Skip to content

ci: add plugin manifest linting#7

Closed
internet-dot wants to merge 2 commits intotalkstream:mainfrom
internet-dot:ci/codex-plugin-scanner
Closed

ci: add plugin manifest linting#7
internet-dot wants to merge 2 commits intotalkstream:mainfrom
internet-dot:ci/codex-plugin-scanner

Conversation

@internet-dot
Copy link
Copy Markdown

@internet-dot internet-dot commented Apr 3, 2026

Follow-up from the awesome-codex-plugins listing for ru-text. Automates manifest checks on every push.

Action source: hashgraph-online/hol-codex-plugin-scanner-action

@internet-dot internet-dot reopened this Apr 3, 2026
@internet-dot internet-dot changed the title ci: add codex-plugin-scanner quality gate ci: add plugin manifest linting Apr 3, 2026
@internet-dot internet-dot reopened this Apr 3, 2026
@internet-dot internet-dot force-pushed the ci/codex-plugin-scanner branch from d7e15ab to e558bee Compare April 5, 2026 19:39
@talkstream
Copy link
Copy Markdown
Owner

Thank you for the contribution, but closing this PR.

Reasons:

  1. Supply chain risk. The action at the pinned SHA runs pip install codex-plugin-scanner without version pinning — actual executable code is pulled from PyPI at runtime, defeating the SHA-pinning security.

  2. Not needed. ru-text already uses claude plugins validate for manifest validation, which covers our needs without introducing third-party CI dependencies.

  3. Mass-automated PR. This account has submitted 300+ near-identical PRs across GitHub. We prefer intentional, project-specific contributions.

If you'd like to contribute to ru-text in a meaningful way, issues and discussions are welcome.

@talkstream talkstream closed this Apr 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants