Skip to content

Harden plugin packaging for HOL scanner listing - #5

Merged
xypkent merged 1 commit into
mainfrom
harden-plugin-scanner
Sep 18, 2026
Merged

xypkent merged 1 commit into
mainfrom
harden-plugin-scanner

Conversation

@xypkent

@xypkent xypkent commented Sep 18, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Add MIT LICENSE, SECURITY.md, Dependabot, a SHA-pinned HOL plugin scanner workflow, and .codexignore
  • Pin GitHub Actions in docs.yml to immutable SHAs
  • Point Codex interface assets at in-repo logo/screenshots so declared links/assets validate

This is to address the review on hashgraph-online/awesome-ai-plugins#345. Local plugin-scanner (v3.0.123) now reports 100/100.

Test plan

  • plugin-scanner scan . → 100/100, 0 findings
  • GitHub Actions Plugin Security Scan is green on this PR
  • After merge, ask awesome-ai-plugins to rerun the centralized scan

Made with Cursor

Add MIT LICENSE, SECURITY.md, Dependabot, SHA-pinned Actions, and in-repo Codex interface assets so the plugin scan can clear the 80/100 listing threshold.

Co-authored-by: Cursor <cursoragent@cursor.com>
@xypkent
xypkent merged commit 7ea425b into main Sep 18, 2026
4 checks passed
@xypkent
xypkent deleted the harden-plugin-scanner branch September 18, 2026 10:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant