Skip to content

Validate declared plugin icon assets - #9

Merged
xeonvs merged 1 commit into
mainfrom
codex/allow-validated-plugin-icons-1.0.4
Sep 12, 2026
Merged

xeonvs merged 1 commit into
mainfrom
codex/allow-validated-plugin-icons-1.0.4

Conversation

@xeonvs

@xeonvs xeonvs commented Sep 12, 2026

Copy link
Copy Markdown
Owner

Summary

  • allow only complete, confined composerIcon/logo/logoDark paths declared by each Codex plugin manifest
  • validate exact PNG dimensions, RGB opacity, complete PNG chunks, CRCs, decompressed pixel dimensions, and row filters
  • continue rejecting undeclared binaries and image metadata in Claude manifests
  • preserve catalog provenance and current bundles unchanged

Validation

  • 16/16 tests
  • catalog validation
  • recorded upstream verification
  • plan lifecycle and whitespace checks
  • redacted Gitleaks tree and reachable-history scans

This closes the fail-closed gap found by sync run 34695567427 before retrying the all-plugin import.

@xeonvs
xeonvs merged commit e7ab445 into main Sep 12, 2026
1 check passed
@xeonvs
xeonvs deleted the codex/allow-validated-plugin-icons-1.0.4 branch September 12, 2026 13:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant