Skip to content

Enforce plugin version bumps in CI + tag releases on bump (PRDE-1152) - #9

Merged
Kshitij Jhunjhunwala (KJ-11) merged 2 commits into
masterfrom
kj/release-discipline
Jul 28, 2026
Merged

Kshitij Jhunjhunwala (KJ-11) merged 2 commits into
masterfrom
kj/release-discipline

Conversation

@KJ-11

Copy link
Copy Markdown
Contributor

Ticket: PRDE-1152

Claude Code only delivers plugin updates when the plugin.json version field bumps — unbumped commits never propagate to installed plugins. This PR makes that discipline mechanical:

  • CI bump check (version-bump job in ci.yml + scripts/check-version-bump.sh): PRs that change anything under plugins/** fail unless plugins/composio/.claude-plugin/plugin.json's version differs from (and sorts above) the version at the PR's merge-base with the base branch. PRs not touching plugins/** are unaffected.
  • Release automation (release.yml): on push to master, if the plugin version changed vs the previous commit, creates tag v<version> + a GitHub release — a machine-queryable "latest plugin version" signal (for PRDE-1153/1158). Note: releases created with GITHUB_TOKEN don't trigger release-event workflows; nothing here depends on that.
  • Manifest consistency: dropped the stale metadata.version (0.2.0) from .claude-plugin/marketplace.json — it had drifted from plugin.json and claude plugin validate passes without it, eliminating the drift class entirely.
  • Bumps the plugin 0.2.2 → 0.2.3 to satisfy its own check.

Auto-update canary: once merged, this bump doubles as the canary for KJ's user-scope autoUpdate: true on the composio marketplace entry — the point is to observe whether the installed plugin picks up 0.2.3 without any manual steps.

Verification:

  • pytest tests/unit (49 passed) and claude plugin validate on both the marketplace manifest and plugin pass locally.
  • Bump-check exercised against synthetic histories: a plugins/** edit with no bump fails, a docs-only change passes, a version downgrade fails; this branch passes (0.2.2 → 0.2.3).

Mirrored in composio-plugin-openai.

🤖 Generated with Claude Code

- CI job fails PRs touching plugins/** unless plugin.json version is
  bumped past the merge-base (scripts/check-version-bump.sh)
- Release workflow tags v<version> + GitHub release on push to master
  when the version changed
- Drop stale marketplace.json metadata.version (was 0.2.0 vs plugin
  0.2.2; claude plugin validate passes without it)
- Bump plugin to 0.2.3 to satisfy the new check

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Resolves CodeQL alert #1 (actions/missing-workflow-permissions): ci.yml
had no explicit permissions block. Both jobs only checkout and run
tests/validation, so contents: read suffices.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@KJ-11

Copy link
Copy Markdown
Contributor Author

f0be635 also resolves the pre-existing CodeQL alert #1 (actions/missing-workflow-permissions on .github/workflows/ci.yml) by adding a least-privilege top-level permissions: contents: read block — both CI jobs only checkout and run tests/validation, nothing needs write. The alert is on master's ref, so it will only auto-close once this PR merges.

@KJ-11
Kshitij Jhunjhunwala (KJ-11) merged commit 4a7766a into master Jul 28, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant