Skip to content

chore: add HOL scanner compliance - #33

Merged
SignalLayerLabs merged 1 commit into
mainfrom
chore/hol-scanner-compliance
Aug 19, 2026
Merged

SignalLayerLabs merged 1 commit into
mainfrom
chore/hol-scanner-compliance

Conversation

@SignalLayerLabs

Copy link
Copy Markdown
Owner

Summary

Adds the repository-level HOL plugin scanner compliance required for submission to hashgraph-online/awesome-ai-plugins.

Changes

  • adds the pinned Plugin Security Scan GitHub Actions workflow;
  • declares the Codex plugin tool_enforcement capability for scanner discovery;
  • replaces scanner-triggering synthetic credential fixture names/literals without changing the tested security behavior;
  • keeps the workflow least-privilege with contents: read and non-persisted checkout credentials.

HOL validation

Local scanner result:

  • score: 85/142
  • critical: 0
  • high: 0
  • plugin-scanner verify: PASS

GitHub Actions:

  • Plugin Security Scan: PASS
  • run: 32225533938

Project validation

  • ruff format --check . — pass
  • ruff check . — pass
  • mypy src/marginal — pass
  • pytest -q — 784 passed
  • python scripts/build_codex_plugin.py --check — pass
  • package build — pass
  • twine check dist/* — pass

The credential-like values changed here are synthetic test/smoke sentinels, not production credentials. Runtime governance behavior is unchanged.

@SignalLayerLabs
SignalLayerLabs merged commit 188b15f into main Aug 19, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants