Repository navigation
Bump lefos13/workspace-snippets to 0.2.6 - #157
Merged
Merged
Conversation
0.2.6 ships OVERVIEW.md, which replaces the copy written at import.
Contributor
There was a problem hiding this comment.
Needs from you: nothing, merged
paseo-workspace-snippets 0.2.6 is approved. It now ships its own OVERVIEW.md, so I removed the registry copy plugins/lefos13/workspace-snippets.md in this pull request and the listing page shows the author's overview from now on.
Review data
- Artifact: npm
paseo-workspace-snippets0.2.6 (from 0.2.4),https://registry.npmjs.org/paseo-workspace-snippets/-/paseo-workspace-snippets-0.2.6.tgz - Integrity: SHA-512 of both tarballs matches the record (old and new pin). npm reports the same version, tarball, and integrity for 0.2.6. No npm provenance; npm
gitHeadis20642968bb997c14222a890a3e786f355011817c. - Validation:
npm testpasses (140/140).node scripts/validate.ts --online --changedwith the validator frommainpasses (the branch predates #155, whose validator readsOVERVIEW.mdfrom the artifact), before and after removing the registry copy. - Extracted and inspected: both tarballs, extracted and diffed locally. The diff adds
OVERVIEW.md, adds it tofilesand bumps the version inpackage.json, and changesfindLocalWorkspaceinserver/projects.ts:53-79: it reads every page ofpaseo.workspaces.list(200 per page) and ranks workspaces by the newer ofactivityAtandstatusEnteredAt(server/projects.ts:27-30). No capability change. - Install-time commands: none.
paseo-plugin.jsonhas noinstallorbuild.package.jsonhas nopreinstall,install,postinstall, orprepare; its only script istypecheck(tsc --noEmit). - Dependencies: no runtime
dependenciesorpeerDependencies; dev dependencies unchanged from 0.2.4. Thepackage-lock.jsonat the source commit has 317 entries, eachresolvedon registry.npmjs.org with anintegrity, andnpm ci --ignore-scriptsinstalls it. The only entry with an install script is the optional macOS dev dependencyfsevents. - Hosts: none. No
fetch, WebSocket, HTTP client, or URL literal in the code. - Credentials and environment: none. No
process.env, credential files, keychain, or token reads. Snippets live in the plugin's host-scoped settings (shared/settings.ts:12-24). - Filesystem: reads the workspace's root
package.json, kept inside the directory and capped at 1 MiB (server/package-json.ts:66-100), and checks for lockfiles to pick the package manager (server/package-json.ts:149-160). No writes. - Execution: no
child_process,eval,new Function, or dynamicimport(). When the user runs a script or snippet, the command is typed into a Paseo workspace terminal (server/terminals.ts:61-102), which is the plugin's stated purpose. Script names are shell-quoted (shared/entries.ts:28-40). - Runtime installs: none.
- Source match: all 31 tarball files are byte-identical to the declared repository at
2064296. Between671ae0b(0.2.5) and2064296onlyOVERVIEW.mdandpackage.jsonchange. - Listing media: four PNG screenshots of the sidebar screen, header button, panel, and Command Center, each HTTP 200
image/png. - Overview:
OVERVIEW.mdfollows the shape inREVIEW.md(what it is, how it works, setup, things to know) with no install steps, badges, or marketing, and each claim matches the code, including that it makes no network requests. - Decision: merge.
- Reviewed commit:
db60f602efd436e7c3218ca429577782b4ad518a
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
lefos13/workspace-snippets: {"kind":"npm","package":"paseo-workspace-snippets","version":"0.2.4","resolved":"https://registry.npmjs.org/paseo-workspace-snippets/-/paseo-workspace-snippets-0.2.4.tgz","integrity":"sha512-VnPmS8NmXVJjcvbOz7MuMAfFo6bf2L6SDjfaadLUOuFbjd+COIa47QtczT9CMmB7+Kmc0FlhMc4u+fb5ou2n/g=="} -> {"kind":"npm","package":"paseo-workspace-snippets","version":"0.2.6","resolved":"https://registry.npmjs.org/paseo-workspace-snippets/-/paseo-workspace-snippets-0.2.6.tgz","integrity":"sha512-qGGF62XM1DuXloF9fbKDJyg9S0KvYSXgiIJINawScpVXDWX/pLDefy5EjbqXsakxrc2nFcVpZfwxuj/nTh/I9g=="}No npm provenance for this version. Review the tarball diff below, not the repository.
Submitted by @lefos13.
Merging approves this version. The published index keeps pointing at the previous one until then.
Artifact diff
This version has no OVERVIEW.md. The registry requires one to update a listing; the bump cannot merge until the repository adds it.
Inline validation failed. See the Bump workflow log.