Files
tobin df21fbd390 Adopt validate-plugins action suite; pin all external SHAs
Adds the shared composite actions (validate / bump / scan) and pins
the 2 external entries that were missing a SHA (figma,
adobe-for-creativity).

Workflows:
- validate-plugins.yml: invariants I1-I11 + claude plugin validate +
  diff-gated clone-at-SHA validation. SHA-pin (I5) is a hard error.
  I1 stays warn (entries are intentionally category-grouped).
- bump-plugin-shas.yml: bot-free weekly refresh.
- scan-plugins.yml: Claude policy scan with the tightened
  hook-scope/telemetry/disclosure rubric. Blocking.

Policy prompt at .github/policy/ uses the same tightened rubric as
the official marketplace (hook scope, undisclosed telemetry,
description-vs-behavior).
2026-05-08 03:04:32 +00:00
..