Skip to content

Security hygiene for the awesome-ai-plugins listing; fix the 7.2.1 version drift - #6

Merged
awrshift merged 2 commits into
mainfrom
chore/scanner-hygiene
Oct 7, 2026
Merged

awrshift merged 2 commits into
mainfrom
chore/scanner-hygiene

Conversation

@awrshift

@awrshift awrshift commented Oct 7, 2026

Copy link
Copy Markdown
Owner
  • SECURITY.md: private reporting channel + what the hooks run locally
  • checks.yml: third-party Actions pinned to commit SHAs (tag kept as a comment)
  • .github/dependabot.yml: monthly github-actions updates, keeps the pins current
  • package.json and the AGENTS.md protocol marker carried 7.2.0 after the 7.2.1 release; tools/check-repo.py flagged it and CI on main has been red since 62b8685

Context: hashgraph-online/awesome-ai-plugins#652 (from #5). Their scanner scored the repo 76/100 against a threshold of 80, no critical or high findings; the gaps were the three hygiene items above.

🤖 Generated with Claude Code

awrshift and others added 2 commits October 7, 2026 23:52
…github-actions

The awesome-ai-plugins listing gate (HOL plugin scanner) scored the repo 76/100 against a
threshold of 80 with no critical or high findings; the gaps were repo hygiene: no SECURITY.md,
third-party Actions referenced by tag, no Dependabot config.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…er carry 7.2.1

The 7.2.1 release bumped VERSION and the manifests but not these two; tools/check-repo.py
caught it and CI on main has been red since 62b8685.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@awrshift
awrshift merged commit 2027283 into main Oct 7, 2026
1 check passed
@awrshift
awrshift deleted the chore/scanner-hygiene branch October 7, 2026 20:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant