Skip to content

chore: address plugin scanner lint findings - #12

Merged
sf-jin-ku merged 2 commits into
mainfrom
jin/scanner-lint-cleanup
Apr 6, 2026
Merged

sf-jin-ku merged 2 commits into
mainfrom
jin/scanner-lint-cleanup

Conversation

@sf-jin-ku

Copy link
Copy Markdown
Contributor

Summary

Address the remaining codex-plugin-scanner lint findings so the plugin package is cleaner for marketplace/release distribution.

Changes

  • pin GitHub Actions to immutable SHAs
  • add SECURITY.md
  • add weekly Dependabot config for npm and GitHub Actions
  • add .codexignore for local-only files

Verification

  • pipx run codex-plugin-scanner lint .
  • pipx run codex-plugin-scanner verify .
  • workflow YAML parse via Ruby YAML.load_file

@sf-jin-ku
sf-jin-ku merged commit add3cdb into main Apr 6, 2026
3 checks passed
@sf-jin-ku
sf-jin-ku deleted the jin/scanner-lint-cleanup branch April 6, 2026 01:18

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4f9217c38d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread package.json
"uninstall:codex": "node scripts/installer-cli.mjs uninstall",
"update:codex": "node scripts/installer-cli.mjs update"
"update:codex": "node scripts/installer-cli.mjs update",
"version": "npm run sync:plugin-version && npm run check:version-sync"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Stage synced plugin.json during npm version

The new version lifecycle script syncs .codex-plugin/plugin.json but never stages that change, so npm version will create a tag/commit without the synced plugin file. npm’s own npm-version command docs state that files generated in version scripts must be explicitly added (e.g., via git add) before the commit step, and without that this leaves a dirty working tree and can publish or push a commit where package.json and plugin metadata diverge.

Useful? React with 👍 / 👎.


describe("version sync", () => {
it("asserts the live repo versions match", () => {
assert.equal(assertVersionsMatch(), "1.0.0");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Remove hardcoded release version from version-sync test

This assertion hardcodes the repository version to 1.0.0, which makes normal version bumps fail test runs even when package.json and .codex-plugin/plugin.json are correctly synchronized. That introduces avoidable CI/release friction because every future release now requires manually editing this test instead of validating version equality dynamically.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant