Skip to content

Add pinned plugin security scan - #11

Draft
hjqcan wants to merge 2 commits into
mainfrom
codex/awesome-ai-plugins-listing
Draft

Add pinned plugin security scan#11
hjqcan wants to merge 2 commits into
mainfrom
codex/awesome-ai-plugins-listing

Conversation

@hjqcan

@hjqcan hjqcan commented Aug 17, 2026

Copy link
Copy Markdown
Owner

Summary

  • add the HOL plugin scanner as a read-only GitHub-hosted check
  • pin checkout and scanner actions to immutable commits
  • keep online probing, submissions, SARIF uploads, and repository secrets disabled
  • add a release contract test for the workflow security boundary

Verification

  • bun test tests/release/orchestration-protocol-boundaries.test.ts (9 pass)
  • bun run typecheck
  • bun test (6802 pass, 60 skip, 0 fail)
  • git diff --check

This is the prerequisite scanner evidence requested by hashgraph-online/awesome-ai-plugins before submitting the GoodMemory Kimi plugin listing.

@hjqcan

hjqcan commented Aug 17, 2026

Copy link
Copy Markdown
Owner Author

Blocked on native Kimi scanner support; keeping this draft instead of merging a permanently red workflow into main.

Evidence from the pinned action run: scanner 2.0.1116 reports ecosystems: ["codex"], requires .codex-plugin/plugin.json despite the repository shipping kimi.plugin.json, and produces 138 high findings by scanning the application/research tree. Reproduction: https://github.com/hjqcan/GoodMemory/actions/runs/31986119511

Upstream issue: hashgraph-online/hol-guard#2446
Listing PR: hashgraph-online/awesome-ai-plugins#95

We should not merge until HOL can validate the actual Kimi bundle without a fake Codex manifest, duplicated manifest, lowered severity threshold, or broad suppressions. Once fixed, update to the reviewed immutable action SHA and rerun the same gate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant