Files
holocron/plugins/kyberforge/docs/research/docs/microsoft-apm/sources.md
Defame1297 6e77c11474 ci(kyberforge): add apm-native marketplace/audit/pack drift gates
Validated the plugin-content-mirror fix (issue #90) against apm's own
packing/CI documentation and source: no apm-native mechanism replaces the
mirror script (apm's bundler treats .apm/ and root convention dirs as
mutually exclusive, by design), but the investigation surfaced a real,
separate gap -- this repo ran zero apm-native audit/check commands in CI,
relying entirely on custom scripts and Claude Code's own client-side
validator.

Add three pre-push hooks matching apm's documented producer CI pattern:
- apm marketplace check: validates every marketplace.packages[] entry
  resolves, including live network reachability for remote refs -- a
  blind spot check-manifests.sh explicitly skips (local sources only).
- apm audit --ci: apm's own lockfile/policy/hidden-content integrity gate.
- apm pack --check-versions --check-clean: closes issue #90's deferred
  item 3 (a check-clean-equivalent gate) using apm's native flag instead
  of bespoke drift logic, verifying .claude-plugin/marketplace.json still
  matches what apm.yml + .apm/ would currently generate.

All three are network-tolerant and whole-repo in scope, so they belong at
pre-push alongside check-manifests/check-plugin-content-sync/
validate-plugins -- not pre-commit, which stays fast/offline/per-file.

Documented the packing/bundling/releasing/CI findings in
docs/research/docs/microsoft-apm/releasing.md (new) and extended
testing-and-validation.md with the apm-action wrapper and its documented
CI patterns, sourced from Context7 and cross-checked against the
installed apm-cli 0.28.0 package directly.

Refs: #90
2026-08-13 17:50:32 +00:00

2.2 KiB

Sources

context7-microsoft-apm

  • URL: context7:/microsoft/apm
  • Description: Microsoft APM (Agent Package Manager) — open-source dependency manager for AI agent configuration (skills, prompts, instructions, agents, hooks, MCP/LSP deps), applying a declare/lock/install/audit workflow.
  • Contributing files: overview.md, installation.md, configuration.md, cli-reference.md, examples.md, troubleshooting.md, testing-and-validation.md, marketplace-and-registries.md, monorepo-and-repo-shapes.md, agent-primitive-schema.md, prompt-primitive-schema.md, instructions-primitive-schema.md, hooks-primitive-schema.md, releasing.md
  • Status: extracted

apm-github-repo

  • URL: https://github.com/microsoft/apm
  • Description: APM's own Python source (src/apm_cli/) read directly for schema/compile-mapping ground truth where Context7's doc snippets were thin — specifically primitives/models.py and primitives/discovery.py (primitive dataclasses and discovery globs), integration/prompt_integrator.py, integration/command_integrator.py, integration/instruction_integrator.py, integration/hook_integrator.py, integration/hook_native_formats.py, integration/hook_ir.py, integration/_hook_dropped_targets.py, integration/targets.py (KNOWN_TARGETS/PrimitiveMapping per-target deploy config), compilation/claude_formatter.py and compilation/distributed_compiler.py (instruction fold-in to CLAUDE.md/AGENTS.md), and models/validation.py.
  • Contributing files: agent-primitive-schema.md, prompt-primitive-schema.md, instructions-primitive-schema.md, hooks-primitive-schema.md, releasing.md
  • Status: extracted

Note: releasing.md's --check-clean/--check-versions scope, apm pack exit-code semantics, and the .apm/-vs-root-flat-dir mutual exclusivity referenced there were additionally cross-checked directly against apm_cli/bundle/plugin_exporter.py, apm_cli/commands/pack.py, and apm_cli/marketplace/drift_check.py in the installed apm-cli 0.28.0 package (/root/.local/pipx/venvs/apm-cli/), not just Context7 doc snippets — confirmed by a live apm pack --format plugin run inside plugins/bin that reproduced the documented [!] Skipping root-level skills/ because .apm/ is present warning.