ci(kyberforge): add apm-native marketplace/audit/pack drift gates
Validated the plugin-content-mirror fix (issue #90) against apm's own packing/CI documentation and source: no apm-native mechanism replaces the mirror script (apm's bundler treats .apm/ and root convention dirs as mutually exclusive, by design), but the investigation surfaced a real, separate gap -- this repo ran zero apm-native audit/check commands in CI, relying entirely on custom scripts and Claude Code's own client-side validator. Add three pre-push hooks matching apm's documented producer CI pattern: - apm marketplace check: validates every marketplace.packages[] entry resolves, including live network reachability for remote refs -- a blind spot check-manifests.sh explicitly skips (local sources only). - apm audit --ci: apm's own lockfile/policy/hidden-content integrity gate. - apm pack --check-versions --check-clean: closes issue #90's deferred item 3 (a check-clean-equivalent gate) using apm's native flag instead of bespoke drift logic, verifying .claude-plugin/marketplace.json still matches what apm.yml + .apm/ would currently generate. All three are network-tolerant and whole-repo in scope, so they belong at pre-push alongside check-manifests/check-plugin-content-sync/ validate-plugins -- not pre-commit, which stays fast/offline/per-file. Documented the packing/bundling/releasing/CI findings in docs/research/docs/microsoft-apm/releasing.md (new) and extended testing-and-validation.md with the apm-action wrapper and its documented CI patterns, sourced from Context7 and cross-checked against the installed apm-cli 0.28.0 package directly. Refs: #90
This commit is contained in:
@@ -70,6 +70,33 @@ repos:
|
||||
pass_filenames: false
|
||||
always_run: true
|
||||
|
||||
- id: apm-marketplace-check
|
||||
name: apm marketplace check
|
||||
description: Validate every marketplace.packages[] entry resolves, including network reachability of remote refs -- catches stale/unreachable remote package references that check-manifests.sh deliberately skips (local-source checks only)
|
||||
entry: apm marketplace check
|
||||
language: system
|
||||
stages: [pre-push]
|
||||
pass_filenames: false
|
||||
always_run: true
|
||||
|
||||
- id: apm-audit-ci
|
||||
name: apm audit --ci
|
||||
description: apm's own producer-side lockfile/policy/hidden-content integrity gate, per apm's documented recommended CI block (see docs/research/docs/microsoft-apm/testing-and-validation.md)
|
||||
entry: apm audit --ci
|
||||
language: system
|
||||
stages: [pre-push]
|
||||
pass_filenames: false
|
||||
always_run: true
|
||||
|
||||
- id: apm-pack-check-clean
|
||||
name: apm pack --check-clean
|
||||
description: Release gate -- verify .claude-plugin/marketplace.json still matches what apm.yml + .apm/ would currently generate, and that per-package versions agree with the per_package versioning strategy. Closes issue #90's deferred item 3 (a check-clean-equivalent gate) using apm's own flag instead of custom drift logic.
|
||||
entry: apm pack --check-versions --check-clean --dry-run
|
||||
language: system
|
||||
stages: [pre-push]
|
||||
pass_filenames: false
|
||||
always_run: true
|
||||
|
||||
- id: check-vale-style-sync
|
||||
name: Check Vale style copies are in sync
|
||||
description: Diff skill-audit's Vale copy against agent-audit's canonical copy
|
||||
|
||||
Reference in New Issue
Block a user