Conversation
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
@acturner, the required source scan must pass before merge. The centralized source scan returned: failure. A passing scan (score at least 80 with no critical or high findings) is required before merge. Review the rule-level findings and rerun the scan. Scanner CI in the source repository is optional. The centralized scan must pass; review its findings and rerun the contribution check. Push the correction and this comment will update on the next check. Contribution requirements. Latest sweep. |
|
The centralized scan is 67/100, below the required 80, with 2 high, 34 medium, 6 low, and 14 informational findings. Please remediate or document the rule-level findings, rerun the source and catalog scans, and request review once the score reaches at least 80; the pinned source scanner workflow is recommended because scanner CI is not detected, but it is not a merge prerequisite. |
kantorcodes
left a comment
There was a problem hiding this comment.
Centralized scan is 67/100, below the 80 threshold. It flags missing SECURITY.md, unpinned Actions, missing Dependabot/lockfile coverage, and metadata/interface gaps. Fix those in plasma-ai/fractal, add the SHA-pinned HOL scanner workflow from the current SCANNER_GUIDE.md, run the same pinned scanner and link that source run, then rerun the centralized scan.
Centralized scanning and source-repository scanner CI are advisory under the current repository policy, so this review no longer represents merge requirements.
zerocodefast
left a comment
There was a problem hiding this comment.
The updated head still scores 67/100, below the required 80-point threshold, with missing SECURITY.md, unpinned Actions, missing Dependabot and lockfile coverage, and metadata or interface gaps. Please address or document those rule-level findings and rerun the catalog scan; because plasma-ai/fractal has no source scanner CI, adding the SHA-pinned HOL Plugin Scanner workflow from SCANNER_GUIDE.md, an ecosystem-appropriate local reproduction using the same pinned scanner, a linked source run, and a follow-up scan and review is recommended. Source scanner CI is optional, but the centralized score must reach 80+ before approval.
Extension
Fractal — https://github.com/plasma-ai/fractal
Hierarchical agent loops with recursive self-organization. A fractal node runs an agent (Claude Code, Codex, and other backends) in an iteration loop inside its own git worktree and branch; nodes spawn child nodes for subtasks, merge their work back with scope enforcement and a shared project wiki, and record runs, steps, events, and cost in a central database with budget caps. The repository ships
.codex-plugin/plugin.jsonand.claude-plugin/plugin.json, and the skill guides an agent through setting up and operating a node tree.Section
Community Plugins → Development & Workflow (alphabetical, between FlexViz and Frappe Agent).
Verification
plasma-fractalwith thefractalpointer distribution (current release 1.3.0, taggedv1.3.0); each release is built and checked by tag-gated GitHub Actions (tests, lint, docs, build withtwine check) before publishing.plasma-ai/plugins).python3 scripts/check-alphabetical.py README.mdshows no new out-of-order pair from this entry (the Development & Workflow section already reports pre-existing order failures onmainunrelated to this change).