Refresh TMCRA Local Memory for 1.0.0-rc.1 (source security gate pending) - #398
Refresh TMCRA Local Memory for 1.0.0-rc.1 (source security gate pending)#398reshuibuduo wants to merge 5 commits into
Conversation
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can route each action level your way: inline, summary, both, or drop |
PR Summary by QodoRefresh TMCRA Local Memory catalog description for rc.10
AI Description
High-Level Assessment
Files changed (1)
|
|
Detector fix proposed upstream: hashgraph-online/hol-guard#2805 . It addresses the Python no-argument inference-method false positives, with 186 related tests passing on Python 3.12 and 93 code-quality tests passing on Python 3.10. Upstream Actions await maintainer approval. This submission remains a draft while the source release's official scanner gate is unresolved. The pinned scanner Action, high-severity threshold and Cisco coverage are unchanged; synthetic test-credential findings remain a separate item. A local detector regression pass is not an official marketplace security pass. |
Refresh the existing TMCRA entry for the unified 1.0.0-rc.1 candidate: visual memory workspace, chat-confirmed source corrections, session controls, local Writer/organizer settings, and account-free Windows x64 one-click local installation.
Source update: reshuibuduo/tmcra-plugin-codex#4
Validation
python scripts/check-alphabetical.py README.md --base-ref upstream/mainpasses. Prerequisite Make alphabetical checks baseline-aware #399 is already merged.npm run verifypasses; the 235-entry Codex archive includes the backend and verified runtime inventory.Pending source security gate
The official HOL action is still blocked. Versions 3.0.17, 3.0.65 and current 3.0.94 classify PyTorch
Module.eval()(inference mode) as dynamic code execution in eight bundled Python files. The source preserves the original high-severity gate and enables Cisco scanning; no runtime exclusions or broad suppressions were added. Setup now uses no placeholder API credential and rejects all authenticated memory operations.Review with exact affected paths: https://github.com/reshuibuduo/tmcra-plugin-codex/blob/codex/memory-controls-continuity/docs/security-scanner-review.md
Please keep this refresh pending until the source gate is resolved or the maintainer explicitly adjudicates those findings. Source main/release and bot-generated marketplace bundles should be refreshed only after that point. Local deployment is a preview; higher-tier hardware and complete offline memory acceptance remain pending.