Skip to content

Sync plugin archives with validated extension source - #2

Draft
f wants to merge 1 commit into
mainfrom
codex/chatgpt-plugin-release-sync
Draft

f wants to merge 1 commit into
mainfrom
codex/chatgpt-plugin-release-sync

Conversation

@f

@f f commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Refreshes the generated plugin archives and provenance from source commit bbb3507cd7c0c7e1039e151c18084aec311fbcfe, which includes the final migration, packaging, and typecheck fixes. The feature payload remains the same as #1.

Validation: all four platforms, 117 regular files, and eight archives checked against fresh generated output. Archive entries and bytes, SHA-256 checksums, production endpoints, and onboarding paths pass.

Hold this archive refresh until regeneration from the next release. The release workflow now selects 0.6.0, while these artifacts still pin spacefast@0.5.1; npm currently has 0.5.0. The next regeneration must include the host-context, domain-event, search, and webhook follow-up fixes and use the actual release version. Hosted extensions also require the backend rollout.

Copilot AI balanced review requested due to automatic review settings October 1, 2026 11:19
@indent

indent Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
PR Summary

Regenerates the published Spacefast plugin distribution from monorepo commit bbb3507 (one commit after the 309185 source used in #1). Version stays at 0.5.1, and the plugin payload doesn't change.

  • sourceSha is updated in PROVENANCE.json, marketplace/submission-index.json, release-manifest.json, and every marketplace entry.json/RUNBOOK.md.
  • All archives (*.tgz, spacefast-plugins.zip, spacefast.mcpb, claude-desktop/spacefast.mcpb) are rebuilt and their checksums refreshed. Extracted contents are identical to main except for the bundled sourceSha strings; the bytes differ only because of file timestamps.
  • .agents/plugins/marketplace.json is now listed in release-manifest.json marketplace artifacts. Its content is unchanged; it is now emitted by the shared openAIPluginMarketplace() catalog helper.
  • Checked: every checksum matches the file on disk, the bundle contents match the repo tree byte for byte, and no reference to the old SHA remains.

Issues

No issues found.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 75a88660-796f-41d4-bffb-531c54ffac6e

📥 Commits

Reviewing files that changed from the base of the PR and between ac9a1a9 and f4af4f1.

⛔ Files ignored due to path filters (1)
  • spacefast-plugins.zip is excluded by !**/*.zip
📒 Files selected for processing (42)
  • PROVENANCE.json
  • claude-code.tgz
  • claude-desktop.tgz
  • claude-desktop/spacefast.mcpb
  • codex.tgz
  • cursor.tgz
  • marketplace/submission-index.json
  • marketplace/submissions/anthropic/RUNBOOK.md
  • marketplace/submissions/anthropic/entry.json
  • marketplace/submissions/awesome-copilot/RUNBOOK.md
  • marketplace/submissions/awesome-copilot/entry.json
  • marketplace/submissions/cline/RUNBOOK.md
  • marketplace/submissions/cline/entry.json
  • marketplace/submissions/codebuddy/RUNBOOK.md
  • marketplace/submissions/codebuddy/entry.json
  • marketplace/submissions/cursor/RUNBOOK.md
  • marketplace/submissions/cursor/entry.json
  • marketplace/submissions/docker/RUNBOOK.md
  • marketplace/submissions/gemini/RUNBOOK.md
  • marketplace/submissions/glama/RUNBOOK.md
  • marketplace/submissions/goose/RUNBOOK.md
  • marketplace/submissions/grok/RUNBOOK.md
  • marketplace/submissions/hermes/RUNBOOK.md
  • marketplace/submissions/hermes/entry.json
  • marketplace/submissions/kilo/RUNBOOK.md
  • marketplace/submissions/kilo/entry.json
  • marketplace/submissions/kimi/RUNBOOK.md
  • marketplace/submissions/official-mcp-registry/RUNBOOK.md
  • marketplace/submissions/official-mcp-registry/entry.json
  • marketplace/submissions/openai/RUNBOOK.md
  • marketplace/submissions/openai/entry.json
  • marketplace/submissions/opencode/RUNBOOK.md
  • marketplace/submissions/qoder/RUNBOOK.md
  • marketplace/submissions/qoder/entry.json
  • marketplace/submissions/skillhub/RUNBOOK.md
  • marketplace/submissions/skillhub/entry.json
  • marketplace/submissions/skills-sh/RUNBOOK.md
  • marketplace/submissions/smithery/RUNBOOK.md
  • marketplace/submissions/smithery/entry.json
  • release-manifest.json
  • spacefast-plugins.tgz
  • spacefast.mcpb

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The provenance source SHA was updated in repository and marketplace submission records. The release manifest was refreshed with a new timestamp and checksums, and its marketplace artifact list now includes .agents/plugins/marketplace.json.

Changes

Provenance and release metadata

Layer / File(s) Summary
Update source commit references
PROVENANCE.json, marketplace/submission-index.json, marketplace/submissions/*/{RUNBOOK.md,entry.json}
Updated recorded source commit references from 309185424b5cc4bfc2b8367d0bd6b6f222ed75f2 to bbb3507cd7c0c7e1039e151c18084aec311fbcfe.
Refresh release manifest
release-manifest.json
Updated the generation timestamp, artifact checksums, and provenance source SHA. Added .agents/plugins/marketplace.json to the marketplace artifact list.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to f4af4

This metadata refresh has matching artifact digests and includes the marketplace file in the packaged release. Although the source-to-payload provenance link was not independently established, no concrete release failure is shown, so no merge-blocking issue remains.

Architecture Summary

Architecture risk: 🔵 Low · up to f4af4

The change affects 3 systems.

Changed systems: marketplace, PROVENANCE.json, release-manifest.json

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — marketplace (service) was modified; 33 changed files map to changed impact.
  • observed — PROVENANCE.json (service) was modified; 1 changed file maps to changed impact.
  • observed — release-manifest.json (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in PROVENANCE.json: The sourceSha value changed from 309185424b5cc4bfc2b8367d0bd6b6f222ed75f2 to bbb3507cd7c0c7e1039e151c18084aec311fbcfe.
  • observed — Modified behavior in marketplace/submission-index.json: Updated the provenance sourceSha value to bbb3507cd7c0c7e1039e151c18084aec311fbcfe, replacing 309185424b5cc4bfc2b8367d0bd6b6f222ed75f2.
  • observed — Modified behavior in marketplace/submissions/anthropic/RUNBOOK.md: The source commit recorded for the submission changed from 309185424b5cc4bfc2b8367d0bd6b6f222ed75f2 to bbb3507cd7c0c7e1039e151c18084aec311fbcfe.
  • observed — Modified behavior in marketplace/submissions/anthropic/entry.json: The sourceSha value changed from 309185424b5cc4bfc2b8367d0bd6b6f222ed75f2 to bbb3507cd7c0c7e1039e151c18084aec311fbcfe.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: synchronizing generated plugin archives with the validated extension source.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The generated distribution depends on an unpublished npm package and pending backend rollout requiring human release coordination.

Review effort: Balanced
Findings: None

What changed in this PR

Synchronizes generated plugin release metadata with source commit bbb3507c while retaining version 0.5.1.

Changes:

  • Refreshes archive checksums and MCPB provenance.
  • Updates marketplace submission provenance consistently.
  • Adds the Codex marketplace manifest to the artifact inventory.
File Description
release-manifest.json Refreshes checksums, provenance, and artifact inventory.
PROVENANCE.json Updates the source commit.
marketplace/​submission-index.json Updates marketplace provenance.
marketplace/​submissions/​smithery/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​smithery/​entry.json Updates source provenance.
marketplace/​submissions/​skills-sh/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​skillhub/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​skillhub/​entry.json Updates source provenance.
marketplace/​submissions/​qoder/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​qoder/​entry.json Updates source provenance.
marketplace/​submissions/​opencode/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​openai/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​openai/​entry.json Updates source provenance.
marketplace/​submissions/​official-mcp-registry/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​official-mcp-registry/​entry.json Updates source provenance.
marketplace/​submissions/​kimi/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​kilo/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​kilo/​entry.json Updates source provenance.
marketplace/​submissions/​hermes/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​hermes/​entry.json Updates source provenance.
marketplace/​submissions/​grok/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​goose/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​glama/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​gemini/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​docker/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​cursor/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​cursor/​entry.json Updates source provenance.
marketplace/​submissions/​codebuddy/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​codebuddy/​entry.json Updates source provenance.
marketplace/​submissions/​cline/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​cline/​entry.json Updates source provenance.
marketplace/​submissions/​awesome-copilot/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​awesome-copilot/​entry.json Updates source provenance.
marketplace/​submissions/​anthropic/​RUNBOOK.md Updates source provenance.
marketplace/​submissions/​anthropic/​entry.json Updates source provenance.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@f
f marked this pull request as draft October 1, 2026 11:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants