plugins/bin/.mcp.json declared the obsidian server as `npx @bitbonsai/mcpvault@latest`, so an unpinned third-party npm package was fetched and executed at every session start. The apm-consumed install promoted that string to committed repo-root content in .mcp.json, giving every clone the same unpinned execution. Pinned to 0.15.0, the version `latest` currently resolves to. bin 1.1.2 -> 1.1.3 and marketplace 0.4.0 -> 0.4.1, following the mappingbb9158destablishes and3bfdf58confirms: the marketplace takes the same bump severity as the highest-severity package bump. kyberforge is not bumped here, so executables.allow's `kyberforge#1.5.0` key is untouched. The pin is not live for this working copy until this lands on the remote and `apm update` re-resolves — apm.lock.yaml still records 1.1.2 and `@latest`, because the six dependencies resolve from the remote rather than from the tree beside them. Correct for a fresh clone immediately. .gitignore gains /.claude-plugin/plugin.json: a bare `apm pack` emits a root-package manifest there that has never been tracked on any branch. Scoped to the file, since the sibling marketplace.json is compiled output that is committed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01X7GvKuJfy2WrdBmUttV4DT
120 lines
4.6 KiB
YAML
120 lines
4.6 KiB
YAML
name: holocron
|
|
version: 0.4.1
|
|
description: AI development skills for Claude Code and GitHub Copilot CLI — factory, design, implement, review, and cross-cutting workflows.
|
|
license: MIT
|
|
|
|
# Consumer side: this repo installs its own published plugins from the holocron
|
|
# remote, so the working copy runs the same released content every other
|
|
# consumer gets. Addressed as git+path objects rather than <name>@holocron
|
|
# marketplace aliases — an alias needs a `apm marketplace add` registration in
|
|
# ~/.apm/marketplaces.json (user scope, outside this repo), the object form
|
|
# needs nothing beyond this manifest.
|
|
# Unpinned (default branch) on purpose: parity with the Claude Code plugin
|
|
# install this replaced, which ran autoUpdate against main. Add `ref: <tag>`
|
|
# per entry to pin.
|
|
targets:
|
|
- claude
|
|
dependencies:
|
|
apm:
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/bin
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/core
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/git
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/gitea
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/kyberforge
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/lint
|
|
mcp: []
|
|
|
|
# Turns apm's executable-trust gate ON. Without this block the gate is disabled
|
|
# and every hook, bin and MCP primitive a dependency ships deploys silently —
|
|
# verified: `apm approve --list` reports "Executable-trust gate disabled -- all
|
|
# executables deploy" until an `executables:` block exists.
|
|
#
|
|
# kyberforge ships the SessionStart hook that keeps this install level with the
|
|
# remote (ADR-0019). The key is version-pinned by apm's own design, so a
|
|
# kyberforge version bump makes this entry stop matching and the hook stops
|
|
# deploying until the version here is bumped too. If skills silently go stale
|
|
# after a kyberforge release, check this first.
|
|
executables:
|
|
allow:
|
|
kyberforge#1.5.0:
|
|
hooks: true
|
|
bin: true
|
|
|
|
marketplace:
|
|
# apm's Claude marketplace mapper only emits description:/version: into the
|
|
# compiled marketplace.json when set explicitly here (an override) — the
|
|
# top-level apm.yml description:/version: above are NOT inherited into the
|
|
# compiled output despite being used elsewhere (e.g. by `apm audit`).
|
|
description: AI development skills for Claude Code and GitHub Copilot CLI — factory, design, implement, review, and cross-cutting workflows.
|
|
version: 0.4.1
|
|
owner:
|
|
name: Defame1297
|
|
email: defame1297@rkdr.net
|
|
url: https://git.dev.rkdr.net/Defame1297/
|
|
|
|
# Default tag pattern used to resolve version ranges for each package.
|
|
build:
|
|
tagPattern: "v{version}"
|
|
|
|
# Output targets (map form). Each output writes to its profile default
|
|
# path; add 'path:' under a key to override.
|
|
# 'codex' requires every package below to declare 'category:' (satisfied).
|
|
outputs:
|
|
claude: {}
|
|
codex: {}
|
|
|
|
# CI tip: build one or all formats with a machine-readable manifest:
|
|
# apm pack --marketplace=claude,codex --json | jq -r '.marketplace.outputs[].path'
|
|
|
|
versioning:
|
|
strategy: per_package
|
|
|
|
packages:
|
|
- name: kyberforge
|
|
description: Skills and agents for creating, maintaining, and managing a Claude Code / Copilot CLI plugin marketplace.
|
|
source: ./plugins/kyberforge
|
|
version: 1.5.0
|
|
category: Developer Tools
|
|
|
|
- name: bin
|
|
description: A place for things to be binned
|
|
source: ./plugins/bin
|
|
version: 1.1.3
|
|
category: Utilities
|
|
|
|
- name: git
|
|
description: Skills for working with Git — conventional commits, branch management, pull requests, and feature flow.
|
|
source: ./plugins/git
|
|
version: 1.3.3
|
|
category: Version Control
|
|
|
|
- name: gitea
|
|
description: Skills for managing Gitea repositories — issues, pull requests, milestones, releases, and wikis.
|
|
source: ./plugins/gitea
|
|
version: 1.3.4
|
|
category: Version Control
|
|
|
|
- name: core
|
|
description: Skills for authoring and auditing a repo's AGENTS.md and the provider adapter files that defer to it.
|
|
source: ./plugins/core
|
|
version: 1.1.1
|
|
category: Productivity
|
|
|
|
- name: mattpocock-skills
|
|
description: Skills for Real Engineers — planning, TDD, architecture, and debugging workflows from Matt Pocock's .claude directory.
|
|
source: mattpocock/skills
|
|
version: "1.2.3"
|
|
category: Productivity
|
|
|
|
- name: lint
|
|
description: Skills and agents for configuring and running linters.
|
|
source: ./plugins/lint
|
|
version: 1.1.6
|
|
category: Developer Tools
|