Skip to content

Read plugin manifests and overviews from their pinned artifact - #155

Merged
boudra merged 1 commit into
mainfrom
fix-pinned-artifact-files
Oct 7, 2026
Merged

boudra merged 1 commit into
mainfrom
fix-pinned-artifact-files

Conversation

@boudra

@boudra boudra commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

npm submissions containing OVERVIEW.md failed when their package lacked provenance: the registry looked for the overview in GitHub while reading the manifest from npm. Both files now come from the verified pinned tarball for npm, or the pinned commit and plugin directory for GitHub.

One artifact reader owns source selection and pin verification across submission pinning, validation, publication, and bumps. Missing-file guidance now points authors to the submitted artifact.

Goals:

  • Read manifest and overview content from the same exact artifact, without npm file reads requiring repository metadata or falling back to GitHub.
  • Preserve registry overrides, repository metadata and ownership checks, registry IDs, asset URLs, and the published index format.

Non-goals: changing submission authorization, registry records or pins, content review policy, or asset hosting.

Refs #152. This fixes the file-reading failure; the submission still needs its normal review.

Verification:

  • Failing-first regressions reproduced npm choosing repository content and ignoring a packaged overview without provenance.
  • 143 tests pass, covering different npm/Git content, exact pins rather than latest/HEAD, absent repository metadata, pin mismatches, missing files without a Git fallback, import policies, and override precedence.
  • Offline and full online validation pass for all 210 records.
  • Build publishes all 210 records.
  • Read-only verification of paseo-theme-studio@0.6.2 resolves its 3,191-character packaged overview and validates with no provenance commit.

Compatibility: existing listings passed full validation and publication. npm packages must ship their overview in the tarball; unchanged imported listings retain the existing registry-stopgap policy.

npm overviews were read from a provenance-linked repository while manifests came from the tarball. Resolve both files through the install pin so package contents do not depend on repository metadata.
@boudra
boudra merged commit ad46aff into main Oct 7, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant