ci: clear the HOL plugin scanner findings and add the scanner gate - #37
Merged
Merged
Conversation
The HOL plugin scanner flags `LITELLM_API_KEY = '<value>'` and `apiKey: '<value>'` literals through its generic API-key detector. Test files count as an "example surface" for the scanner, but the exemption only applies to placeholder-marked values, so `test-env-key` / `test-key` were reported as a high-severity hardcoded secret. Use `example-*` values, which the scanner recognises as placeholders. No behaviour change: the fixtures are still asserted end-to-end.
Pin actions/checkout and actions/setup-node to immutable commit SHAs (v4.4.0) so a mutable tag cannot silently change the code CI executes, and add the scanner workflow from the catalog's SCANNER_GUIDE.md (hashgraph-online/ai-plugin-scanner-action v1.2.635, min_score 80, fail_on_severity high). Clears the GITHUB_ACTION_UNPINNED findings and keeps them clear on every PR.
Documents supported versions, the private disclosure channel (GitHub private vulnerability reporting, now enabled on this repository) and what is in scope for this plugin. Clears the scanner's SECURITY_MD_MISSING finding.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (5)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The listing PR hashgraph-online/awesome-ai-plugins#533 is blocked by the catalog's required source scan:
This PR clears those findings, adds the recommended scanner gate to our own CI, and leaves the one remaining finding documented rather than papered over.
Findings and remediation
HARDCODED_SECRETtest-env-key/test-key; the scanner's generic API-key detector matchesapi_key = '<8+ chars>'. Test files are an "example surface" for the scanner, but the exemption only accepts placeholder-marked values, so the fixtures now useexample-litellm-key/example-api-key. No behaviour change — the values are still asserted end-to-end.GITHUB_ACTION_UNPINNEDactions/checkoutandactions/setup-nodepinned tov4.4.0commit SHAs inci.ymlandrelease.yml.SECURITY_MD_MISSINGSECURITY.md, with GitHub private vulnerability reporting (now enabled on the repo) as the disclosure channel.DEPENDABOT_MISSINGrenovate.jsonalready covers GitHub Actions and npm with grouping and automerge; adding.github/dependabot.ymlwould duplicate every update PR. Score is 94 without it, above the 80 bar.Also added
.github/workflows/plugin-scan.yml— the SHA-pinned workflow fromSCANNER_GUIDE.md(plugin_dir: ".",min_score: 80,fail_on_severity: high) — so the scan runs on our own PRs and pushes.Verification
Local run with the catalog's pinned scanner (
plugin-scanner==3.0.123, same version the sweep uses):npm run typecheck— passnpm test— 73/73 passSECRET_PATTERNS+ skip logic: 0 surviving matches (the scanner reports only the first match per file, so this avoided fixing them one at a time).Scope
actions/checkoutandactions/setup-nodestay on the v4 line (pinned, not upgraded) to keep this a reviewable security change rather than a dependency bump. Worth a separate PR to move off the deprecated Node 20 actions.Summary by CodeRabbit