Commit Graph

5 Commits

Author SHA1 Message Date
DimoHG eba2af2c64 fix(cursor): add path traversal checks and require per-plugin manifest
Address two issues flagged in PR review:

1. Validate pluginRoot and source with isSafeRelativePath before using
   them in path.resolve. Without this, absolute paths or .. traversals
   in marketplace.json would pass validation silently.

2. Error when the per-plugin .cursor-plugin/plugin.json is missing
   instead of silently skipping it. A missing manifest would prevent
   the plugin from loading, so the validator should catch it.

Made-with: Cursor
2026-03-10 13:27:23 +02:00
DimoHG 772c79e73b feat(cursor): update validator to support marketplace.json
The pre-commit validator previously required a root plugin.json and
would fail when only marketplace.json was present.

Refactor the validator to check for marketplace.json first, falling
back to root plugin.json for single-plugin repos. For marketplace
repos, validate the marketplace manifest (name, owner, plugins array),
resolve each plugin directory using pluginRoot + source, and validate
per-plugin manifests with paths relative to the plugin directory.

Made-with: Cursor
2026-03-10 13:19:57 +02:00
Benoit Dion 10f147965a fix(cursor): consolidate to single root plugin manifest 2026-02-26 20:35:40 +01:00
Phil 925b65ef80 chore: sync marketplace review updates and cursor validation
Apply Claude PR review follow-ups, align owner/email metadata for Cursor, add dedicated Cursor validator checks, and wire validate scripts in CI/package scripts.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-02-20 15:41:20 -05:00
Philip Laussermair 06812f52f5 Add Cursor plugin marketplace support 2026-02-20 15:40:59 -05:00