Why --- ADR-0018 left deployed skills tracking the remote default branch with nothing watching for drift. The mechanism that was supposed to cover this, scripts/git-hooks/post-push, could never have worked: git has no client-side post-push hook. install.sh copied it into .git/hooks/ so it looked installed, and it had never once fired. Issue #78 reported it as skipping the gitea plugin; it was skipping everything. Refreshing on push was also the wrong shape. Your install goes stale when someone else merges, so a push of your own is neither necessary nor sufficient for staleness to have occurred. Implementation notes -------------------- kyberforge ships a SessionStart hook (startup matcher only) that runs `apm outdated`, and when anything is behind runs `apm update --yes` and returns reloadSkills:true so the running session picks up redeployed content. It exits silently with no apm.lock.yaml present, which keeps it inert for hosts that installed this plugin natively rather than through apm. Two findings drove the wiring, both verified rather than assumed: - apm resolves ${CLAUDE_PLUGIN_ROOT} against the installed package root, and `apm pack` keeps only *.json from .apm/hooks/. A .../hooks/<script> reference therefore points into the generated mirror where the script does not exist — apm reports "Hook script not found" and deploys a hook aimed at nothing. The reference must be .apm/-relative, and a test pins it. - apm's executable-trust gate is OFF unless apm.yml carries an `executables:` block; until now every hook, bin and MCP primitive a dependency shipped would have deployed unprompted. Root apm.yml now enables it. The allow key is version-pinned by apm's design, so a kyberforge version bump silently blocks the hook until the key is bumped too — called out in the block and the ADR. Also corrects ADR-0018 and AGENTS.md, which named `apm install` as the refresh command. It is not: `apm install` deploys from apm.lock.yaml's pinned commit and does not re-resolve refs. `apm update` does. Impact ------ Session startup costs ~0.7s when current and ~10.4s when six packages are behind. Auto-refresh rewrites apm.lock.yaml, so an unexplained modification to it after opening a session is expected; the emitted notice says so. .claude/settings.json stops being exactly {"hooks": {}} once the hook lands there — the merged entry is apm's own output, and the rule that nothing repo-authored goes in that file is unchanged. .claude/hooks/ and the .claude/apm-hooks.json sidecar are gitignored install output. The hook cannot install itself: dependencies resolve from the remote, so it takes effect only after this merges and `apm update` runs once against the new default branch. scripts/git-hooks/ is now empty. install.sh's copy block is kept and test-git-hooks-install.sh synthesizes its own fixture, so the mechanism stays tested without requiring a dead hook to exist. ADR: 0019 Refs: #78 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01X7GvKuJfy2WrdBmUttV4DT
120 lines
4.6 KiB
YAML
120 lines
4.6 KiB
YAML
name: holocron
|
|
version: 0.3.4
|
|
description: AI development skills for Claude Code and GitHub Copilot CLI — factory, design, implement, review, and cross-cutting workflows.
|
|
license: MIT
|
|
|
|
# Consumer side: this repo installs its own published plugins from the holocron
|
|
# remote, so the working copy runs the same released content every other
|
|
# consumer gets. Addressed as git+path objects rather than <name>@holocron
|
|
# marketplace aliases — an alias needs a `apm marketplace add` registration in
|
|
# ~/.apm/marketplaces.json (user scope, outside this repo), the object form
|
|
# needs nothing beyond this manifest.
|
|
# Unpinned (default branch) on purpose: parity with the Claude Code plugin
|
|
# install this replaced, which ran autoUpdate against main. Add `ref: <tag>`
|
|
# per entry to pin.
|
|
targets:
|
|
- claude
|
|
dependencies:
|
|
apm:
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/bin
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/core
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/git
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/gitea
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/kyberforge
|
|
- git: git@git.dev.rkdr.net:Defame1297/holocron.git
|
|
path: plugins/lint
|
|
mcp: []
|
|
|
|
# Turns apm's executable-trust gate ON. Without this block the gate is disabled
|
|
# and every hook, bin and MCP primitive a dependency ships deploys silently —
|
|
# verified: `apm approve --list` reports "Executable-trust gate disabled -- all
|
|
# executables deploy" until an `executables:` block exists.
|
|
#
|
|
# kyberforge ships the SessionStart hook that keeps this install level with the
|
|
# remote (ADR-0019). The key is version-pinned by apm's own design, so a
|
|
# kyberforge version bump makes this entry stop matching and the hook stops
|
|
# deploying until the version here is bumped too. If skills silently go stale
|
|
# after a kyberforge release, check this first.
|
|
executables:
|
|
allow:
|
|
kyberforge#1.4.1:
|
|
hooks: true
|
|
bin: true
|
|
|
|
marketplace:
|
|
# apm's Claude marketplace mapper only emits description:/version: into the
|
|
# compiled marketplace.json when set explicitly here (an override) — the
|
|
# top-level apm.yml description:/version: above are NOT inherited into the
|
|
# compiled output despite being used elsewhere (e.g. by `apm audit`).
|
|
description: AI development skills for Claude Code and GitHub Copilot CLI — factory, design, implement, review, and cross-cutting workflows.
|
|
version: 0.3.4
|
|
owner:
|
|
name: Defame1297
|
|
email: defame1297@rkdr.net
|
|
url: https://git.dev.rkdr.net/Defame1297/
|
|
|
|
# Default tag pattern used to resolve version ranges for each package.
|
|
build:
|
|
tagPattern: "v{version}"
|
|
|
|
# Output targets (map form). Each output writes to its profile default
|
|
# path; add 'path:' under a key to override.
|
|
# 'codex' requires every package below to declare 'category:' (satisfied).
|
|
outputs:
|
|
claude: {}
|
|
codex: {}
|
|
|
|
# CI tip: build one or all formats with a machine-readable manifest:
|
|
# apm pack --marketplace=claude,codex --json | jq -r '.marketplace.outputs[].path'
|
|
|
|
versioning:
|
|
strategy: per_package
|
|
|
|
packages:
|
|
- name: kyberforge
|
|
description: Skills and agents for creating, maintaining, and managing a Claude Code / Copilot CLI plugin marketplace.
|
|
source: ./plugins/kyberforge
|
|
version: 1.4.1
|
|
category: Developer Tools
|
|
|
|
- name: bin
|
|
description: A place for things to be binned
|
|
source: ./plugins/bin
|
|
version: 1.1.2
|
|
category: Utilities
|
|
|
|
- name: git
|
|
description: Skills for working with Git — conventional commits, branch management, pull requests, and feature flow.
|
|
source: ./plugins/git
|
|
version: 1.3.3
|
|
category: Version Control
|
|
|
|
- name: gitea
|
|
description: Skills for managing Gitea repositories — issues, pull requests, milestones, releases, and wikis.
|
|
source: ./plugins/gitea
|
|
version: 1.3.4
|
|
category: Version Control
|
|
|
|
- name: core
|
|
description: Skills for authoring and auditing a repo's AGENTS.md and the provider adapter files that defer to it.
|
|
source: ./plugins/core
|
|
version: 1.1.1
|
|
category: Productivity
|
|
|
|
- name: mattpocock-skills
|
|
description: Skills for Real Engineers — planning, TDD, architecture, and debugging workflows from Matt Pocock's .claude directory.
|
|
source: mattpocock/skills
|
|
version: "1.2.3"
|
|
category: Productivity
|
|
|
|
- name: lint
|
|
description: Skills and agents for configuring and running linters.
|
|
source: ./plugins/lint
|
|
version: 1.1.6
|
|
category: Developer Tools
|