Repository navigation
Security hygiene for the awesome-ai-plugins listing; fix the 7.2.1 version drift - #6
Merged
Merged
Conversation
…github-actions The awesome-ai-plugins listing gate (HOL plugin scanner) scored the repo 76/100 against a threshold of 80 with no critical or high findings; the gaps were repo hygiene: no SECURITY.md, third-party Actions referenced by tag, no Dependabot config. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…er carry 7.2.1 The 7.2.1 release bumped VERSION and the manifests but not these two; tools/check-repo.py caught it and CI on main has been red since 62b8685. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
SECURITY.md: private reporting channel + what the hooks run locallychecks.yml: third-party Actions pinned to commit SHAs (tag kept as a comment).github/dependabot.yml: monthly github-actions updates, keeps the pins currentpackage.jsonand the AGENTS.md protocol marker carried 7.2.0 after the 7.2.1 release;tools/check-repo.pyflagged it and CI on main has been red since 62b8685Context: hashgraph-online/awesome-ai-plugins#652 (from #5). Their scanner scored the repo 76/100 against a threshold of 80, no critical or high findings; the gaps were the three hygiene items above.
🤖 Generated with Claude Code