Skip to content

build(deps): bump hashgraph-online/ai-plugin-scanner-action from 1.2.532 to 1.2.715 - #22

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/hashgraph-online/ai-plugin-scanner-action-1.2.715
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/hashgraph-online/ai-plugin-scanner-action-1.2.715

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown

Bumps hashgraph-online/ai-plugin-scanner-action from 1.2.532 to 1.2.715.

Release notes

Sourced from hashgraph-online/ai-plugin-scanner-action's releases.

v1.2.715

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/0ef32aa0ffd80027f88679a8c542c0f569ecea8f with plugin-scanner 3.7.4.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.714...v1.2.715

v1.2.714

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/e4b6449781f1a26c676a5fb8f3248c8db2a336ea with plugin-scanner 3.7.3.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.713...v1.2.714

v1.2.713

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/505c62e1e0fd506ff4d040d8cba2dd2ca1fb25f4 with plugin-scanner 3.7.2.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.712...v1.2.713

v1.2.712

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/00b6dbb2abe5b6936ff403d7e5d0a39bea6448ef with plugin-scanner 3.7.1.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.711...v1.2.712

v1.2.711

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/7851c8d8525a6672ffb3ba0429324ca75fe8b944 with plugin-scanner 3.7.0.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.710...v1.2.711

v1.2.710

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/a5392792063cb3e061e0a8dfb2a122fee7d13f05 with plugin-scanner 3.6.4.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.709...v1.2.710

v1.2.709

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/e5350eb2427d7948b0ec54d2cfbf790c62507cbc with plugin-scanner 3.6.3.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.708...v1.2.709

v1.2.708

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/277707b3a44d7237b1470b5d88c5460ace5def3e with plugin-scanner 3.6.2.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.707...v1.2.708

v1.2.707

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/3292474fa2373da9a17471360fcd890dc099f237 with plugin-scanner 3.6.1.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.706...v1.2.707

v1.2.706

Published automatically from https://github.com/hashgraph-online/hol-guard/tree/ad3621183d5b33079d858450d476e135bbb87d08 with plugin-scanner 3.6.0.

Full Changelog: hashgraph-online/ai-plugin-scanner-action@v1.2.705...v1.2.706

... (truncated)

Commits
  • 20e0837 chore: publish action bundle v1.2.715 (plugin-scanner 3.7.4)
  • 0cf2e9c chore: publish action bundle v1.2.714 (plugin-scanner 3.7.3)
  • 987a3c1 chore: publish action bundle v1.2.713 (plugin-scanner 3.7.2)
  • 9595abb chore: publish action bundle v1.2.712 (plugin-scanner 3.7.1)
  • 255627a chore: publish action bundle v1.2.711 (plugin-scanner 3.7.0)
  • 0ab65eb chore: publish action bundle v1.2.710 (plugin-scanner 3.6.4)
  • e0f4fdf chore: publish action bundle v1.2.709 (plugin-scanner 3.6.3)
  • 61cb9aa chore: publish action bundle v1.2.708 (plugin-scanner 3.6.2)
  • 9d2fff4 chore: publish action bundle v1.2.707 (plugin-scanner 3.6.1)
  • ff72bdc chore: publish action bundle v1.2.706 (plugin-scanner 3.6.0)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

High-level PR Summary

This PR updates the hashgraph-online/ai-plugin-scanner-action GitHub Action from version 1.2.532 to 1.2.715, a dependency bump that includes multiple intermediate releases with plugin-scanner updates ranging from version 3.6.0 to 3.7.4. The change modifies the action reference in the workflow file to use the newer commit hash.

⏱️ Estimated Review Time: 5-15 minutes

💡 Review Order Suggestion
Order File Path
1 .github/workflows/hol-plugin-scanner.yml

Need help? Join our Discord

Bumps [hashgraph-online/ai-plugin-scanner-action](https://github.com/hashgraph-online/ai-plugin-scanner-action) from 1.2.532 to 1.2.715.
- [Release notes](https://github.com/hashgraph-online/ai-plugin-scanner-action/releases)
- [Commits](hashgraph-online/ai-plugin-scanner-action@5d17bb2...20e0837)

---
updated-dependencies:
- dependency-name: hashgraph-online/ai-plugin-scanner-action
  dependency-version: 1.2.715
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 30, 2026
@ecc-tools

ecc-tools Bot commented Sep 30, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: 4ffca4bd225dffc4e569edc8f6c120756150db48

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 1 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 30, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: 4ffca4bd225dffc4e569edc8f6c120756150db48

PR taxonomy review recommended (neutral)

Detected 2 PR taxonomy bucket(s): Security Evidence, CI/CD Recommendation.

Scanned 1 changed file(s).

Roadmap taxonomy buckets:

Security Evidence

Security-sensitive changes should carry explicit scanner, code-scanning, or focused regression evidence.

Signals:

  • 1 security-sensitive path(s) changed

Paths:

  • .github/workflows/hol-plugin-scanner.yml

CI/CD Recommendation

CI, dependency, coverage, and contract signals should be routed into follow-up checks or verification work.

Signals:

  • CI workflow changes may ship without failure-mode evidence
  • Dependency or CI drift could surface after merge
  • 1 CI or workflow path(s) changed

Paths:

  • .github/workflows/hol-plugin-scanner.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 30, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: 4ffca4bd225dffc4e569edc8f6c120756150db48

Reference set readiness gaps detected (neutral)

Reference evidence present for 1/7 areas (14%) across 1 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Present .github/workflows/hol-plugin-scanner.yml
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 3428c469-724d-4771-a3c1-d15ef80cd03e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ecc-tools

ecc-tools Bot commented Sep 30, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: 4ffca4bd225dffc4e569edc8f6c120756150db48

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 1 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 30, 2026

Copy link
Copy Markdown

ECC Tools / PR Config Audit

Commit: 4ffca4bd225dffc4e569edc8f6c120756150db48

No changed-config issues detected (success)

Scanned 1 config file(s) present at this commit across 1 changed config path(s) and found no issues in the supported security rules.

Changed config files:

  • .github/workflows/hol-plugin-scanner.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 30, 2026

Copy link
Copy Markdown

ECC Tools / PR Harness Audit

Commit: 4ffca4bd225dffc4e569edc8f6c120756150db48

No harness issues detected (success)

Scanned 1 changed config file(s) and found no harness issues.

Changed config files:

  • .github/workflows/hol-plugin-scanner.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Author

Superseded by #23.

@dependabot dependabot Bot closed this Oct 7, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/hashgraph-online/ai-plugin-scanner-action-1.2.715 branch October 7, 2026 09:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants