v1.0.10
v1.0.10
Security and supply-chain hardening release.
- New: HOL Plugin Scanner runs in CI on every push and PR (
.github/workflows/hol-plugin-scanner.yml), SHA-pinned actions,min_score: 80, fails on high severity - New:
SECURITY.mdvulnerability disclosure policy - New: plugin icon (
assets/icon.svg) wired viainterface.composerIconin the Codex manifest - New:
requirements-lock.txtpinned dependency lockfile,.codexignore, Dependabot config - Sync script now mirrors README, SECURITY.md, assets, and the lockfile into the Codex marketplace package
- Scanner result: 88/100 (B), 0 critical, 0 high findings