fix: resolve sonarqube security findings#1373
Conversation
There was a problem hiding this comment.
Pull request overview
This PR aims to address SonarQube security findings by hardening dependency installation steps in GitHub Actions and tightening wget behavior in devcontainer Dockerfiles and workflows.
Changes:
- Updates
npm install/cisteps to use--ignore-scriptsin CI/action contexts. - Modifies multiple
wgetinvocations (and bumpsdiffocito v0.1.8) to add redirect-related flags. - Adjusts devcontainer build download steps for Rust and C++ flavors.
Reviewed changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated 5 comments.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/wc-build-push.yml | Bumps diffoci download and changes wget flags used during container diff generation. |
| .github/workflows/wc-acceptance-test.yml | Runs npm ci with --ignore-scripts before Playwright installation. |
| .github/actions/container-size-diff/action.yml | Runs npm install with --ignore-scripts for the composite action’s runtime deps. |
| .devcontainer/rust/Dockerfile | Changes wget flags for downloading/extracting cargo-binstall. |
| .devcontainer/cpp/Dockerfile | Changes wget flags for downloading ARM toolchain, IWYU source, and CPM.cmake. |
✅
|
| Descriptor | Linter | Files | Fixed | Errors | Warnings | Elapsed time |
|---|---|---|---|---|---|---|
| ✅ ACTION | actionlint | 23 | 0 | 0 | 0.27s | |
| ✅ DOCKERFILE | hadolint | 4 | 0 | 0 | 0.3s | |
| ✅ JSON | npm-package-json-lint | yes | no | no | 0.51s | |
| ✅ JSON | prettier | 44 | 6 | 0 | 0 | 0.86s |
| ✅ JSON | v8r | 44 | 0 | 0 | 17.19s | |
| ✅ MARKDOWN | markdownlint | 13 | 0 | 0 | 0 | 1.17s |
| ✅ MARKDOWN | markdown-table-formatter | 13 | 0 | 0 | 0 | 0.34s |
| ✅ REPOSITORY | betterleaks | yes | no | no | 1.53s | |
| ✅ REPOSITORY | checkov | yes | no | no | 30.0s | |
| ✅ REPOSITORY | gitleaks | yes | no | no | 1.17s | |
| ✅ REPOSITORY | git_diff | yes | no | no | 0.01s | |
| ✅ REPOSITORY | grype | yes | no | no | 67.94s | |
| osv-scanner | yes | 1 | no | 0.78s | ||
| ✅ REPOSITORY | secretlint | yes | no | no | 2.45s | |
| ✅ REPOSITORY | syft | yes | no | no | 2.79s | |
| ✅ REPOSITORY | trivy | yes | no | no | 15.1s | |
| ✅ REPOSITORY | trivy-sbom | yes | no | no | 0.4s | |
| ✅ REPOSITORY | trufflehog | yes | no | no | 6.79s | |
| lychee | 113 | 1 | 0 | 29.91s | ||
| ✅ YAML | prettier | 33 | 0 | 0 | 0 | 1.38s |
| ✅ YAML | v8r | 33 | 0 | 0 | 15.11s | |
| ✅ YAML | yamllint | 33 | 0 | 0 | 1.36s |
Detailed Issues
⚠️ SPELL / lychee - 1 error
📝 Summary
---------------------
🔍 Total..........154
🔗 Unique.........126
✅ Successful.....148
⏳ Timeouts.........0
🔀 Redirected......19
👻 Excluded.........0
❓ Unknown..........0
🚫 Errors...........1
⛔ Unsupported......1
Errors in .github/TOOL_VERSION_ISSUE_TEMPLATE.md
[403] https://developer.arm.com/downloads/-/arm-gnu-toolchain-downloads (at 38:7) | Rejected status code: 403 Forbidden
Hint: Followed 19 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.
Hint: You can configure accepted/rejected response codes with `-a` or `--accept`
⚠️ REPOSITORY / osv-scanner - 1 error
Scanning dir .
Starting filesystem walk for root: /
Scanned .devcontainer/cpp/requirements.txt file and found 20 packages
Scanned .devcontainer/docs/requirements.txt file and found 14 packages
Scanned test/embedded-rust/workspace/cortex-m/Cargo.lock file and found 20 packages
Scanned test/embedded-rust/workspace/cortex-mf/Cargo.lock file and found 20 packages
Scanned test/rust/workspace/cargo/Cargo.lock file and found 1 package
Scanned test/rust/workspace/clippy/Cargo.lock file and found 1 package
Scanned test/rust/workspace/test/Cargo.lock file and found 1 package
Scanned package-lock.json file and found 73 packages
End status: 105 dirs visited, 342 inodes visited, 8 Extract calls, 33.352706ms elapsed, 33.352906ms wall time
Total 2 packages affected by 2 known vulnerabilities (0 Critical, 0 High, 0 Medium, 0 Low, 2 Unknown) from 1 ecosystem.
0 vulnerabilities can be fixed.
+-----------------------------------+------+-----------+------------+---------+---------------+---------------------------------------------------+
| OSV URL | CVSS | ECOSYSTEM | PACKAGE | VERSION | FIXED VERSION | SOURCE |
+-----------------------------------+------+-----------+------------+---------+---------------+---------------------------------------------------+
| https://osv.dev/RUSTSEC-2026-0110 | | crates.io | bare-metal | 0.2.5 | -- | test/embedded-rust/workspace/cortex-m/Cargo.lock |
| https://osv.dev/RUSTSEC-2026-0110 | | crates.io | bare-metal | 0.2.5 | -- | test/embedded-rust/workspace/cortex-mf/Cargo.lock |
+-----------------------------------+------+-----------+------------+---------+---------------+---------------------------------------------------+
Notices
📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)
See detailed reports in MegaLinter artifacts
You could have the same capabilities but better runtime performances if you use a MegaLinter flavor:
- oxsecurity/megalinter/flavors/salesforce@v9.6.0 (57 linters)
- oxsecurity/megalinter/flavors/javascript@v9.6.0 (63 linters)
Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)
- Documentation: Custom Flavors
- Command:
npx mega-linter-runner@9.6.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,DOCKERFILE_HADOLINT,JSON_V8R,JSON_PRETTIER,JSON_NPM_PACKAGE_JSON_LINT,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_GITLEAKS,REPOSITORY_BETTERLEAKS,REPOSITORY_GRYPE,REPOSITORY_OSV_SCANNER,REPOSITORY_SECRETLINT,REPOSITORY_SYFT,REPOSITORY_TRIVY,REPOSITORY_TRIVY_SBOM,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

Show us your support by starring ⭐ the repository
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
📦 Container Size AnalysisNote Comparing 📈 Size Comparison Table
|
wget's --https-only does not work for single file downloads, it only works in recursive mode
|
Pull Request Report (#1373)Static measures
Time related measures
Status check related measures
|
|
🎉 Hooray! The changes in this pull request went live with the release of v8.0.1 🎉 |



🚀 Hey, I have created a Pull Request
Description of changes
This pull request updates the development container Dockerfiles for C++ and Rust to improve supply chain security, reproducibility, and consistency in dependency management. It also makes minor improvements to GitHub Actions workflows. The most important changes are grouped below.
C++ Devcontainer Improvements:
CPM.cmakeandinclude-what-you-use(IWYU) by downloading these dependencies in the Docker build and installing from local sources, rather than fetching at build time. This improves reproducibility and supply chain security. [1] [2] [3] [4] [5] [6]ccache,xwin) by usinginstall -m 0755instead ofcp, ensuring correct permissions.update-alternativescommands to use quoted paths for improved safety.Rust Devcontainer Improvements:
cargo-binstallbinary with checksum validation, instead of fetching and extracting directly from GitHub. This enhances supply chain security and reproducibility. [1] [2] [3] [4]cargo-binstall.CI Workflow Improvements:
npm installandnpm cicommands in GitHub Actions to use--ignore-scripts, improving CI security by preventing arbitrary script execution during dependency installation. [1] [2]diffocitool to version 0.1.8 with checksum verification in the build workflow, improving security and reliability of image comparison.✔️ Checklist