Skip to content

Add NotFair plugin - #336

Open
ununununium wants to merge 1 commit into
hashgraph-online:mainfrom
ununununium:add-notfair-plugin
Open

ununununium wants to merge 1 commit into
hashgraph-online:mainfrom
ununununium:add-notfair-plugin

Conversation

@ununununium

Copy link
Copy Markdown

Summary

Adds NotFair to Community Plugins (alphabetical, after NeatContext).

Invited in nowork-studio/notfair-plugin#115 — NotFair maintainers approved the listing.

Category

Community Plugins

Verification

Listing approved by NotFair maintainers in response to
nowork-studio/notfair-plugin#115.
@github-actions

github-actions Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

Contribution check passed. @ununununium, catalog validation succeeded.

scan findings

HOL centralized scan reported findings or did not pass: failure. This is advisory and does not block listing.

Recommended: add scanner CI for security

This listing can merge without it. HOL still scans nowork-studio/notfair-plugin independently.

We recommend including hashgraph-online/ai-plugin-scanner-action under .github/workflows/ on push and pull_request. Continuous scanning keeps this catalog safer for MCP servers, skills, plugins, and other agent extensions people install from HOL.

Adding it:

  • protects the ecosystem by catching secrets, dangerous hooks, and supply-chain issues before they ship;
  • keeps the listing at the full trust score (without maintainer CI it stays eligible, with a 10% trust-score reduction);
  • can surface findings in GitHub code scanning.

See CONTRIBUTING.md and SCANNER_GUIDE.md.

HOL's centralized scan reported findings. This does not block listing.

View the latest sweep.

@kantorcodes kantorcodes left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The centralized scan is 65/100, below the 80 merge threshold, with 24 high findings. Fix the high findings first, including the hardcoded-secret and shell-injection detections and unpinned Actions, then add the SHA-pinned HOL scanner workflow from the current guide, link the source run, and rerun the catalog scan.

@kantorcodes

Copy link
Copy Markdown
Member

The centralized scan is 65/100, below the required 80, with 24 high, 21 medium, 6 low, and 4 informational findings. Please remediate or document the rule-level findings, rerun the source and catalog scans, and request review once the score reaches at least 80; the pinned source scanner workflow is recommended because scanner CI is not detected, but it is not a merge prerequisite.

@kantorcodes
kantorcodes dismissed their stale review September 18, 2026 04:10

Centralized scan did not run on this head; prior score attribution was stale.

@kantorcodes kantorcodes left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Centralized scan is 65/100, below the 80 threshold. It flags hardcoded-secret and shell-injection findings, missing SECURITY.md, unpinned Actions, and missing Dependabot/lockfile coverage. Fix those in nowork-studio/notfair-plugin, add the SHA-pinned HOL scanner workflow from the current SCANNER_GUIDE.md, run the same pinned scanner and link that source run, then rerun the centralized scan.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants