Enforce plugin version bumps in CI + tag releases on bump (PRDE-1152) - #9
Merged
Merged
Conversation
- CI job fails PRs touching plugins/** unless plugin.json version is bumped past the merge-base (scripts/check-version-bump.sh) - Release workflow tags v<version> + GitHub release on push to master when the version changed - Drop stale marketplace.json metadata.version (was 0.2.0 vs plugin 0.2.2; claude plugin validate passes without it) - Bump plugin to 0.2.3 to satisfy the new check Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Resolves CodeQL alert #1 (actions/missing-workflow-permissions): ci.yml had no explicit permissions block. Both jobs only checkout and run tests/validation, so contents: read suffices. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Contributor
Author
|
f0be635 also resolves the pre-existing CodeQL alert #1 ( |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ticket: PRDE-1152
Claude Code only delivers plugin updates when the
plugin.jsonversionfield bumps — unbumped commits never propagate to installed plugins. This PR makes that discipline mechanical:version-bumpjob inci.yml+scripts/check-version-bump.sh): PRs that change anything underplugins/**fail unlessplugins/composio/.claude-plugin/plugin.json's version differs from (and sorts above) the version at the PR's merge-base with the base branch. PRs not touchingplugins/**are unaffected.release.yml): on push tomaster, if the plugin version changed vs the previous commit, creates tagv<version>+ a GitHub release — a machine-queryable "latest plugin version" signal (for PRDE-1153/1158). Note: releases created withGITHUB_TOKENdon't triggerrelease-event workflows; nothing here depends on that.metadata.version(0.2.0) from.claude-plugin/marketplace.json— it had drifted from plugin.json andclaude plugin validatepasses without it, eliminating the drift class entirely.Auto-update canary: once merged, this bump doubles as the canary for KJ's user-scope
autoUpdate: trueon the composio marketplace entry — the point is to observe whether the installed plugin picks up 0.2.3 without any manual steps.Verification:
pytest tests/unit(49 passed) andclaude plugin validateon both the marketplace manifest and plugin pass locally.plugins/**edit with no bump fails, a docs-only change passes, a version downgrade fails; this branch passes (0.2.2 → 0.2.3).Mirrored in composio-plugin-openai.
🤖 Generated with Claude Code