Conversation
|
✅ Contribution check passed. @zachdunn, catalog validation succeeded. scan findingsHOL centralized scan reported findings or did not pass: failure. This is advisory and does not block listing. Recommended: add scanner CI for securityThis listing can merge without it. HOL still scans We recommend including Adding it:
See CONTRIBUTING.md and SCANNER_GUIDE.md. HOL's centralized scan reported findings. This does not block listing. |
|
The centralized scan is 71/100, below the required 80, with 76 high, 1 medium, and 2 low findings. The README also begins with an extraneous downloaded-file SHA line; remove that line, remediate or document the rule-level findings, add the pinned scanner workflow for reproducible source-side results, rerun the scans, and request review once the score reaches at least 80; this PR remains unmerged. |
|
Thanks for the review. Local
We’re fine adding a root We won’t add the scanner Action as permanent CI on this monorepo. If listing requires ≥80 with no highs under the current rules, we may close rather than chase false positives — unless you can scope the scan to the plugin package or provide exemptions for tests/docs/generated bundles. |
README listing only; drop accidental download SHA header.
ffb358b to
8e02ab0
Compare
|
The latest head now contains only the intended README entry, but the centralized scan is 71/100, below the required 80, with 76 high, 1 medium, and 2 low findings. Please remediate or document the rule-level findings, rerun the source and catalog scans, and request review once the score reaches at least 80; the pinned source scanner workflow is recommended because scanner CI is not detected, but it is not a merge prerequisite. |
kantorcodes
left a comment
There was a problem hiding this comment.
Centralized HOL scan is 71/100, below the 80 merge threshold, with 77 high, 1 medium, and 2 low findings. Fix the hardcoded-secret and eval/Function findings, Claude marketplace structure, and missing Dependabot coverage. The source has no HOL scanner workflow, so add the SHA-pinned workflow from SCANNER_GUIDE.md, run the same pinned scanner in source CI, link that run, then rerun the catalog scan.
Summary
Adds Releases Index (releases.sh) under Community Plugins → Development & Workflow.
Open release-notes registry with MCP and CLI so agents can search and fetch product changelogs.
Related: buildinternet/uploads#989