Add pinned plugin security scan - #11
Conversation
|
Blocked on native Kimi scanner support; keeping this draft instead of merging a permanently red workflow into Evidence from the pinned action run: scanner 2.0.1116 reports Upstream issue: hashgraph-online/hol-guard#2446 We should not merge until HOL can validate the actual Kimi bundle without a fake Codex manifest, duplicated manifest, lowered severity threshold, or broad suppressions. Once fixed, update to the reviewed immutable action SHA and rerun the same gate. |
|
Validation evidence before merge: the native Kimi scan completed with HOL AI Plugin Scanner 2.2.118 against |
Summary
Verification
bun test tests/release/orchestration-protocol-boundaries.test.ts(9 pass)bun run typecheckbun test(6802 pass, 60 skip, 0 fail)git diff --checkThis is the prerequisite scanner evidence requested by
hashgraph-online/awesome-ai-pluginsbefore submitting the GoodMemory Kimi plugin listing.