plugins/bin/.mcp.json declared the obsidian server as `npx @bitbonsai/mcpvault@latest`, so an unpinned third-party npm package was fetched and executed at every session start. The apm-consumed install promoted that string to committed repo-root content in .mcp.json, giving every clone the same unpinned execution. Pinned to 0.15.0, the version `latest` currently resolves to. bin 1.1.2 -> 1.1.3 and marketplace 0.4.0 -> 0.4.1, following the mappingbb9158destablishes and3bfdf58confirms: the marketplace takes the same bump severity as the highest-severity package bump. kyberforge is not bumped here, so executables.allow's `kyberforge#1.5.0` key is untouched. The pin is not live for this working copy until this lands on the remote and `apm update` re-resolves — apm.lock.yaml still records 1.1.2 and `@latest`, because the six dependencies resolve from the remote rather than from the tree beside them. Correct for a fresh clone immediately. .gitignore gains /.claude-plugin/plugin.json: a bare `apm pack` emits a root-package manifest there that has never been tracked on any branch. Scoped to the file, since the sibling marketplace.json is compiled output that is committed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01X7GvKuJfy2WrdBmUttV4DT
68 lines
2.2 KiB
JSON
68 lines
2.2 KiB
JSON
{
|
|
"name": "holocron",
|
|
"description": "AI development skills for Claude Code and GitHub Copilot CLI — factory, design, implement, review, and cross-cutting workflows.",
|
|
"version": "0.4.1",
|
|
"owner": {
|
|
"name": "Defame1297",
|
|
"email": "defame1297@rkdr.net",
|
|
"url": "https://git.dev.rkdr.net/Defame1297/"
|
|
},
|
|
"plugins": [
|
|
{
|
|
"name": "kyberforge",
|
|
"description": "Skills and agents for creating, maintaining, and managing a Claude Code / Copilot CLI plugin marketplace.",
|
|
"version": "1.5.0",
|
|
"category": "Developer Tools",
|
|
"source": "./plugins/kyberforge"
|
|
},
|
|
{
|
|
"name": "bin",
|
|
"description": "A place for things to be binned",
|
|
"version": "1.1.3",
|
|
"category": "Utilities",
|
|
"source": "./plugins/bin"
|
|
},
|
|
{
|
|
"name": "git",
|
|
"description": "Skills for working with Git — conventional commits, branch management, pull requests, and feature flow.",
|
|
"version": "1.3.3",
|
|
"category": "Version Control",
|
|
"source": "./plugins/git"
|
|
},
|
|
{
|
|
"name": "gitea",
|
|
"description": "Skills for managing Gitea repositories — issues, pull requests, milestones, releases, and wikis.",
|
|
"version": "1.3.4",
|
|
"category": "Version Control",
|
|
"source": "./plugins/gitea"
|
|
},
|
|
{
|
|
"name": "core",
|
|
"description": "Skills for authoring and auditing a repo's AGENTS.md and the provider adapter files that defer to it.",
|
|
"version": "1.1.1",
|
|
"category": "Productivity",
|
|
"source": "./plugins/core"
|
|
},
|
|
{
|
|
"name": "mattpocock-skills",
|
|
"description": "Skills for Real Engineers — planning, TDD, architecture, and debugging workflows from Matt Pocock's .claude directory.",
|
|
"version": "1.2.3",
|
|
"category": "Productivity",
|
|
"source": {
|
|
"source": "github",
|
|
"repo": "mattpocock/skills",
|
|
"ref": "v1.2.3",
|
|
"sha": "835450ef244ab7335f75d95b83e7d979eae22a6d",
|
|
"tag_pattern": "v{version}"
|
|
}
|
|
},
|
|
{
|
|
"name": "lint",
|
|
"description": "Skills and agents for configuring and running linters.",
|
|
"version": "1.1.6",
|
|
"category": "Developer Tools",
|
|
"source": "./plugins/lint"
|
|
}
|
|
]
|
|
}
|