Repository navigation
Conversation
Adds ayghri/i-have-adhd to the Development & Workflow section, following the request in ayghri/i-have-adhd#141. The source project documents support for GitHub Copilot and other coding assistants. This is a README-only change.
|
@hamulante, the required source scan must pass before merge. The centralized source scan returned: failure. A passing scan (score at least 80 with no critical or high findings) is required before merge. Review the rule-level findings and rerun the scan. Scanner CI in the source repository is optional. The centralized scan must pass; review its findings and rerun the contribution check. Push the correction and this comment will update on the next check. Contribution requirements. Latest sweep. |
|
The centralized scan is 77/100, below the required 80, with 38 medium, 9 low, and 4 informational findings. Please remediate or document the rule-level findings, add the pinned scanner workflow for reproducible source-side results, rerun the source and catalog scans, and request review once the score reaches at least 80; this PR remains unmerged. |
|
Thanks for the review. I’m addressing the source-side requirements in ayghri/i-have-adhd#226. The pinned scanner workflow passes on the fork with a score of 81/100: https://github.com/hamulante/i-have-adhd/actions/runs/35302125863 I’ll follow up and request a catalog rescan once the source PR is merged. |
kantorcodes
left a comment
There was a problem hiding this comment.
Centralized HOL scan is 77/100, below the 80 merge threshold, with 38 medium and 9 low findings. SHA-pin third-party Actions, fix the Codex marketplace/source validation findings, and add Dependabot plus lockfile coverage. Add the SHA-pinned HOL scanner workflow from SCANNER_GUIDE.md, run the same pinned scanner in source CI, link that run, then rerun the catalog scan.
|
Thanks for the detailed review. I can address the Action pinning, Dependabot, lockfile coverage, and pinned source-side scanner CI in ayghri/i-have-adhd#226. Before changing The current manifest uses a remote URL source consistent with the repository's documented installation flow: The scanner recommends replacing it with a local Would you be open to accepting these two findings as documented limitations? The proposed source changes currently score 81/100 in the pinned scanner workflow on the fork, with no critical or high findings. The source PR has not |
|
Yes, those marketplace findings can stay documented if the centralized scan reaches 80+ after the source hardening lands. I would not change the manifest just to satisfy a static rule without a validated Codex path. Once ayghri/i-have-adhd#226 is merged, rerun the catalog scan; if it scores 80+ and the required catalog checks pass, I’ll clear the old 77/100 review. |
Centralized scanning and source-repository scanner CI are advisory under the current repository policy, so this review no longer represents merge requirements.
kantorcodes
left a comment
There was a problem hiding this comment.
The updated head scores 77/100, below the required 80-point threshold, with 38 medium and 9 low findings. Please address or document the marketplace and source-safety findings and rerun the centralized scan; ayghri/i-have-adhd has no source scanner CI, so adding the SHA-pinned HOL Plugin Scanner workflow from SCANNER_GUIDE.md, running the same pinned scanner locally and in source CI, linking that run, and requesting re-review at 80+ is recommended.
Summary
i-have-adhdto Community Plugins → Development & Workflow.README.md.Context
Requested in ayghri/i-have-adhd#141.
The source project documents support for GitHub Copilot and other coding assistants.
Validation