Skip to content

[External Plugin]: megalinter #2773

Description

@nvuillam

Plugin name

megalinter

Short description

Set up, run and fix MegaLinter on any repository: 100+ linters for 69+ languages, 23+ formats and 21+ tooling formats, from CI or locally.

GitHub repository

oxsecurity/megalinter

Plugin path inside the repository

./skills

Ref to review

No response

Commit SHA to review

e96b2d606cd8b32303706e8cd8f9c3c9269eb043

Version

1.0.3

License identifier

AGPL-3.0

Author name

OX Security

Author URL

https://github.com/oxsecurity

Homepage URL

https://megalinter.io

Keywords

linter
code-quality
formatter
security
ci

Additional notes for reviewers

MegaLinter aggregates 100+ linters covering 69+ languages, 23+ formats and 21+ tooling formats.

The plugin lives at the repository root and ships:

  • 4 skills under skills/ (megalinter, megalinter-setup, megalinter-check, megalinter-fix), auto-discovered per Agent Plugins 1.0
  • 3 sub-agents (megalinter-watcher, megalinter-runner, megalinter-fixer)

Manifests: a root plugin.json conforming to Agent Plugins 1.0, with no extra top-level keys.

Updated since the first submission, after the Copilot portability review in this issue:

  • The 3 sub-agents now ship to Copilot clients as com.github.copilot/agents/.agent.md. They were previously declared only in the Claude Code and Cursor manifests, which Copilot does not read, so Copilot loaded none of them. They are generated from the Claude Code definitions, and CI fails if the two drift.
  • megalinter-setup no longer infers the install mode from skill naming, since no platform exposes a skill's origin: it reads the filesystem and asks the user when that is ambiguous. Its manual Copilot instructions now use the required .agent.md suffix in .github/agents/, and drop the model override that is not a Copilot model id.
  • The skills' frontmatter key licence is corrected to license.
  • CI now loads this repository as an external plugin in the GitHub Copilot CLI (copilot --plugin-dir . plugins list --json) and asserts it is accepted with no manifest error. It runs offline, with no marketplace and no authentication.

No API key, credentials, or network service are required. The skills drive the public mega-linter-runner npm package and the MegaLinter Docker image.

Docs: https://megalinter.io/latest/agent-plugins/

Submission checklist

  • The plugin lives in a public GitHub repository.
  • The ref and/or sha I provided is immutable (release tag and/or full 40-character commit SHA), not a branch.
  • This submission follows this repository's contribution, security, and responsible AI policies.
  • This plugin is not already listed in the Awesome Copilot marketplace.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    external-pluginPublic external plugin submissionneeds-review:MEDIUMContributor reputation check flagged MEDIUM riskrequires-submitter-fixesSubmission has quality-gate findings that submitter must fix before maintainer review

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions