Skip to content

GitHub Action v1.0.2

Latest

Choose a tag to compare

@fxjim fxjim released this 25 Jul 02:03
· 7 commits to main since this release

GitHub Action v1.0.2

Agent Commerce Guard now puts package proof and the authorized Base MCP purchase handoff directly in every completed Action run.

Use The Stable Major Ref

- uses: fxjim/agent-commerce-guard@v1
  with:
    manifest: agent-commerce-actions.json
    fail-on: deny

New In v1.0.2

  • Adds sample-report-url for the full pre-purchase CLI report.
  • Adds package-metadata-url for the machine-readable 13-file package inventory.
  • Adds base-mcp-recipe-url for an authorized Base MCP assistant.
  • Puts the sample report and inventory before purchase links in the GitHub job summary.
  • Keeps checkout-url and x402-evaluate-url unchanged.

GitHub-hosted smoke run

Both stable tags point to the tested Action source:

  • v1 -> 26203637f50040aa46c56134b5d806df28603152
  • v1.0.2 -> 26203637f50040aa46c56134b5d806df28603152

Inspect Before Buying

Purchase Routes

The paid tarball is unchanged: SHA-1 c67fb09bd83da591c58ae5fae002a6a59557fc97, 122737 bytes. Payment completion is recognized only from qualifying onchain Base USDC transfer evidence or the live verifier.

The hosted evaluator receives the submitted manifest. Do not send secrets, private source, credentials, or sensitive customer data. Use the paid local package for private manifests.