plugins/bin/.mcp.json declared the obsidian server as `npx @bitbonsai/mcpvault@latest`, so an unpinned third-party npm package was fetched and executed at every session start. The apm-consumed install promoted that string to committed repo-root content in .mcp.json, giving every clone the same unpinned execution. Pinned to 0.15.0, the version `latest` currently resolves to. bin 1.1.2 -> 1.1.3 and marketplace 0.4.0 -> 0.4.1, following the mappingbb9158destablishes and3bfdf58confirms: the marketplace takes the same bump severity as the highest-severity package bump. kyberforge is not bumped here, so executables.allow's `kyberforge#1.5.0` key is untouched. The pin is not live for this working copy until this lands on the remote and `apm update` re-resolves — apm.lock.yaml still records 1.1.2 and `@latest`, because the six dependencies resolve from the remote rather than from the tree beside them. Correct for a fresh clone immediately. .gitignore gains /.claude-plugin/plugin.json: a bare `apm pack` emits a root-package manifest there that has never been tracked on any branch. Scoped to the file, since the sibling marketplace.json is compiled output that is committed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01X7GvKuJfy2WrdBmUttV4DT
31 lines
699 B
JSON
31 lines
699 B
JSON
{
|
|
"name": "bin",
|
|
"version": "1.1.3",
|
|
"description": "A place for things to be binned",
|
|
"author": {
|
|
"name": "Defame1297",
|
|
"email": "defame1297@rkdr.net",
|
|
"url": "https://git.dev.rkdr.net/Defame1297/"
|
|
},
|
|
"license": "MIT",
|
|
"homepage": "https://git.dev.rkdr.net/Defame1297/holocron/src/branch/main/plugins/bin",
|
|
"repository": "https://git.dev.rkdr.net/Defame1297/holocron/src/branch/main/plugins/bin",
|
|
"keywords": [
|
|
"utility",
|
|
"diagnostics",
|
|
"prototyping",
|
|
"tdd",
|
|
"research"
|
|
],
|
|
"mcpServers": {
|
|
"obsidian": {
|
|
"args": [
|
|
"@bitbonsai/mcpvault@0.15.0",
|
|
"docs/"
|
|
],
|
|
"command": "npx",
|
|
"type": "stdio"
|
|
}
|
|
}
|
|
}
|