From 810323316938395c825cde62dd3e68003da9a48b Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Wed, 19 Aug 2026 13:14:51 +0000 Subject: [PATCH] docs: cite HOL Plugin Security Hugging Face dataset Link the first-party HashgraphOnline/hol-plugin-security dataset from the README and add it as a related CFF identifier so GitHub citation metadata can emit the URL. Runtime fixtures remain modeled software evidence, not live attacks or third-party validation. Co-authored-by: Michael Kantor --- CITATION.cff | 4 ++++ README.md | 4 ++++ 2 files changed, 8 insertions(+) diff --git a/CITATION.cff b/CITATION.cff index 5b850fb..d55b82c 100644 --- a/CITATION.cff +++ b/CITATION.cff @@ -7,3 +7,7 @@ authors: url: "https://github.com/hashgraph-online/hol-guard-benchmark" repository-code: "https://github.com/hashgraph-online/hol-guard-benchmark" license: "Apache-2.0" +identifiers: + - type: url + value: "https://huggingface.co/datasets/HashgraphOnline/hol-plugin-security" + description: "Related Hugging Face dataset (HOL Plugin Security). Runtime fixtures in that dataset are modeled, not live attacks." diff --git a/README.md b/README.md index fc0b738..8ea6011 100644 --- a/README.md +++ b/README.md @@ -54,6 +54,10 @@ bun run typecheck The current release demonstrates that a documented fixture matrix can be normalized and published reproducibly. It does not demonstrate live harness behavior, exploit resistance, real-world false-positive rates, network/container/OS isolation, or independent review. Future live adapters must publish their harness versions, setup steps, raw observations, environment, data-egress statement, and a separate run identifier rather than silently replacing fixture output. +## Dataset + +Runtime fixtures in the [HOL Plugin Security dataset on Hugging Face](https://huggingface.co/datasets/HashgraphOnline/hol-plugin-security) are modeled, not live attacks; a scan is not a safety guarantee, and HOL publishes this rather than independent third-party validation. + ## Contributing and security Read [CONTRIBUTING.md](./CONTRIBUTING.md) before changing scenarios or result semantics. Report security issues privately using [SECURITY.md](./SECURITY.md); do not open a public issue for a vulnerability.