Skip to content

Releases: MiguelElGallo/agent-plugin-forge

Agent Plugin Forge 1.0.1

Choose a tag to compare

@MiguelElGallo MiguelElGallo released this 12 Sep 08:27
eba8fc3

Agent Plugin Forge 1.0.1

Two low-severity security fixes:

  • Consistent import approvals (#14): capture safety-checked file bytes and executable modes together, bind the exact file map into the approval hash, and copy/hash those captured bytes. License hashing uses inspected bytes. The issue required concurrent local source changes; this is not a repository-wide concurrency lock.
  • Safe terminal diagnostics (#15): visibly escape terminal controls and undecodable POSIX filename bytes in human-readable output. Ordinary Unicode paths, file contents, and decoded JSON values are preserved. The issue concerned misleading display, not code execution.

Upgrade

Refresh the marketplace and update the Forge plugin, or install the attached Python wheel for the CLI. Verify forge --version reports 1.0.1.

Generate, review, and approve fresh import plans after upgrading. The approval hash now includes the exact source file map, so hashes saved by earlier versions intentionally do not match. Do not replace an approved hash without review.

Verification

Independent patch review completed; its POSIX surrogateescape finding was fixed and regression-tested. On macOS, Python 3.11.16 and 3.12.13 each passed 386 tests with two platform-specific skips and 92% coverage. Ruff, ty, actionlint, Forge validation, strict docs, and isolated wheel checks passed. The packaged skill instructions and bootstrap helper are unchanged from 1.0.0.

All five PR CI jobs passed, including native Windows (368 passed, 20 platform-specific skips, 91% coverage). A Windows metadata incompatibility found during qualification was corrected and independently reviewed before the green run.

PR #16 merged the exact reviewed head with required checks green. The release tree is eba8fc362ccd1b2feef0d6ed5934b5f811f67587. A fresh public Copilot CLI installation enabled plugin 1.0.1 and matched all nine packaged files from that revision. The documentation deployed from the merged commit. These checks qualify installation and CLI behavior; no new VS Code/Codex runtime or full agent publication invocation is claimed.

The attached wheel and source archive are built from the merged release tree and the wheel passed isolated version, branch-name, and repository-validation checks. SHA256SUMS identifies their exact bytes. This release is published to GitHub, not PyPI.

Agent Plugin Forge 1.0.0

Choose a tag to compare

@MiguelElGallo MiguelElGallo released this 12 Sep 06:51
dc48477

Agent Plugin Forge 1.0.0 makes the publication destination an explicit user choice. Asking the installed Forge to publish a skill no longer selects the project's public repository automatically.

  • First use asks where to publish, confirms the exact URL, and can remember one default across projects.
  • Later requests reuse that saved destination and show it in every review plan.
  • One-time overrides preserve the saved default. Replacing a different default requires explicit confirmation.
  • The bootstrap helper stops before cloning when no destination is configured. Invalid settings also stop the operation, and concurrent saves cannot overwrite another client's choice without explicit replacement. Settings replacements are written atomically.
  • The shipped skill, setup and publication guides, private-marketplace guidance, CLI reference, troubleshooting, and release documentation describe the same workflow.

Each publication still follows plan, review, approval, and implementation. A saved destination does not authorize an import, push, pull request, or merge.

Upgrading

Refresh the Forge marketplace, update the installed plugin, verify version 1.0.0, and start a new chat. Your first publication will ask for a destination unless one is already explicitly configured. Automated bootstrap callers must supply --origin, set AGENT_PLUGIN_FORGE_ORIGIN, or save a confirmed default; there is no built-in repository fallback.

Upgrade instructions · Publication workflow · Saved destination settings

Validation

The local suite passed 288 tests on Python 3.11.16 and 3.12.13, with two platform-specific skips per run and 92% coverage. Ruff, formatting, ty, Forge validation, generation drift checks, skill validation, actionlint, and the strict documentation build passed. The real CLI tutorial covers a remembered destination through review, approved apply, generation, and validation.

The wheel installed into a fresh environment and passed version, branch-name, and repository validation commands. A local Copilot CLI 1.0.84-1 configuration loaded the 1.0.0 plugin and its skill. The benchmark workflow smoke test used isolated destination settings.

After the protected merge, a fresh public marketplace installation in Copilot CLI 1.0.84-1 installed version 1.0.0 with one skill. All nine installed package files and executable modes matched the merged source. The installed helper refused an unset destination, reused a remembered destination from another project, preserved the default during a one-time override, and refused an unconfirmed replacement. These are client installation and deterministic helper checks; they do not claim a full agent publication invocation. The deployed upgrade, publication, compatibility, and CLI documentation was read back successfully.

Published from PR #13 after quality and the Linux, macOS, Windows, and Python 3.11 CI checks passed. Exact client and historical qualification boundaries are in the compatibility evidence.

Artifacts

The wheel and source distribution provide the Python Forge CLI. Install the Forge plugin through the Git marketplace using the client installation instructions. Verify downloaded archives against the attached SHA256SUMS.

Agent Plugin Forge 0.3.0

Choose a tag to compare

@MiguelElGallo MiguelElGallo released this 12 Sep 04:51
2a97c34

Agent Plugin Forge 0.3.0

This release improves generation recovery and the day-to-day workflow for maintaining a shared skill marketplace.

  • Preserve recovery files when marketplace rollback cannot complete, and continue restoring unaffected outputs.
  • Validate both sides of renames and handle Git filenames without losing Unicode, whitespace, or control characters.
  • Add forge --version and align Python, plugin, catalog, and lockfile version checks.
  • Let ordinary skill additions and updates pass renderer tests without editing golden snapshots.
  • Clarify check-only requests, multiple skill additions, and existing-skill maintenance in the shipped Forge skill.
  • Add a tested provenance preview, team maintenance guidance, reproducible benchmarks, and dated client acceptance evidence.
  • Update Python libraries and development tools, including the pytest-cov subprocess coverage migration.

Local validation passed 257 tests on Python 3.11 and 3.12 with 92% coverage. Private client acceptance installed and invoked four new skills across three plugins, then updated one plugin while the others remained unchanged. These observations do not certify every client or host; see the compatibility documentation for precise boundaries.

Published from the reviewed PR #12 after all required Linux, macOS, Windows, and quality checks passed. The source and wheel archives are attached below.

Install

copilot plugin marketplace add MiguelElGallo/agent-plugin-forge
copilot plugin install agent-plugin-forge@agent-plugin-forge

For an existing installation, refresh the marketplace and run copilot plugin update agent-plugin-forge@agent-plugin-forge.

Installation documentation · Team maintenance guide

Fresh public acceptance

GitHub Copilot CLI 1.0.84-1 installed agent-plugin-forge version 0.3.0 from the public marketplace in an isolated configuration. All nine package files matched merged commit 2a97c34889aa9fa035b6e1397e799df491cb7562. The installed package-agent-skill ran its check-only workflow on a fresh checkout: generation drift and package validation passed, with no file or branch changes. Documentation deployment and all five post-merge CI jobs passed.