.github/linters/valestyles/proselint/Very.yml 2ms (unchanged)
.github/release-drafter.yml 14ms (unchanged)
.grype.yaml 4ms (unchanged)
.mega-linter.yml 20ms (unchanged)
.pre-commit-hooks.yaml 11ms (unchanged)
action.yml 6ms (unchanged)
codecov.yml 2ms (unchanged)
mega-linter-runner/.eslintrc.yml 3ms (unchanged)
mega-linter-runner/.mega-linter.yml 7ms (unchanged)
mega-linter-runner/generators/mega-linter-custom-flavor/templates/action.yml 5ms (unchanged)
mega-linter-runner/generators/mega-linter-custom-flavor/templates/check-new-megalinter-version.yml 28ms (unchanged)
mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor-builder.yml 16ms (unchanged)
[error] mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor.yml: SyntaxError: Implicit map keys need to be followed by map values (6:1)
[error]   4 | label: <%= CUSTOM_FLAVOR_LABEL %>
[error]   5 | linters:
[error] > 6 | <%= CUSTOM_FLAVOR_LINTERS %>
[error]     | ^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[error]   7 |
mega-linter-runner/generators/mega-linter/templates/.drone.yml 6ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/.gitlab-ci.yml 11ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/azure-pipelines.yml 16ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/bitbucket-pipelines.yml 13ms (unchanged)
mega-linter-runner/generators/mega-linter/templates/concourse-task.yml 8ms (unchanged)
[error] mega-linter-runner/generators/mega-linter/templates/mega-linter.yml: SyntaxError: Implicit map keys need to be followed by map values (67:11)
[error]   65 |           # Only define `secrets.PAT` if you fully understand the trade-off.
[error]   66 |           token: ${{ secrets.PAT || secrets.GITHUB_TOKEN }}
[error] > 67 |           <%- PERSIST_CREDENTIALS %>
[error]      |           ^^^^^^^^^^^^^^^^^^^^^^^^^^
[error]   68 |
[error]   69 |           # If you use VALIDATE_ALL_CODEBASE = true, you can remove this line to
[error]   70 |           # improve performance
megalinter/descriptors/action.megalinter-descriptor.yml 32ms (unchanged)
megalinter/descriptors/ansible.megalinter-descriptor.yml 16ms (unchanged)
megalinter/descriptors/api.megalinter-descriptor.yml 17ms (unchanged)
megalinter/descriptors/arm.megalinter-descriptor.yml 14ms (unchanged)
megalinter/descriptors/bash.megalinter-descriptor.yml 28ms (unchanged)
megalinter/descriptors/bicep.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/c.megalinter-descriptor.yml 29ms (unchanged)
megalinter/descriptors/clojure.megalinter-descriptor.yml 24ms (unchanged)
megalinter/descriptors/cloudformation.megalinter-descriptor.yml 13ms (unchanged)
megalinter/descriptors/coffee.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/copypaste.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/cpp.megalinter-descriptor.yml 15ms (unchanged)
megalinter/descriptors/csharp.megalinter-descriptor.yml 24ms (unchanged)
megalinter/descriptors/css.megalinter-descriptor.yml 14ms (unchanged)
megalinter/descriptors/dart.megalinter-descriptor.yml 16ms (unchanged)
megalinter/descriptors/dockerfile.megalinter-descriptor.yml 12ms (unchanged)
megalinter/descriptors/editorconfig.megalinter-descriptor.yml 8ms (unchanged)
megalinter/descriptors/env.megalinter-descriptor.yml 9ms (unchanged)
megalinter/descriptors/gherkin.megalinter-descriptor.yml 12ms (unchanged)
megalinter/descriptors/go.megalinter-descriptor.yml 14ms (unchanged)
megalinter/descriptors/graphql.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/groovy.megalinter-descriptor.yml 12ms (unchanged)
megalinter/descriptors/html.megalinter-descriptor.yml 15ms (unchanged)
megalinter/descriptors/java.megalinter-descriptor.yml 18ms (unchanged)
megalinter/descriptors/javascript.megalinter-descriptor.yml 56ms (unchanged)
megalinter/descriptors/json.megalinter-descriptor.yml 72ms (unchanged)
megalinter/descriptors/jsx.megalinter-descriptor.yml 13ms (unchanged)
megalinter/descriptors/kotlin.megalinter-descriptor.yml 7ms (unchanged)
megalinter/descriptors/kubernetes.megalinter-descriptor.yml 25ms (unchanged)
megalinter/descriptors/latex.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/lua.megalinter-descriptor.yml 29ms (unchanged)
megalinter/descriptors/makefile.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/markdown.megalinter-descriptor.yml 46ms (unchanged)
megalinter/descriptors/perl.megalinter-descriptor.yml 11ms (unchanged)
megalinter/descriptors/php.megalinter-descriptor.yml 67ms (unchanged)
megalinter/descriptors/powershell.megalinter-descriptor.yml 14ms (unchanged)
megalinter/descriptors/protobuf.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/puppet.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/python.megalinter-descriptor.yml 113ms (unchanged)
megalinter/descriptors/r.megalinter-descriptor.yml 11ms (unchanged)
megalinter/descriptors/raku.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/repository.megalinter-descriptor.yml 191ms (unchanged)
megalinter/descriptors/robotframework.megalinter-descriptor.yml 14ms (unchanged)
megalinter/descriptors/rst.megalinter-descriptor.yml 14ms (unchanged)
megalinter/descriptors/ruby.megalinter-descriptor.yml 13ms (unchanged)
megalinter/descriptors/rust.megalinter-descriptor.yml 9ms (unchanged)
megalinter/descriptors/salesforce.megalinter-descriptor.yml 75ms (unchanged)
megalinter/descriptors/scala.megalinter-descriptor.yml 15ms (unchanged)
megalinter/descriptors/snakemake.megalinter-descriptor.yml 5ms (unchanged)
megalinter/descriptors/spell.megalinter-descriptor.yml 36ms (unchanged)
megalinter/descriptors/sql.megalinter-descriptor.yml 29ms (unchanged)
megalinter/descriptors/swift.megalinter-descriptor.yml 21ms (unchanged)
megalinter/descriptors/tekton.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/terraform.megalinter-descriptor.yml 28ms (unchanged)
megalinter/descriptors/tsx.megalinter-descriptor.yml 19ms (unchanged)
megalinter/descriptors/typescript.megalinter-descriptor.yml 32ms (unchanged)
megalinter/descriptors/vbdotnet.megalinter-descriptor.yml 10ms (unchanged)
megalinter/descriptors/xml.megalinter-descriptor.yml 6ms (unchanged)
megalinter/descriptors/yaml.megalinter-descriptor.yml 19ms (unchanged)
server/docker-compose-dev.yml 14ms (unchanged)
server/docker-compose.yml 7ms (unchanged)
trivy-secret.yaml 2ms (unchanged)
zizmor.yml 2ms (unchanged)

(Truncated to last 6666 characters out of 12077)
⚠️ YAML / yamllint - 42 errors
.grype.yaml
  6:1       warning  missing document start "---"  (document-start)

mega-linter-runner/.eslintrc.yml
  11:9      warning  too few spaces inside empty braces  (braces)

mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor-builder.yml
  48:15     warning  too few spaces inside empty braces  (braces)

mega-linter-runner/generators/mega-linter-custom-flavor/templates/megalinter-custom-flavor.yml
  7:1       error    syntax error: could not find expected ':' (syntax)

mega-linter-runner/generators/mega-linter/templates/mega-linter.yml
  38:15     warning  too few spaces inside empty braces  (braces)
  69:11     error    syntax error: could not find expected ':' (syntax)

megalinter/descriptors/copypaste.megalinter-descriptor.yml
  18:301    warning  line too long (313 > 300 characters)  (line-length)

megalinter/descriptors/javascript.megalinter-descriptor.yml
  54:301    warning  line too long (475 > 300 characters)  (line-length)
  348:301   warning  line too long (307 > 300 characters)  (line-length)

megalinter/descriptors/jsx.megalinter-descriptor.yml
  30:301    warning  line too long (475 > 300 characters)  (line-length)

megalinter/descriptors/markdown.megalinter-descriptor.yml
  89:301    warning  line too long (366 > 300 characters)  (line-length)

megalinter/descriptors/perl.megalinter-descriptor.yml
  26:301    warning  line too long (310 > 300 characters)  (line-length)

megalinter/descriptors/php.megalinter-descriptor.yml
  195:301   warning  line too long (389 > 300 characters)  (line-length)
  209:301   warning  line too long (302 > 300 characters)  (line-length)

megalinter/descriptors/repository.megalinter-descriptor.yml
  183:301   warning  line too long (408 > 300 characters)  (line-length)
  273:301   warning  line too long (329 > 300 characters)  (line-length)
  305:301   warning  line too long (306 > 300 characters)  (line-length)
  310:301   warning  line too long (321 > 300 characters)  (line-length)
  450:301   warning  line too long (345 > 300 characters)  (line-length)
  627:301   warning  line too long (338 > 300 characters)  (line-length)
  718:301   warning  line too long (306 > 300 characters)  (line-length)
  881:301   warning  line too long (316 > 300 characters)  (line-length)
  1206:301  warning  line too long (1263 > 300 characters)  (line-length)
  1299:301  warning  line too long (879 > 300 characters)  (line-length)
  1313:301  warning  line too long (358 > 300 characters)  (line-length)
  1375:301  warning  line too long (346 > 300 characters)  (line-length)
  1382:301  warning  line too long (307 > 300 characters)  (line-length)

megalinter/descriptors/salesforce.megalinter-descriptor.yml
  52:301    warning  line too long (359 > 300 characters)  (line-length)
  446:301   warning  line too long (359 > 300 characters)  (line-length)

megalinter/descriptors/spell.megalinter-descriptor.yml
  174:301   warning  line too long (315 > 300 characters)  (line-length)

megalinter/descriptors/sql.megalinter-descriptor.yml
  103:301   warning  line too long (319 > 300 characters)  (line-length)

megalinter/descriptors/terraform.megalinter-descriptor.yml
  27:301    warning  line too long (330 > 300 characters)  (line-length)
  92:301    warning  line too long (391 > 300 characters)  (line-length)
  150:301   warning  line too long (346 > 300 characters)  (line-length)
  216:301   warning  line too long (328 > 300 characters)  (line-length)

megalinter/descriptors/tsx.megalinter-descriptor.yml
  30:301    warning  line too long (475 > 300 characters)  (line-length)

megalinter/descriptors/typescript.megalinter-descriptor.yml
  41:301    warning  line too long (475 > 300 characters)  (line-length)
  338:301   warning  line too long (314 > 300 characters)  (line-length)

mkdocs.yml
  8:301     warning  line too long (552 > 300 characters)  (line-length)
  66:5      warning  wrong indentation: expected 6 but found 4  (indentation)
  78:5      warning  wrong indentation: expected 6 but found 4  (indentation)

zizmor.yml
  1:1       warning  missing document start "---"  (document-start)

✅ Linters with no issues

actionlint, betterleaks, black, checkov, cspell, flake8, git_diff, grype, hadolint, isort, jscpd, jsonlint, markdown-table-formatter, mypy, npm-groovy-lint, osv-scanner, pylint, ruff, secretlint, shellcheck, shfmt, syft, trivy, trivy-sbom, trufflehog, v8r, v8r, xmllint, zizmor

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

Resolves cspell false positives in the new SALESFORCE_CODE_ANALYZER_FLOW
descriptor text and Python-detection regex.
The flow linter reused the salesforce-lfs fixture and the shared
code-analyzer.yml, which forced PMD to load ./apex-pmd-ruleset.xml (absent
from that workspace) and raised a Critical pmd:UninstantiableEngineError,
plus the "good" DML flow still tripped High/Moderate flow rules.

- Add TEMPLATES/code-analyzer-flow.yml that disables the PMD engine, since
  the flow linter only selects flow rules (--rule-selector flow). This also
  fixes real-world use on workspaces without an Apex PMD ruleset.
- Point the flow linter at code-analyzer-flow.yml via config_file_name.
- Drop the non-clean DML_Statement_In_A_Loop_Fixed flow from the good
  fixture; the remaining flow only yields sub-threshold (Low) violations.
The MegaLinter self-scan reported 258 cspell errors across every linter
doc page (projectb/projectr/fileb/argumentb/argumentr) - each is a real
word that sits immediately before a <br/> in the generated CLI_LINT_MODE
tables, with the tag's "b"/"r" glued on by cspell's HTML handling.

Add an ignoreRegExpList entry that removes <br/> (and <br>, <br />) before
spell-checking so the tag can no longer merge into adjacent words.
MegaLinter's cspell (v10.0.1) tokenizes the <br/> tags in the generated
CLI_LINT_MODE doc tables by gluing the tag's "b"/"r" onto the adjacent
word, producing 258 false positives across every linter doc page
(projectb, projectr, fileb, argumentb, argumentr). This is not
reproducible with cspell + this config outside the MegaLinter runtime,
and a repo-level ignoreRegExpList had no effect, so ignore the five
artifact tokens directly. Also drop that ineffective ignoreRegExpList.
@nvuillam
nvuillam merged commit e9a23f8 into main Jul 14, 2026
142 checks passed
@nvuillam
nvuillam deleted the add-salesforce-code-analyzer-flow branch July 14, 2026 06:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant