Skip to content

fix: honor warn_list after --fix rewrites task names - #5085

Merged
rockygeekz merged 25 commits into
ansible:mainfrom
santosh7676:fix/5030-warn-list-after-fix
Sep 1, 2026
Merged

rockygeekz merged 25 commits into
ansible:mainfrom
santosh7676:fix/5030-warn-list-after-fix

Conversation

@santosh7676

@santosh7676 santosh7676 commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Invalidate stale YAML parse cache when lintable content changes after `--fix`.
  • Preserve `warn_list` `yaml[line-length]` matches during fix reruns.
  • Avoid folding long YAML lines on dump when line-length is warn-only.

Fixes #5030

Summary by CodeRabbit

  • Bug Fixes

    • Improved --fix rerun handling so resolved issues are removed while warning-only issues remain accurately tracked.
    • Preserved updated warning locations after automatic fixes.
    • Prevented stale YAML parsing data when file content changes.
    • Preserved long YAML lines when line-length checks are configured as warnings.
    • Improved include resolution, YAML parsing reliability, and error reporting.
    • Added warnings when directory expansion discovers additional files.
  • Tests

    • Added regression coverage for fix reruns, warning handling, caching, directory expansion, and long-line preservation.

@santosh7676
santosh7676 requested a review from a team as a code owner June 23, 2026 14:03
@github-actions github-actions Bot added the fix label Jun 23, 2026
@santosh7676
santosh7676 force-pushed the fix/5030-warn-list-after-fix branch 3 times, most recently from 058c928 to 15956e1 Compare June 24, 2026 05:37

@rockygeekz rockygeekz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice fix. The yaml.width = 4096 approach is a bit blunt but matches user intent. LGTM.

@rockygeekz rockygeekz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SonarCloud is reporting 75.5% coverage on new code (required >= 90%). No recent merged PRs bypassed this check. Could you add coverage for the uncovered branches in _process_fix_rerun_matches (match.fixed, rule not in rerun, uid in resolved paths)?

@github-project-automation github-project-automation Bot moved this from Review to In Progress in 🧰 devtools project board Jun 25, 2026
@santosh7676

Copy link
Copy Markdown
Contributor Author

Thanks @rockygeekz for the review.
Sure! I will fix the Sonar coverage and push the latest changes.

@santosh7676
santosh7676 requested a review from rockygeekz June 27, 2026 16:56
@santosh7676
santosh7676 force-pushed the fix/5030-warn-list-after-fix branch from e5ae9a1 to d31aa04 Compare June 28, 2026 03:08
@coderabbitai

coderabbitai Bot commented Jul 14, 2026 •

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: feaa7a7a-8d25-4bc3-a921-28ca831cef7d

📥 Commits

Reviewing files that changed from the base of the PR and between dd39cfd and 1a1bd2d.

📒 Files selected for processing (4)
  • src/ansiblelint/file_utils.py
  • src/ansiblelint/utils.py
  • test/test_file_utils.py
  • test/test_utils.py

Included review availability: Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The change updates YAML fix rerun bookkeeping, invalidates stale YAML state, caches parsing by path and content, and preserves long lines when yaml[line-length] remains warning-only.

Changes

YAML fix and rerun handling

Layer / File(s) Summary
Warn-aware fix rerun processing
src/ansiblelint/__main__.py, test/test_main.py
Fix reruns classify warning matches, correlate refreshed violations, remove resolved matches, preserve unrelated matches, and restore runtime options.

YAML parsing and state invalidation

Layer / File(s) Summary
Cached YAML parsing and state invalidation
src/ansiblelint/utils.py, src/ansiblelint/file_utils.py, test/test_file_utils.py, test/test_utils.py
YAML parsing is cached by absolute path and content. Content changes reset lintable state. Returned parse results are independent copies.

Warn-only long-line transformation

Layer / File(s) Summary
Warn-only long-line transformation
src/ansiblelint/transformer.py, test/test_transformer.py, test/test_utils.py
Warn-only long-line handling sets YAML dump width to 4096. Regression tests cover task-name fixes and long shell lines. Directory expansion also logs newly discovered lintables.

Estimated code review effort: 4 (Complex) | ~45 minutes

Merge Risk: ⚪ Minimal · up to 1a1bd

The change refreshes lint data after --fix rewrites task names and preserves warn-only YAML line-length findings; no actionable merge-blocking risk remains beyond normal checks and review.

Suggested reviewers: rockygeekz

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Out of Scope Changes check ⚠️ Warning The pull request includes unrelated directory-expansion warnings and broader include/import resolution changes not required by #5030. Remove unrelated directory-expansion and include/import resolution changes, or link issues that define those requirements.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: preserving warn_list behavior after task-name rewrites during --fix.
Linked Issues check ✅ Passed The changes address #5030 by preserving warned rules, preventing stale matching errors, and applying enabled fixes without editing warned long lines.
Docstring Coverage ✅ Passed Docstring coverage is 90.00% which is sufficient. The required threshold is 80.00%.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
src/ansiblelint/utils.py (1)

1230-1303: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift

Avoid caching the mutated YAML object
_load_yaml_state() mutates the parsed tree in place via append_skipped_rules(), so returning the same cached object for identical (abspath, content) keys lets skip metadata bleed between Lintable instances. Cache the raw parse and clone before appending skips, or keep the cached value immutable.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/ansiblelint/utils.py` around lines 1230 - 1303, The YAML parsing cache
must not return a mutable tree that is later modified by _load_yaml_state() and
append_skipped_rules(). Update _parse_yaml_linenumbers_cached and its cache
usage so cached parse results remain immutable, or return an independent deep
clone for each caller before skip metadata is appended, ensuring identical
(abspath, content) loads do not share mutations.
🧹 Nitpick comments (1)
src/ansiblelint/utils.py (1)

1230-1237: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Unbounded cache now grows with every distinct file version, not just per-file.

Switching the cache key from the Lintable object to (abspath, content) fixes staleness, but also changes growth characteristics: previously the cache was effectively bounded by the number of distinct file paths (content wasn't part of the key); now every distinct content version (e.g. each intermediate --fix rewrite) gets its own permanent entry, and the full file text is stored again as part of the dict key (on top of Lintable._content), for the lifetime of the process.

Consider a bounded cache (functools.lru_cache(maxsize=...)) or keying on a content hash instead of the raw content string to cap memory growth for large repos/files under repeated --fix reruns.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/ansiblelint/utils.py` around lines 1230 - 1237, The cache for
_parse_yaml_linenumbers_cached currently retains every raw content version
indefinitely, causing unbounded memory growth. Replace the unbounded caching
with a bounded functools.lru_cache configuration, or use a content-hash-based
key while enforcing a finite cache size; preserve cache invalidation across
changed file contents and avoid storing full content strings in cache keys when
possible.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/ansiblelint/__main__.py`:
- Around line 264-302: Preserve the caller’s original runtime_options.tags,
runtime_options.lintables, and runtime_options._skip_ansible_syntax_check values
across _process_fix_rerun_matches. Save these fields before the rerun loop,
restore them after all iterations—including when reruns exit through handled
outcomes or exceptions—and keep the temporary per-match values only during
get_matches execution.
- Around line 223-240: Update _handle_warn_list_rerun so repeated violations
sharing the same tag and filename are correlated one-to-one with
new_results.matches, using their original position or consuming each matched
rerun result exactly once. Preserve unmatched warn-list matches and ensure
distinct violations are not overwritten by the first matching result.

---

Outside diff comments:
In `@src/ansiblelint/utils.py`:
- Around line 1230-1303: The YAML parsing cache must not return a mutable tree
that is later modified by _load_yaml_state() and append_skipped_rules(). Update
_parse_yaml_linenumbers_cached and its cache usage so cached parse results
remain immutable, or return an independent deep clone for each caller before
skip metadata is appended, ensuring identical (abspath, content) loads do not
share mutations.

---

Nitpick comments:
In `@src/ansiblelint/utils.py`:
- Around line 1230-1237: The cache for _parse_yaml_linenumbers_cached currently
retains every raw content version indefinitely, causing unbounded memory growth.
Replace the unbounded caching with a bounded functools.lru_cache configuration,
or use a content-hash-based key while enforcing a finite cache size; preserve
cache invalidation across changed file contents and avoid storing full content
strings in cache keys when possible.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Enterprise

Run ID: 85e41409-ec7b-41ea-9dbc-c2c0224c067f

📥 Commits

Reviewing files that changed from the base of the PR and between f1b71a8 and 1d8614b.

📒 Files selected for processing (8)
  • src/ansiblelint/__main__.py
  • src/ansiblelint/file_utils.py
  • src/ansiblelint/transformer.py
  • src/ansiblelint/utils.py
  • test/test_file_utils.py
  • test/test_main.py
  • test/test_transformer.py
  • test/test_utils.py

Comment thread src/ansiblelint/__main__.py
Comment thread src/ansiblelint/__main__.py Outdated

@rockygeekz rockygeekz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @santosh7676, Can you resolve the conflicts and address the coderabbit's review?

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
src/ansiblelint/transformer.py (1)

138-140: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Preserve warn-only lines beyond 4096 columns.

Line 140 still folds a warn-only scalar that exceeds 4096 columns. This modifies content that the fix flow must leave unchanged. Use an effectively unbounded dump width and add a regression case with a line longer than 4096 columns.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/ansiblelint/transformer.py` around lines 138 - 140, Update the width
assigned in the _should_preserve_long_lines() branch to an effectively unbounded
dump width so warn-only scalars longer than 4096 columns remain unchanged. Add a
regression test covering a scalar line exceeding 4096 columns and verify the fix
flow preserves it without folding.

Source: Path instructions

src/ansiblelint/utils.py (1)

804-807: 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Recurse through nested lists.

Line 806 only processes direct mappings. A value such as [[{"__line__": 3}]] retains internal metadata in the sanitized task. This metadata can become part of module arguments.

Proposed fix
     elif isinstance(value, list):
         for item in value:
-            if isinstance(item, MutableMapping):
-                _strip_internal_keys_from_mapping(item)
+            _strip_internal_keys_from_value(item)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/ansiblelint/utils.py` around lines 804 - 807, Update the list branch in
_strip_internal_keys_from_mapping to recurse into every item, including nested
lists, while preserving direct MutableMapping sanitization. Ensure structures
such as nested lists have all internal keys removed before sanitized task data
is used.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@src/ansiblelint/transformer.py`:
- Around line 138-140: Update the width assigned in the
_should_preserve_long_lines() branch to an effectively unbounded dump width so
warn-only scalars longer than 4096 columns remain unchanged. Add a regression
test covering a scalar line exceeding 4096 columns and verify the fix flow
preserves it without folding.

In `@src/ansiblelint/utils.py`:
- Around line 804-807: Update the list branch in
_strip_internal_keys_from_mapping to recurse into every item, including nested
lists, while preserving direct MutableMapping sanitization. Ensure structures
such as nested lists have all internal keys removed before sanitized task data
is used.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: ca1f0164-a5c4-4686-a499-3c58ff00bb36

📥 Commits

Reviewing files that changed from the base of the PR and between 1d8614b and 9da86f1.

📒 Files selected for processing (8)
  • src/ansiblelint/__main__.py
  • src/ansiblelint/file_utils.py
  • src/ansiblelint/transformer.py
  • src/ansiblelint/utils.py
  • test/test_file_utils.py
  • test/test_main.py
  • test/test_transformer.py
  • test/test_utils.py

@santosh7676

Copy link
Copy Markdown
Contributor Author

Apologize for the delay, @rockygeekz,
I have addressed CodeRabbit's observations and resolved the merge conflicts

@santosh7676

Copy link
Copy Markdown
Contributor Author

Frequent CI failures occur due to unrelated changes.

@santosh7676
santosh7676 force-pushed the fix/5030-warn-list-after-fix branch from a2b2057 to 8f11f5f Compare August 28, 2026 08:52
@santosh7676
santosh7676 force-pushed the fix/5030-warn-list-after-fix branch from 0e2c27a to b253b0d Compare August 30, 2026 16:53
@santosh7676

Copy link
Copy Markdown
Contributor Author

@rockygeekz All checks are passed, can you please review and approve.

@rockygeekz rockygeekz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The cache/deepcopy change, warn_list rerun correlation, and yaml.width uncap all look solid, and the integration tests match the reported repro well.

One edge case: in _process_fix_rerun_matches, the uid in resolved shortcut at line 309 pops subsequent yaml matches before _handle_warn_list_rerun runs. I simulated a file with both a non-warn yaml match and a yaml[line-length] warn_list match where the first rerun returns empty — the warn match gets dropped while two warn-only matches would be retained. Probably rare after these fixes, but a guard like skipping the pop for warn_list matches (or a regression test) would close it.

@santosh7676

Copy link
Copy Markdown
Contributor Author

Good catch @rockygeekz
Fixed by guarding the shortcut so it doesn't apply to warn_list matches, they now always go through the real rerun + _handle_warn_list_rerun, which correctly retains them even when that rerun comes back empty

Added test_process_fix_rerun_matches_previously_resolved_keeps_warn_list, which reproduces your scenario (a non-warn yaml match and a yaml[line-length] warn_list match sharing one rule/file, with the non-warn one processed first and its rerun returning empty).

@santosh7676
santosh7676 force-pushed the fix/5030-warn-list-after-fix branch from 436d1d8 to 9261fe4 Compare September 1, 2026 08:43

@rockygeekz rockygeekz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks! LGTM

@github-project-automation github-project-automation Bot moved this from In Progress to Review in 🧰 devtools project board Sep 1, 2026
@rockygeekz
rockygeekz merged commit 878e4f5 into ansible:main Sep 1, 2026
23 checks passed
@github-project-automation github-project-automation Bot moved this from Review to Done in 🧰 devtools project board Sep 1, 2026
ivanch added a commit to ivanch/haven that referenced this pull request Sep 27, 2026
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ansible-lint](https://github.com/ansible/ansible-lint) ([changelog](https://github.com/ansible/ansible-lint/releases)) | minor | `==26.6.0` → `==26.9.0` |

---

### Release Notes

<details>
<summary>ansible/ansible-lint (ansible-lint)</summary>

### [`v26.9.0`](https://github.com/ansible/ansible-lint/releases/tag/v26.9.0)

[Compare Source](ansible/ansible-lint@v26.8.0...v26.9.0)

#### Features

- feat: support `example` section in file `meta/argument_specs.yml` ([#&#8203;5164](ansible/ansible-lint#5164)) [@&#8203;berndfinger](https://github.com/berndfinger)

#### Fixes

- fix: resolve short mock modules during syntax check ([#&#8203;5149](ansible/ansible-lint#5149)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: propagate `extra_vars` to `import_playbook` syntax check ([#&#8203;5148](ansible/ansible-lint#5148)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: resolve nested `include_tasks` relative paths ([#&#8203;5159](ansible/ansible-lint#5159)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: resolve `include_tasks` paths from playbook dir ([#&#8203;5184](ansible/ansible-lint#5184)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: apply profile-level skip list during linting ([#&#8203;5151](ansible/ansible-lint#5151)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: honor `warn_list` after `--fix` rewrites task names ([#&#8203;5085](ansible/ansible-lint#5085)) [@&#8203;santosh7676](https://github.com/santosh7676)
- fix: mock\_modules clobbering collections and args false positives ([#&#8203;5157](ansible/ansible-lint#5157)) [@&#8203;djdanielsson](https://github.com/djdanielsson)
- fix: inject plain-name mock roles path regardless of `--offline` ([#&#8203;5183](ansible/ansible-lint#5183)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: warn users when directory expansion discovers new files ([#&#8203;5158](ansible/ansible-lint#5158)) [@&#8203;rockygeekz](https://github.com/rockygeekz)
- fix: skip auto-fix `no-jinja-when` on string-embedded jinja ([#&#8203;5103](ansible/ansible-lint#5103)) [@&#8203;f1047](https://github.com/f1047)
- fix: do not warn when Jinja block indent is only trim-marker noise ([#&#8203;5153](ansible/ansible-lint#5153)) [@&#8203;DSeaStar](https://github.com/DSeaStar)
- fix: preserve blank lines after flow collections ([#&#8203;5178](ansible/ansible-lint#5178)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: add `validate_argspec` to play schema ([#&#8203;5187](ansible/ansible-lint#5187)) [@&#8203;sameeralam3127](https://github.com/sameeralam3127)
- fix: use ThreadPoolExecutor for syntax check workers ([#&#8203;5173](ansible/ansible-lint#5173)) [@&#8203;rockygeekz](https://github.com/rockygeekz)
- fix: drop ruamel.yaml.clib ([#&#8203;5163](ansible/ansible-lint#5163)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix(deps): upgrade gitpython 3.1.57 to 3.1.59 ([#&#8203;5152](ansible/ansible-lint#5152)) [@&#8203;rockygeekz](https://github.com/rockygeekz)
- fix: upgrade black to >=25.2.0 to address CVE-2026-32274 ([#&#8203;5166](ansible/ansible-lint#5166)) [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh)
- fix: raise cryptography floor and bump js-yaml for Guardian prod vulns ([#&#8203;5174](ansible/ansible-lint#5174)) [@&#8203;rockygeekz](https://github.com/rockygeekz)

#### Performance

- perf: cache `get_deps_versions()` result ([#&#8203;5113](ansible/ansible-lint#5113)) [@&#8203;BlackDark](https://github.com/BlackDark)

#### Maintenance

- chore: Add `.github/SECURITY.md` ([#&#8203;5165](ansible/ansible-lint#5165)) [@&#8203;gundalow](https://github.com/gundalow)
- chore(deps): update all dependencies and pep621 ([#&#8203;5138](ansible/ansible-lint#5138), [#&#8203;5154](ansible/ansible-lint#5154), [#&#8203;5155](ansible/ansible-lint#5155), [#&#8203;5160](ansible/ansible-lint#5160), [#&#8203;5161](ansible/ansible-lint#5161), [#&#8203;5172](ansible/ansible-lint#5172), [#&#8203;5175](ansible/ansible-lint#5175), [#&#8203;5176](ansible/ansible-lint#5176)) @&#8203;[renovate\[bot\]](https://github.com/apps/renovate)

#### What's Changed

- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5138](ansible/ansible-lint#5138)
- fix: resolve short mock modules during syntax check by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5149](ansible/ansible-lint#5149)
- fix(deps): upgrade gitpython 3.1.57 to 3.1.59 by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5152](ansible/ansible-lint#5152)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5155](ansible/ansible-lint#5155)
- fix: propagate extra\_vars to import\_playbook syntax check by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5148](ansible/ansible-lint#5148)
- fix: warn users when directory expansion discovers new files by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5158](ansible/ansible-lint#5158)
- fix: resolve nested include\_tasks relative paths by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5159](ansible/ansible-lint#5159)
- fix: apply profile-level skip list during linting by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5151](ansible/ansible-lint#5151)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5154](ansible/ansible-lint#5154)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5160](ansible/ansible-lint#5160)
- fix: skip auto-fix no-jinja-when on string-embedded jinja by [@&#8203;f1047](https://github.com/f1047) in [#&#8203;5103](ansible/ansible-lint#5103)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5161](ansible/ansible-lint#5161)
- fix: do not warn when Jinja block indent is only trim-marker noise by [@&#8203;DSeaStar](https://github.com/DSeaStar) in [#&#8203;5153](ansible/ansible-lint#5153)
- chore: Add .github/SECURITY.md by [@&#8203;gundalow](https://github.com/gundalow) in [#&#8203;5165](ansible/ansible-lint#5165)
- fix: upgrade black to >=25.2.0 to address CVE-2026-32274 by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5166](ansible/ansible-lint#5166)
- Fix/drop ruamel yaml clib fresh by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5163](ansible/ansible-lint#5163)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5172](ansible/ansible-lint#5172)
- fix: honor warn\_list after --fix rewrites task names  by [@&#8203;santosh7676](https://github.com/santosh7676) in [#&#8203;5085](ansible/ansible-lint#5085)
- feat: support 'example' section in file meta/argument\_specs.yml by [@&#8203;berndfinger](https://github.com/berndfinger) in [#&#8203;5164](ansible/ansible-lint#5164)
- fix: use ThreadPoolExecutor for syntax check workers by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5173](ansible/ansible-lint#5173)
- fix: mock\_modules clobbering collections and args false positives by [@&#8203;djdanielsson](https://github.com/djdanielsson) in [#&#8203;5157](ansible/ansible-lint#5157)
- fix: raise cryptography floor and bump js-yaml for Guardian prod vulns by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5174](ansible/ansible-lint#5174)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5176](ansible/ansible-lint#5176)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5175](ansible/ansible-lint#5175)
- fix: preserve blank lines after flow collections by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5178](ansible/ansible-lint#5178)
- perf: cache get\_deps\_versions() result by [@&#8203;BlackDark](https://github.com/BlackDark) in [#&#8203;5113](ansible/ansible-lint#5113)
- fix: inject plain-name mock roles path regardless of --offline by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5183](ansible/ansible-lint#5183)
- fix: resolve include\_tasks paths from playbook dir by [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) in [#&#8203;5184](ansible/ansible-lint#5184)
- fix: add validate\_argspec to play schema by [@&#8203;sameeralam3127](https://github.com/sameeralam3127) in [#&#8203;5187](ansible/ansible-lint#5187)

#### New Contributors

- [@&#8203;shvenkat-rh](https://github.com/shvenkat-rh) made their first contribution in [#&#8203;5149](ansible/ansible-lint#5149)
- [@&#8203;f1047](https://github.com/f1047) made their first contribution in [#&#8203;5103](ansible/ansible-lint#5103)
- [@&#8203;DSeaStar](https://github.com/DSeaStar) made their first contribution in [#&#8203;5153](ansible/ansible-lint#5153)
- [@&#8203;berndfinger](https://github.com/berndfinger) made their first contribution in [#&#8203;5164](ansible/ansible-lint#5164)
- [@&#8203;BlackDark](https://github.com/BlackDark) made their first contribution in [#&#8203;5113](ansible/ansible-lint#5113)
- [@&#8203;sameeralam3127](https://github.com/sameeralam3127) made their first contribution in [#&#8203;5187](ansible/ansible-lint#5187)

**Full Changelog**: <ansible/ansible-lint@v26.8.0...v26.9.0>

### [`v26.8.0`](https://github.com/ansible/ansible-lint/releases/tag/v26.8.0)

[Compare Source](ansible/ansible-lint@v26.6.0...v26.8.0)

#### What's Changed

- Fix/sonarcloud unbounded recursion complexity by [@&#8203;sathyapramod](https://github.com/sathyapramod) in [#&#8203;5098](ansible/ansible-lint#5098)
- feat: honor ANSIBLE\_VAULT\_PASSWORD\_FILE for vault decryption by [@&#8203;JohnLahr](https://github.com/JohnLahr) in [#&#8203;5019](ansible/ansible-lint#5019)
- fix: jinja\[spacing] rule creating invalid syntax for minus modifiers by [@&#8203;Dotify71](https://github.com/Dotify71) in [#&#8203;5102](ansible/ansible-lint#5102)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5081](ansible/ansible-lint#5081)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5082](ansible/ansible-lint#5082)
- fix: remove stale words from cspell dictionary by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5109](ansible/ansible-lint#5109)
- chore(deps): bump schemas npm packages for Dependabot CVEs by [@&#8203;sudhirverma](https://github.com/sudhirverma) in [#&#8203;5114](ansible/ansible-lint#5114)
- fix(security): update dependencies \[SECURITY] by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5111](ansible/ansible-lint#5111)
- fix: address SonarCloud new code violations by [@&#8203;sudhirverma](https://github.com/sudhirverma) in [#&#8203;5116](ansible/ansible-lint#5116)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5121](ansible/ansible-lint#5121)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5122](ansible/ansible-lint#5122)
- fix(deps): exclude ansible-core 2.17.x (CVE-2026-11332) by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5123](ansible/ansible-lint#5123)
- fix: expose ansible-galaxy on the uv tool-install path by [@&#8203;jeffcpullen](https://github.com/jeffcpullen) in [#&#8203;5124](ansible/ansible-lint#5124)
- fix: var-naming for register projections by [@&#8203;0xTaoZ](https://github.com/0xTaoZ) in [#&#8203;5110](ansible/ansible-lint#5110)
- chore: Adding OpenWrt 25.12 as platform by [@&#8203;sscheib](https://github.com/sscheib) in [#&#8203;5132](ansible/ansible-lint#5132)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5134](ansible/ansible-lint#5134)
- chore(deps): update all dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5133](ansible/ansible-lint#5133)
- fix: add timeout to release-check urlopen() call by [@&#8203;cooperlees](https://github.com/cooperlees) in [#&#8203;5128](ansible/ansible-lint#5128)
- fix: respect ANSIBLE\_HOME env var for cache dir selection ([#&#8203;5806](https://github.com/ansible/ansible-lint/issues/5806)) by [@&#8203;Jkhall81](https://github.com/Jkhall81) in [#&#8203;5105](ansible/ansible-lint#5105)
- fix: deduplicate ANSIBLE\_HOME isolation check by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5140](ansible/ansible-lint#5140)
- fix(security): update dependencies \[SECURITY] by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5141](ansible/ansible-lint#5141)
- fix: do not require role prefix for ansible\_ connection variables by [@&#8203;Sanjays2402](https://github.com/Sanjays2402) in [#&#8203;5130](ansible/ansible-lint#5130)
- Adding missing FreeBSD versions. by [@&#8203;jmpalacios](https://github.com/jmpalacios) in [#&#8203;5143](ansible/ansible-lint#5143)
- chore(deps): update all dependencies pep621 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;5139](ansible/ansible-lint#5139)
- fix: prepend runtime cache dir to collections paths ([#&#8203;5137](ansible/ansible-lint#5137)) by [@&#8203;rockygeekz](https://github.com/rockygeekz) in [#&#8203;5145](ansible/ansible-lint#5145)

#### New Contributors

- [@&#8203;sathyapramod](https://github.com/sathyapramod) made their first contribution in [#&#8203;5098](ansible/ansible-lint#5098)
- [@&#8203;JohnLahr](https://github.com/JohnLahr) made their first contribution in [#&#8203;5019](ansible/ansible-lint#5019)
- [@&#8203;jeffcpullen](https://github.com/jeffcpullen) made their first contribution in [#&#8203;5124](ansible/ansible-lint#5124)
- [@&#8203;0xTaoZ](https://github.com/0xTaoZ) made their first contribution in [#&#8203;5110](ansible/ansible-lint#5110)
- [@&#8203;cooperlees](https://github.com/cooperlees) made their first contribution in [#&#8203;5128](ansible/ansible-lint#5128)
- [@&#8203;Sanjays2402](https://github.com/Sanjays2402) made their first contribution in [#&#8203;5130](ansible/ansible-lint#5130)
- [@&#8203;jmpalacios](https://github.com/jmpalacios) made their first contribution in [#&#8203;5143](ansible/ansible-lint#5143)

**Full Changelog**: <ansible/ansible-lint@v26.6.0...v26.8.0>

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDMuNyIsInVwZGF0ZWRJblZlciI6IjQ0LjEwMy43IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

---------

Co-authored-by: Renovate Bot <bot@renovateapp.com>
Reviewed-on: https://git.ivanch.me/ivanch/haven/pulls/17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

skipped/warned YAML tasks execute anyway under --fix when task name is changed

2 participants