The six packages[].version lines restated each plugin's own apm.yml version and were unpoliced: on drift apm silently shipped the curator value. apm reads the plugin's apm.yml when the entry is absent, and apm pack --check-versions --check-clean still passes with the committed marketplace.json unchanged. Simplification audit finding 33. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
106 lines
4.3 KiB
YAML
106 lines
4.3 KiB
YAML
name: holocron
|
|
version: 0.4.7
|
|
description: AI development skills for Claude Code and GitHub Copilot CLI — factory, design, implement, review, and cross-cutting workflows.
|
|
license: MIT
|
|
|
|
# Consumer side: this repo installs its own published plugins from the holocron
|
|
# remote, so the working copy runs the same released content every other
|
|
# consumer gets. Addressed as git+path objects rather than <name>@holocron
|
|
# marketplace aliases — an alias needs a `apm marketplace add` registration in
|
|
# ~/.apm/marketplaces.json (user scope, outside this repo), the object form
|
|
# needs nothing beyond this manifest.
|
|
# Unpinned (default branch) on purpose: parity with the Claude Code plugin
|
|
# install this replaced, which ran autoUpdate against main. Add `ref: <tag>`
|
|
# per entry to pin.
|
|
targets:
|
|
- claude
|
|
dependencies:
|
|
apm:
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/bin
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/core
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/git
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/gitea
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/kyberforge
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/lint
|
|
mcp: []
|
|
|
|
# Turns apm's executable-trust gate ON. Without this block the gate is disabled
|
|
# and every hook, bin and MCP primitive a dependency ships deploys silently —
|
|
# verified: `apm approve --list` reports "Executable-trust gate disabled -- all
|
|
# executables deploy" until an `executables:` block exists.
|
|
#
|
|
# kyberforge ships the SessionStart hook that keeps this install level with the
|
|
# remote (ADR-0019). The key is version-pinned by apm's own design, so a
|
|
# kyberforge version bump makes this entry stop matching and the hook stops
|
|
# deploying until the version here is bumped too. If skills silently go stale
|
|
# after a kyberforge release, check this first.
|
|
executables:
|
|
allow:
|
|
kyberforge#2.0.0:
|
|
hooks: true
|
|
bin: true
|
|
|
|
marketplace:
|
|
# apm's Claude marketplace mapper only emits description:/version: into the
|
|
# compiled marketplace.json when set explicitly here (an override) — the
|
|
# top-level apm.yml description:/version: above are NOT inherited into the
|
|
# compiled output despite being used elsewhere (e.g. by `apm audit`).
|
|
description: AI development skills for Claude Code and GitHub Copilot CLI — factory, design, implement, review, and cross-cutting workflows.
|
|
version: 0.4.7
|
|
owner:
|
|
name: Defame1297
|
|
email: defame1297@rkdr.net
|
|
url: https://git.dev.rkdr.net/Defame1297/
|
|
|
|
# Default tag pattern used to resolve version ranges for each package.
|
|
build:
|
|
tagPattern: "v{version}"
|
|
|
|
# Output targets (map form). Each output writes to its profile default
|
|
# path; add 'path:' under a key to override.
|
|
outputs:
|
|
claude: {}
|
|
|
|
# CI tip: build a machine-readable manifest:
|
|
# apm pack --marketplace=claude --json | jq -r '.marketplace.outputs[].path'
|
|
|
|
versioning:
|
|
strategy: per_package
|
|
|
|
packages:
|
|
- name: kyberforge
|
|
description: Skills and agents for creating, maintaining, and managing a Claude Code / Copilot CLI plugin marketplace.
|
|
source: ./plugins/kyberforge
|
|
category: Developer Tools
|
|
|
|
- name: bin
|
|
description: Skills for everyday AI-assisted development work that is not tied to a single tool, forge or language, and has not yet been split into a focused plugin.
|
|
source: ./plugins/bin
|
|
category: Utilities
|
|
|
|
- name: git
|
|
description: Skills and agents for working with a local Git clone over the git wire protocol, and for authoring and running the pre-commit hooks that guard it.
|
|
source: ./plugins/git
|
|
category: Version Control
|
|
|
|
- name: gitea
|
|
description: Skills and agents for working with a Gitea forge through its HTTP API — the forge's own objects, as distinct from the local git clone.
|
|
source: ./plugins/gitea
|
|
category: Version Control
|
|
|
|
- name: core
|
|
description: Skills for authoring and auditing a repo's AGENTS.md and the provider adapter files that defer to it.
|
|
source: ./plugins/core
|
|
category: Productivity
|
|
|
|
- name: lint
|
|
description: Skills and agents for configuring and running linters.
|
|
source: ./plugins/lint
|
|
category: Developer Tools
|