feat(catalog): gate catalog README labels against ref + close the drift
The catalog README's per-plugin `vX.Y.Z` labels were an UNGUARDED surface: check-versions validated each plugin's OWN README badge, never the catalog README's labels, so they drifted (config-audit shown v5.5.0 while pinned to v5.7.0; voyage v5.1.1 while pinned to v5.6.0) — the doc misstated what `claude plugin install` actually resolves. Close the class, same pattern as the ref surface: - check-versions.mjs: new ERROR rule "catalog README label == catalog ref" via pure extractCatalogLabel() (matches the /open/<name>) heading, takes the first `vX.Y.Z`, ignores a trailing lang/flag badge). No legitimate transient state lets label != ref, so ERROR (not WARN). +5 tests. - release-plugin.mjs: on --write, bump the README label atomically with the ref via pure reconcileReadmeLabel() and git add README.md on --commit, so future releases keep label and ref in lock-step. +4 tests. - README.md: reconcile the 2 stale labels (config-audit -> v5.7.0, voyage -> v5.6.0). Gate now 9 OK / 1 WARN / 0 ERROR. - CLAUDE.md: doctrine updated to document the new gate rule + atomic label bump. ms-ai-architect stays WARN by decision (1.16.0 is unreleased WIP, never tagged). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Cm2RxKbomdLqjiWGcwCCPi
This commit is contained in:
parent
cf2420f7c5
commit
2e1d206ab3
6 changed files with 155 additions and 18 deletions
16
CLAUDE.md
16
CLAUDE.md
|
|
@ -24,12 +24,16 @@ their own Forgejo repositories under `https://git.fromaitochitta.com/open/`.
|
|||
`node scripts/release-plugin.mjs <plugin> [--version X.Y.Z]` — dry-run by default; it REFUSES unless
|
||||
`plugin.json` == README badge == the target version AND the `vX.Y.Z` tag exists, then prints the
|
||||
planned bump. Apply with `--write [--commit] [--push]`; `--create-tag` mints+pushes a missing plugin
|
||||
tag first. Because it only moves the `ref` to a verified, tagged, consistent version,
|
||||
`check-versions.mjs` is green by construction. Never hand-edit a `ref` for a release — use this.
|
||||
Pure planner covered by `scripts/release-plugin.test.mjs`.
|
||||
tag first. On `--write` it bumps the catalog `ref` AND the catalog README's per-plugin `` `vX.Y.Z` ``
|
||||
label together (and `git add`s both on `--commit`). Because it only moves both to a verified, tagged,
|
||||
consistent version, `check-versions.mjs` is green by construction. Never hand-edit a `ref` or a
|
||||
README label for a release — use this. Pure planner + label reconciler covered by
|
||||
`scripts/release-plugin.test.mjs`.
|
||||
- **Version-consistency gate:** run `node scripts/check-versions.mjs` before committing any `ref`
|
||||
change. For each plugin it checks (against the sibling repo) that the catalog `ref` resolves to a
|
||||
real git tag (ERROR if dangling — breaks install), that `plugin.json` version == README
|
||||
version-badge (ERROR), and that the catalog `ref` matches `plugin.json` version (WARN — catalog
|
||||
lags or an unreleased bump). Exit 1 on any ERROR; `--strict` also fails on WARN. Pure-function
|
||||
core covered by `scripts/check-versions.test.mjs` (`node --test scripts/check-versions.test.mjs`).
|
||||
version-badge (ERROR), that the catalog README's per-plugin `` `vX.Y.Z` `` label == the catalog
|
||||
`ref` (ERROR — the human-facing doc must not misstate the installed version), and that the catalog
|
||||
`ref` matches `plugin.json` version (WARN — catalog lags or an unreleased bump). Exit 1 on any
|
||||
ERROR; `--strict` also fails on WARN. Pure-function core covered by
|
||||
`scripts/check-versions.test.mjs` (`node --test scripts/check-versions.test.mjs`).
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue