Skip to content

ci: clear the HOL plugin scanner findings and add the scanner gate - #37

Merged
yuseferi merged 3 commits into
mainfrom
ci/hol-plugin-scanner-remediation
Sep 30, 2026
Merged

yuseferi merged 3 commits into
mainfrom
ci/hol-plugin-scanner-remediation

Conversation

@yuseferi

@yuseferi yuseferi commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Why

The listing PR hashgraph-online/awesome-ai-plugins#533 is blocked by the catalog's required source scan:

Centralized HOL Plugin Scanner score is 65/100 (1 high, 4 medium, 2 low), below the required 80.

This PR clears those findings, adds the recommended scanner gate to our own CI, and leaves the one remaining finding documented rather than papered over.

Findings and remediation

Sev Rule Fix
high HARDCODED_SECRET Test fixtures used test-env-key / test-key; the scanner's generic API-key detector matches api_key = '<8+ chars>'. Test files are an "example surface" for the scanner, but the exemption only accepts placeholder-marked values, so the fixtures now use example-litellm-key / example-api-key. No behaviour change — the values are still asserted end-to-end.
medium ×4 GITHUB_ACTION_UNPINNED actions/checkout and actions/setup-node pinned to v4.4.0 commit SHAs in ci.yml and release.yml.
low SECURITY_MD_MISSING Added SECURITY.md, with GitHub private vulnerability reporting (now enabled on the repo) as the disclosure channel.
low DEPENDABOT_MISSING Not changed, by design. renovate.json already covers GitHub Actions and npm with grouping and automerge; adding .github/dependabot.yml would duplicate every update PR. Score is 94 without it, above the 80 bar.

Also added .github/workflows/plugin-scan.yml — the SHA-pinned workflow from SCANNER_GUIDE.md (plugin_dir: ".", min_score: 80, fail_on_severity: high) — so the scan runs on our own PRs and pushes.

Verification

Local run with the catalog's pinned scanner (plugin-scanner==3.0.123, same version the sweep uses):

Before:  Final Score: 65/100 (D)  Findings: critical:0, high:1, medium:4, low:2
After:   Final Score: 94/100 (A)  Findings: critical:0, high:0, medium:0, low:1
  • npm run typecheck — pass
  • npm test — 73/73 pass
  • Independently enumerated every file in the repo against the scanner's own SECRET_PATTERNS + skip logic: 0 surviving matches (the scanner reports only the first match per file, so this avoided fixing them one at a time).

Scope

  • No runtime/source changes; the plugin's behaviour is unchanged.
  • actions/checkout and actions/setup-node stay on the v4 line (pinned, not upgraded) to keep this a reviewable security change rather than a dependency bump. Worth a separate PR to move off the deprecated Node 20 actions.

Summary by CodeRabbit

  • Security
    • Added automated plugin scanning for pull requests and pushes, with checks for minimum scores and high-severity findings.
  • Documentation
    • Added security guidance covering supported versions, how to report vulnerabilities privately, what details to include, and response expectations.
    • Clarified which security concerns should be reported and which should be referred upstream.

The HOL plugin scanner flags `LITELLM_API_KEY = '<value>'` and
`apiKey: '<value>'` literals through its generic API-key detector. Test files
count as an "example surface" for the scanner, but the exemption only applies
to placeholder-marked values, so `test-env-key` / `test-key` were reported as
a high-severity hardcoded secret.

Use `example-*` values, which the scanner recognises as placeholders. No
behaviour change: the fixtures are still asserted end-to-end.
Pin actions/checkout and actions/setup-node to immutable commit SHAs (v4.4.0)
so a mutable tag cannot silently change the code CI executes, and add the
scanner workflow from the catalog's SCANNER_GUIDE.md
(hashgraph-online/ai-plugin-scanner-action v1.2.635, min_score 80,
fail_on_severity high).

Clears the GITHUB_ACTION_UNPINNED findings and keeps them clear on every PR.
Documents supported versions, the private disclosure channel (GitHub private
vulnerability reporting, now enabled on this repository) and what is in scope
for this plugin. Clears the scanner's SECURITY_MD_MISSING finding.
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: ff3ca1dc-0f70-4038-9007-68d0d2224a96

📥 Commits

Reviewing files that changed from the base of the PR and between 8939b85 and b57fc6a.

📒 Files selected for processing (5)
  • .github/workflows/ci.yml
  • .github/workflows/plugin-scan.yml
  • .github/workflows/release.yml
  • SECURITY.md
  • test/plugin-v2.test.ts
 _____________________________________________________________________________________________________
< Trained in all forms of code review, from the ancient art of waterfall to the modern ways of agile. >
 -----------------------------------------------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yuseferi
yuseferi merged commit 782d349 into main Sep 30, 2026
5 of 6 checks passed
@yuseferi
yuseferi deleted the ci/hol-plugin-scanner-remediation branch September 30, 2026 07:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant