forked from bchanot/claude
Full pull per user verdict (human review of #2047 gbrowser stealth done, accepted) — motivated by the #1911 fail-open fix for 4 security guards (careful, guard, freeze, data-loss) plus PII/secrets redaction (#1797), telemetry-consent + cache sanitization (#1848). Gate: make test 90/0 green after bump; re-ran link.sh (symlinks already current) + gstack ./setup (browse binary rebuilt); smoked /careful and /freeze (guard's constituents) via direct JSON-payload invocation (job4 §2.3 idiom) — both confirmed blocking a trivial case (rm -rf, edit outside freeze boundary) that must be blocked. Local playwright pin (BDR-029/BLK-008, ubuntu26.04 Chromium support) was reset by the submodule checkout as designed, then re-applied via gstack_bump_playwright_if_unsupported's own steps (bun install, detect unsupported, bun add playwright@latest — 1.58.2→1.61.1, one minor ahead of the pre-bump local patch). Original local diff backed up before discarding: scratchpad/gstack-local-playwright-fix-070722a.patch. plugins.lock.json note updated with the pinned SHA and rationale. Rollback if needed: git -C skills-external/gstack checkout 070722a && git add skills-external/gstack && link.sh re-run.
47 lines
3.3 KiB
JSON
47 lines
3.3 KiB
JSON
{
|
|
"_readme": "Pinned versions for reproducible installs. Update versions deliberately, then run install-plugins.sh.",
|
|
"rtk": {
|
|
"source": "https://github.com/rtk-ai/rtk",
|
|
"version": "latest",
|
|
"note": "Check latest at https://github.com/rtk-ai/rtk/releases before updating"
|
|
},
|
|
"gsd": {
|
|
"source": "npm:gsd-pi",
|
|
"version": "3.0.0",
|
|
"note": "Check latest at https://www.npmjs.com/package/gsd-pi before updating. GSD is a standalone CLI (Pi SDK), not a Claude Code plugin. Run 'gsd' in terminal, not '/gsd' in Claude Code. ADR-013 cutover (3.0.0): DB is authoritative, .gsd/ROADMAP.md no longer exists — read state via 'gsd headless query' (see agents/status-reporter.md PHASE 3), not markdown scraping. NOTE: update-all.sh honors this pin — 'make update' will NOT advance gsd past it; bump this version deliberately, then re-run."
|
|
},
|
|
"gstack": {
|
|
"source": "https://github.com/garrytan/gstack.git",
|
|
"managed_by": "git submodule",
|
|
"note": "Version controlled by submodule pointer in .gitmodules. Update: git submodule update --remote. Pinned at 11de390 (v1.58.5.0, job6): pulled deliberately for the #1911 fail-open security-guard fix (careful/guard/freeze/data-loss guards) after human review of #2047 (gbrowser stealth, accepted). Local playwright bump (BDR-029, BLK-008) is reset by every submodule update and re-applied by install-plugins.sh's gstack_bump_playwright_if_unsupported()."
|
|
},
|
|
"ctx7": {
|
|
"source": "npm:ctx7",
|
|
"version": "latest",
|
|
"note": "Context7 CLI — doc lookup for fast-evolving libs. Standalone CLI, not an MCP server. Install: npm install -g ctx7. Standalone: ctx7 docs /vercel/next.js \"middleware\"."
|
|
},
|
|
"graphifyy": {
|
|
"source": "pypi:graphifyy",
|
|
"version": "latest",
|
|
"managed_by": "pipx",
|
|
"note": "Codebase knowledge graph. CLI is 'graphify'. Install: pipx install graphifyy && graphify install && graphify claude install. Adds PreToolUse hook for Glob/Grep."
|
|
},
|
|
"semgrep": {
|
|
"source": "pypi:semgrep",
|
|
"version": "1.168.0",
|
|
"managed_by": "pipx",
|
|
"note": "SAST engine for the security gate (security-auditor agent, onboard cso fallback, audit-delta). Rulesets pinned in-agent: p/security-audit + p/secrets (never --config auto). BLOCKING gate -> pin honored by update-all.sh: 'make update' will NOT advance semgrep past it; bump deliberately (new rules = new BLOCKs on unchanged code). Never run 'semgrep login' automatically (Pro rules are optional, guide-only)."
|
|
},
|
|
"emil-design-eng": {
|
|
"source": "https://github.com/emilkowalski/skill",
|
|
"path": "skills/emil-design-eng/SKILL.md",
|
|
"managed_by": "curl",
|
|
"note": "Emil Kowalski's design engineering skill — UI polish, animations, component craft. Downloaded to skills-external/emil-design-eng/, symlinked by link.sh."
|
|
},
|
|
"impeccable": {
|
|
"source": "npm:impeccable",
|
|
"version": "3.2.0",
|
|
"note": "Design anti-pattern detector (45 deterministic rules, CLI 'impeccable detect', exit 0/2) + /impeccable skill (23 verbs) by pbakaus. Pin = CLI version; the skill dist has its own release track fetched by 'skills install'. Pinned for audit reproducibility (LRN-077 class: a rules update silently changes audit output). Requires Node >= 24 — install step skips gracefully below that. Machine-owned: synced to skills-external/impeccable/ (gitignored), symlinked by link.sh."
|
|
}
|
|
}
|