Commit Graph

5 Commits

Author SHA1 Message Date
Stefan Broenner b2eab4ca91 Migrate plugins to Agent Plugins 1.0 (#776)
Build plugins from canonical source templates, validate portable manifests and MCP configuration, synchronize complete Agent Skill directories, and scope Excel E2E to runtime-impacting changes.

Tests: 23 targeted SkillGeneration tests passed; Release build completed with 0 warnings and 0 errors; Excel E2E path classification passed for 12 cases; MCPB and Agent Skills packaging passed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Co-authored-by: Stefan Brönner <sbroenne@openclaw.fritz.box>
Copilot-Session: 858e5fa0-f0ef-490f-a154-00c470943904
2026-08-16 10:11:38 +02:00
github-actions[bot] 352b1da895 Revert: remove RELEASE_PAT verification scratch file [skip ci]
Reverts the scratch verification commit; confirms PAT push authentication
and ruleset bypass work end-to-end for the release-automation fix.
2026-07-23 09:40:03 +02:00
github-actions[bot] f1d85698f3 test: verify RELEASE_PAT can push directly to protected main [skip ci]
This is a scratch verification commit for the release-automation fix in
PR #739 (direct changelog push using RELEASE_PAT as a ruleset bypass
actor). It will be reverted immediately by a follow-up commit.
2026-07-23 09:39:47 +02:00
Stefan Broenner 3b54044d39 Ship plugin bootstrap runtime wrappers and packaging validation
## Summary
- Ship bootstrap-only Copilot CLI plugin packages for Excel CLI and MCP runtime launchers.
- Auto-download the latest self-contained Windows runtime on first invocation and refresh through wrapper scripts.
- Keep public skills concise by moving detailed CLI command guidance into references/cli-commands.md.
- Add packaging regressions for plugin bootstrap assets and CLI command reference inclusion.

## Validation
- dotnet test tests\ExcelMcp.SkillGeneration.Tests\ExcelMcp.SkillGeneration.Tests.csproj --filter "FullyQualifiedName~PluginBootstrapBuildTests|Feature=SkillGeneration" --blame-hang-timeout 5m --no-restore

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-27 13:35:17 +02:00
Stefan Broenner cb14f2eb5b Add Copilot CLI plugin publish flow and Squad cleanup (#608)
* chore(squad): plan refinement after rubber-duck review — added Phase -1 spike

- Accept all 4 critical + 4 moderate findings from rubber-duck critique
- User approved Phase -1 spike to validate {pluginDir} placeholder before Phase 0
- Incorporate wrapper script design, GitHub App auth, SHA256 verification
- Answer all 5 open questions (Q1–Q5)
- Document decisions in .squad/decisions.md (merged from inbox, deduplicated)
- Update Kelso agent history with session context
- Created orchestration logs and session log for audit trail

Critical fixes ready for Phase -1 execution:
1. Wrapper script (bin/start-mcp.ps1) for missing-binary detection
2. Phase -1 spike to prove {pluginDir} placeholder works
3. GitHub App replacing PAT in release workflow (Phase 4)
4. SHA256 checksum verification in download.ps1 (Phase 4)
5. Version skew detection (version.txt + wrapper validation)
6. Workflow atomicity (concurrency control, single commit)
7. CLI discovery without agent (skill-driven)
8. Drop non-spec frontmatter fields

Next: Execute Phase -1 spike, await Phase 0 GO/NO-GO decision.

* Add plugin publish pipeline

Add Copilot CLI plugin publish automation and supporting docs for syncing
excel-mcp and excel-cli artifacts to the published plugin repository.

Refs #606

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Update Squad governance and remove workflows

Add Kelso to the Squad roster, save the default GPT-5.4 model preference,
remove unused Squad GitHub workflows, and align the active agent guidance
with workflow-free operation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: Plugin release path audit and documentation sync

Agents: Kelso (Plugin Release), Trejo (Documentation)

## Orchestration

- Kelso: Validated GitHub Copilot CLI plugin publishing workflow; added
  preflight validation; identified PLUGINS_REPO_TOKEN as required secret
- Trejo: Aligned install docs and release strategy with two-plugin flow;
  removed CLI-exclusive wording; clarified plugin support across surfaces

## Changes

### Release Automation
- `.github/workflows/publish-plugins.yml`: Added preflight job that fails
  fast when PLUGINS_REPO_TOKEN is missing (better UX than generic auth error)
- `docs/RELEASE-STRATEGY.md`: Treats plugin publish as required follow-on
  step; added surface-neutral wording for release artifacts

### Documentation Updates
- `README.md`: Two-plugin install flow (marketplace registration + dual install)
- `docs/INSTALLATION.md`: Clarified plugin surface support (Copilot CLI, VS
  Code, Claude); removed CLI-exclusive language
- `gh-pages/index.md`: Updated landing content to reflect multi-surface plugin
  support
- `docs/publish-plugins-setup.md`: Separated artifact publication from
  client-specific install UX

## Decisions Merged

- 2026-04-24: Plugin release preflight and verification (Kelso)
- 2026-04-24: Plugin release wording should be surface-neutral (Kelso)
- 2026-04-24: Plugin install and release sync (Trejo)
- 2026-04-24: Plugin wording must separate concept from install path (Trejo)

## Session Logs

- `.squad/orchestration-log/2026-04-24T10-36-50Z-kelso.md`
- `.squad/orchestration-log/2026-04-24T10-36-50Z-trejo.md`
- `.squad/log/2026-04-24T10-36-50Z-release-plugin-audit.md`

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* chore: revert plugin publish auth from GitHub App to stored PAT

Switches publish-plugins.yml from GitHub App auth (PLUGINS_PUBLISH_APP_ID + PLUGINS_PUBLISH_APP_PRIVATE_KEY) back to a single stored cross-repo token (PLUGINS_REPO_TOKEN) while preserving all operational hardening (preflight gate, sync gate, version guards, manual re-sync path).

WORKFLOW CHANGES:

- Removed GitHub App token minting steps

- Replaced app-id/private-key refs with PLUGINS_REPO_TOKEN secret

- Kept preflight validation (fails fast if token missing/unreachable)

- Kept all guards: downgrade, tag mismatch, duplicate skip, manual override

- Changed commit identity from app bot to github-actions[bot]

DOCS UPDATED:

- publish-plugins-setup.md: PAT setup instructions (removed App sections)

- RELEASE-STRATEGY.md: Updated secrets table, troubleshooting

- INSTALLATION.md: Changed 'GitHub App auth' to 'stored cross-repo PAT'

- README.md: Updated release strategy reference

- gh-pages/index.md: Aligned with README change

- cross-repo-release-preflight SKILL: Generalized patterns for both PAT and App auth

RATIONALE:

Simpler setup (1 secret vs 1 variable + 1 secret), easier rotation, same security posture for this public-repo use case. Keeps iq-core-style operational hardening intact.

* docs: record plugin auth revert decision and learnings

* Scribe: Orchestrate plugin auth revert session (Kelso + Trejo)

- Merged inbox decision: Revert plugin publish auth from GitHub App to stored PAT (PLUGINS_REPO_TOKEN)
- Kelso verified workflow already token-based; coordinated docs revert
- Trejo aligned all user-facing and maintainer docs to simpler PAT model
- Cross-repo-release-preflight skill generalized to document both PAT and App auth patterns
- Updated agent history files with session context and coordination notes
- Decision merged to decisions.md; inbox file deleted

Status: Ready for user to store PLUGINS_REPO_TOKEN secret in repo

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix Copilot plugin marketplace layout

Align the source repo with the two-plugin marketplace model and migrate
published marketplace sync toward the canonical manifest layout.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Stefan Broenner <stefan.broenner@microsoft.comm>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-25 14:38:47 +02:00