docs(kyberforge): stop apm-workflow assuming root package versions

The root apm.yml packages[] entries no longer carry version:, and a
version there is a silent override that --check-versions does not
catch. configure.md and marketplace.md now name the package's own
apm.yml as the single source and drop version: from the examples.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-09-16 10:33:35 +00:00
parent dd0b9233e6
commit c07ca0767e
2 changed files with 20 additions and 14 deletions

View File

@@ -53,12 +53,13 @@ output changes.** Two triggers, not one:
The version belongs to the package, not to the repo: editing `plugins/foo/.apm/` never bumps
`plugins/bar/apm.yml`.
Under a `per_package` strategy the same number is also carried in the catalog's
`marketplace.packages[]` entry, so both copies move together in the same commit. The catalog's own
version follows a separate rule — see `references/marketplace.md`. `apm pack --check-versions`
fails the push when a package's version disagrees with the configured strategy, so a bump applied
in only one of the two places is caught, but a bump skipped in both is not: nothing infers intent
from a content diff.
Under a `per_package` strategy this `version:` is the single source: when a catalog's
`marketplace.packages[]` entry omits `version:`, `apm pack` reads it from the package's `apm.yml`.
Do not restate it there. A `version:` on the entry is an override, not a copy — it silently wins in
the compiled `marketplace.json`, and `apm pack --check-versions` still reports `[matches]` when it
disagrees with the package's own number, so drift between the two is never caught. Set one only
when an override is the intent. A skipped bump is not caught either: nothing infers intent from a
content diff. The catalog's own version follows a separate rule — see `references/marketplace.md`.
## Dependency reference forms