Skip to content

Add Draw.io MCP Server to README.md - #315

Open
lgazo wants to merge 3 commits into
hashgraph-online:mainfrom
lgazo:patch-1
Open

lgazo wants to merge 3 commits into
hashgraph-online:mainfrom
lgazo:patch-1

Conversation

@lgazo

@lgazo lgazo commented Sep 16, 2026

Copy link
Copy Markdown

No description provided.

@github-actions

github-actions Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

@lgazo, the required source scan must pass before merge.

The centralized source scan returned: failure. A passing scan (score at least 80 with no critical or high findings) is required before merge. Review the rule-level findings and rerun the scan.

Scanner CI in the source repository is optional. The centralized scan must pass; review its findings and rerun the contribution check.

Push the correction and this comment will update on the next check. Contribution requirements. Latest sweep.

@kantorcodes

Copy link
Copy Markdown
Member

The centralized scan is 78/100, below the required 80, with 45 medium and 7 low findings. Please remediate or document the rule-level findings, add the pinned scanner workflow for reproducible source-side results, rerun the source and catalog scans, and request review once the score reaches at least 80; this PR remains unmerged.

@kantorcodes kantorcodes left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Centralized HOL scan is 78/100, below the 80 merge threshold, with 45 medium and 7 low findings. Fix the Claude marketplace structure, SHA-pin third-party Actions, and add Dependabot plus missing lockfile/security metadata where applicable. The source has no HOL scanner workflow, so add the SHA-pinned workflow from SCANNER_GUIDE.md, link the source run, then rerun the centralized scan.

@kantorcodes
kantorcodes dismissed their stale review September 22, 2026 10:23

Centralized scanning and source-repository scanner CI are advisory under the current repository policy, so this review no longer represents merge requirements.

@kantorcodes kantorcodes left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The updated head scores 78/100, below the required 80-point threshold, with 45 medium and 7 low findings. Please address the marketplace, action-pinning, Dependabot, lockfile, and security metadata findings and rerun the centralized scan; lgazo/drawio-mcp-server has no source scanner CI, so adding the SHA-pinned HOL Plugin Scanner workflow from SCANNER_GUIDE.md, running the same pinned scanner locally and in source CI, linking that run, and requesting re-review at 80+ is recommended.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants