Skip to content

Fix catalog scan false positive and pin GitHub Actions - #41

Merged
917Dhj merged 1 commit into
mainfrom
fix/catalog-scan-findings
Sep 27, 2026
Merged

917Dhj merged 1 commit into
mainfrom
fix/catalog-scan-findings

Conversation

@917Dhj

@917Dhj 917Dhj commented Sep 27, 2026

Copy link
Copy Markdown
Owner

The catalog source scan for hashgraph-online/awesome-ai-plugins#488 flagged the shell-config test fixture as a hardcoded secret and deducted points for mutable GitHub Actions references.

Use an explicit redacted dummy value while preserving the shell-config fallback assertions, and pin the three Actions references to the commits currently targeted by checkout v5 and setup-python v6. No runtime behavior or scanner exclusions change.

Validation:

  • Full test suite: 923 passed, 1 skipped.
  • Workflow YAML parses; git diff --check passes.
  • plugin-scanner 3.0.123, default profile, on a clean source snapshot: score increases from 70 to 85, critical/high findings both zero, exits successfully with --min-score 80 --fail-on-severity high.
  • Existing medium/low/info findings remain outside this scoped change.

@917Dhj
917Dhj merged commit 2cdc437 into main Sep 27, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant