Files
anthropics__knowledge-work-…/.github/workflows/validate-plugins.yml
tobin df21fbd390 Adopt validate-plugins action suite; pin all external SHAs
Adds the shared composite actions (validate / bump / scan) and pins
the 2 external entries that were missing a SHA (figma,
adobe-for-creativity).

Workflows:
- validate-plugins.yml: invariants I1-I11 + claude plugin validate +
  diff-gated clone-at-SHA validation. SHA-pin (I5) is a hard error.
  I1 stays warn (entries are intentionally category-grouped).
- bump-plugin-shas.yml: bot-free weekly refresh.
- scan-plugins.yml: Claude policy scan with the tightened
  hook-scope/telemetry/disclosure rubric. Blocking.

Policy prompt at .github/policy/ uses the same tightened rubric as
the official marketplace (hook scope, undisclosed telemetry,
description-vs-behavior).
2026-05-08 03:04:32 +00:00

35 lines
859 B
YAML

name: Validate Plugins
on:
pull_request:
paths:
- '.claude-plugin/**'
- '*/.claude-plugin/**'
- '*/agents/**'
- '*/skills/**'
- '*/commands/**'
- 'partner-built/**'
push:
branches: [main]
paths:
- '.claude-plugin/**'
permissions:
contents: read
jobs:
validate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: anthropics/claude-plugins-community/.github/actions/validate-plugins@706952a0caebac4024b4be25137ff2faa64e153b
with:
marketplace-path: .claude-plugin/marketplace.json
# Curated marketplace: SHA-pin (I5) is a HARD error.
# I1 (sort) stays warn — entries are intentionally category-grouped.
warn-invariants: "I1 I3 I8 I11"
claude-cli-version: latest