build(apm): pin the obsidian MCP server and release bin 1.1.3

plugins/bin/.mcp.json declared the obsidian server as
`npx @bitbonsai/mcpvault@latest`, so an unpinned third-party npm package
was fetched and executed at every session start. The apm-consumed install
promoted that string to committed repo-root content in .mcp.json, giving
every clone the same unpinned execution. Pinned to 0.15.0, the version
`latest` currently resolves to.

bin 1.1.2 -> 1.1.3 and marketplace 0.4.0 -> 0.4.1, following the mapping
bb9158d establishes and 3bfdf58 confirms: the marketplace takes the same
bump severity as the highest-severity package bump. kyberforge is not
bumped here, so executables.allow's `kyberforge#1.5.0` key is untouched.

The pin is not live for this working copy until this lands on the remote
and `apm update` re-resolves — apm.lock.yaml still records 1.1.2 and
`@latest`, because the six dependencies resolve from the remote rather
than from the tree beside them. Correct for a fresh clone immediately.

.gitignore gains /.claude-plugin/plugin.json: a bare `apm pack` emits a
root-package manifest there that has never been tracked on any branch.
Scoped to the file, since the sibling marketplace.json is compiled output
that is committed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X7GvKuJfy2WrdBmUttV4DT
This commit is contained in:
2026-08-14 18:31:16 +00:00
parent 099cf5846c
commit b4f5881973
10 changed files with 22 additions and 14 deletions

View File

@@ -1,7 +1,7 @@
{
"name": "holocron",
"description": "AI development skills for Claude Code and GitHub Copilot CLI — factory, design, implement, review, and cross-cutting workflows.",
"version": "0.4.0",
"version": "0.4.1",
"owner": {
"name": "Defame1297",
"email": "defame1297@rkdr.net",
@@ -18,7 +18,7 @@
{
"name": "bin",
"description": "A place for things to be binned",
"version": "1.1.2",
"version": "1.1.3",
"category": "Utilities",
"source": "./plugins/bin"
},

View File

@@ -1,7 +1,7 @@
{
"name": "holocron",
"description": "AI development skills for Claude Code and GitHub Copilot CLI — factory, design, implement, review, and cross-cutting workflows.",
"version": "0.4.0",
"version": "0.4.1",
"owner": {
"name": "Defame1297",
"email": "defame1297@rkdr.net",
@@ -18,7 +18,7 @@
{
"name": "bin",
"description": "A place for things to be binned",
"version": "1.1.2",
"version": "1.1.3",
"category": "Utilities",
"source": "./plugins/bin"
},

8
.gitignore vendored
View File

@@ -44,3 +44,11 @@ apm_modules/
# `apm pack` bundle output. The pre-push gate runs pack with --dry-run, so this
# only appears after a bare `apm pack` during a release; it is not repo content.
build/
# `apm pack`'s manifest for the *root* package. Emitted beside the marketplace
# manifest by a bare `apm pack`, and never tracked on any branch — the repo's
# own paths hide it, since sync-plugin-content.sh redirects `apm pack -o` to a
# scratch tree and the apm-pack-check-clean pre-push hook runs --dry-run. Scoped
# to the file, not the directory: the sibling .claude-plugin/marketplace.json is
# compiled output that IS committed and must stay tracked.
/.claude-plugin/plugin.json

View File

@@ -2,7 +2,7 @@
"mcpServers": {
"obsidian": {
"args": [
"@bitbonsai/mcpvault@latest",
"@bitbonsai/mcpvault@0.15.0",
"docs/"
],
"command": "npx",

View File

@@ -1,5 +1,5 @@
name: holocron
version: 0.4.0
version: 0.4.1
description: AI development skills for Claude Code and GitHub Copilot CLI — factory, design, implement, review, and cross-cutting workflows.
license: MIT
@@ -52,7 +52,7 @@ marketplace:
# top-level apm.yml description:/version: above are NOT inherited into the
# compiled output despite being used elsewhere (e.g. by `apm audit`).
description: AI development skills for Claude Code and GitHub Copilot CLI — factory, design, implement, review, and cross-cutting workflows.
version: 0.4.0
version: 0.4.1
owner:
name: Defame1297
email: defame1297@rkdr.net
@@ -85,7 +85,7 @@ marketplace:
- name: bin
description: A place for things to be binned
source: ./plugins/bin
version: 1.1.2
version: 1.1.3
category: Utilities
- name: git

View File

@@ -1,6 +1,6 @@
{
"name": "bin",
"version": "1.1.2",
"version": "1.1.3",
"description": "A place for things to be binned",
"author": {
"name": "Defame1297",
@@ -20,7 +20,7 @@
"mcpServers": {
"obsidian": {
"args": [
"@bitbonsai/mcpvault@latest",
"@bitbonsai/mcpvault@0.15.0",
"docs/"
],
"command": "npx",

View File

@@ -1,6 +1,6 @@
{
"name": "bin",
"version": "1.1.2",
"version": "1.1.3",
"description": "A place for things to be binned",
"author": {
"name": "Defame1297",

View File

@@ -2,7 +2,7 @@
"mcpServers": {
"obsidian": {
"args": [
"@bitbonsai/mcpvault@latest",
"@bitbonsai/mcpvault@0.15.0",
"docs/"
],
"command": "npx",

View File

@@ -33,7 +33,7 @@ copilot plugin install ./plugins/bin
| Component | Path | Description |
|---|---|---|
| Skills | `.apm/skills/` → `skills/` | Slash commands available after install |
| MCP servers | `.mcp.json` | The `obsidian` server (`npx @bitbonsai/mcpvault@latest docs/`), hand-authored at the plugin root |
| MCP servers | `.mcp.json` | The `obsidian` server (`npx @bitbonsai/mcpvault@0.15.0 docs/`), hand-authored at the plugin root |
`.apm/` is the authoring source; `skills/` is the generated mirror plugin hosts scan (ADR-0017). This plugin ships no agents. It is the only plugin here with a non-empty `.mcp.json`, which is why its compiled manifests are the only ones carrying an `mcpServers` block.

View File

@@ -1,5 +1,5 @@
name: bin
version: 1.1.2
version: 1.1.3
description: A place for things to be binned
author:
name: Defame1297