Repository navigation
Bump omercnet/omp to 1.3.2 - #199
github-actions[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
OMP 1.3.2 remains unpublished because its runtime dependency installation is not locked. Your shipped OVERVIEW.md completes the listing page; no overview-only release is needed.
Please publish a new version with npm-shrinkwrap.json at the package root, locking all runtime dependencies and their transitive tree with resolved sources and integrity. For the npm artifact, remove the catalog preparation command from paseo-plugin.json, or change it to consume the shipped lockfile without --no-package-lock or floating installs. Then update this PR’s artifact pin. The current package has no lockfile, declares yaml: "^2.9.0", and its preparation script can run another unlocked npm install when it finds an ancestor catalog. See REVIEW.md’s packaging requirement and the publishing guide’s build guidance.
Optional next release: mention that archived history can now open read-only after its workspace is removed, so users understand when OMP will run and when it only reads transcripts.
Review data
- Reviewed head:
5dd5e3fe8687ec4e38d80506a1a3864d850d59b6. REVIEW.md blob:7268134d240de9e474c52480f4937af4e369a6e2. - npm
@omercnet/paseo-omp@1.2.0→1.3.2. Both pinned tarballs downloaded, SHA-512 matched records and npm metadata, archive paths/types checked before extraction. New integrity:sha512-WnW5siuFtdOqgXcBtzri5Zc1ZQCS/qOCU6ZSukLoy3G6waKS86yjhzwOVlNfqv2TXLDeYDHIrtk9EqbUqicV8w==. Provenance backs registry commit45b6656c5963468b10d41206e4386eabf528db23; existing ownership/submitter unchanged. - 97 old and 100 new files; complete independent 941-line diff inspected. Changes include author overview, quota/tool-boundary text, larger bounded model catalog responses, updated SDK dependency, and history-only session handling. New history path checks persisted replay and host-derived purpose, authorizes the native ID and recorded cwd, reads the transcript, and rejects prompt/configure/revert/browser operations. Interactive launches strip the reserved marker (
server/provider/session-purpose.ts,session-history.ts,connection.ts,config-normalization.ts); authorization uses the existing exact session/cwd lookup (session.ts:214-232). - Runtime dependencies: protocol 0.11.1, MCP SDK 1.30.0, yaml ^2.9.0. No lockfile or bundled installed tree is shipped. Manifest invokes
node scripts/prepare-dependencies.mjs; full invoked script read. Its ancestor catalog search (:8-16) conditionally stages package.json and invokesnpm install --omit=dev --ignore-scripts --no-package-lock --workspaces=false(:19-50). It otherwise returns without installing. This script is unchanged; the runtime tree was already unlocked in 1.2.0. No package install lifecycle hooks. - Existing purposeful OMP/MCP process launches, settings/transcript/quota reads, settings edits and provider environment handling remain. The changed history path does not spawn OMP or connect MCP; it reads authorized history. No new unrelated outbound destination was found in the delta. Full dependency internals and the eventual installed tree remain uninspected because that tree is not fixed; no security approval is claimed.
- Shipped overview takes precedence and fallback deletion is correct. No bot registry edits needed. Trusted current-main online validation passes, including existing listing media URL checks, but does not enforce dependency locking. Prior PR #161’s packaging discussion was read; this is an author-fixable packaging requirement under current policy, without a new maintainer safety decision.
- No plugin/dependency code installed, built or run. Live provider sessions were not exercised. No linked submission issue or author discussion was found.
omercnet/omp: {"kind":"npm","package":"@omercnet/paseo-omp","version":"1.2.0","resolved":"https://registry.npmjs.org/@omercnet/paseo-omp/-/paseo-omp-1.2.0.tgz","integrity":"sha512-ueZede5D34hoNrdF4y6DBaomErA+hHcv+bcz0Sd6eArQKqF8L6ecKXdBe2tEZd3Ev8uQwxMHuiDQhMBx3q6gOw=="} -> {"kind":"npm","package":"@omercnet/paseo-omp","version":"1.3.2","resolved":"https://registry.npmjs.org/@omercnet/paseo-omp/-/paseo-omp-1.3.2.tgz","integrity":"sha512-WnW5siuFtdOqgXcBtzri5Zc1ZQCS/qOCU6ZSukLoy3G6waKS86yjhzwOVlNfqv2TXLDeYDHIrtk9EqbUqicV8w=="}Provenance verified: built from https://github.com/omercnet/paseo-plugins/tree/HEAD/paseo-omp at
45b6656c5963468b10d41206e4386eabf528db23.Submitted by @omercnet.
Merging approves this version. The published index keeps pointing at the previous one until then.
Artifact diff
This version ships OVERVIEW.md, so the registry's copy is removed in this bump.
Inline validation passed:
npm testand the checks fromnode scripts/validate.ts --online --changed. The default GITHUB_TOKEN does not trigger the PR validation workflow.