Skip to content

refactor(plugin)!: rename the ticker plugin to stocks - #326

Merged
ralyodio merged 1 commit into
mainfrom
rename-plugin-to-stocks
Aug 8, 2026
Merged

refactor(plugin)!: rename the ticker plugin to stocks#326
ralyodio merged 1 commit into
mainfrom
rename-plugin-to-stocks

Conversation

@ralyodio

@ralyodio ralyodio commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

BREAKING CHANGE: ticker@moshcode is no longer published. The plugin is stocks@moshcode, shipping the same six commands from plugins/stocks/.

v0.28.0 renamed the verb but deliberately left the plugin id alone, to spare existing installs an uninstall/reinstall. That left ticker@moshcode serving a command called /stocks — the kind of mismatch that reads as a bug. Finishing the rename costs one migration; not finishing it costs an explanation forever.

The migration is the part worth getting right

A renamed plugin is not a renamed command. The old one is still installed in someone's engine, still serving /stocks, and installing the new one puts a second copy beside it rather than over it — so /stocks would resolve to two plugins at once.

So the old id stays reachable by remove while being refused by install:

$ moshcode plugin install ticker
✗ "ticker" is now "stocks" — install stocks@moshcode
· already have the old one? moshcode plugin remove ticker first

$ moshcode plugin remove ticker
# still plans: claude plugin uninstall ticker@moshcode

RETIRED_PLUGINS in src/plugins.mjs records the rename and resolveRetiredPlugin reads it. A test asserts the asymmetry in both directions — that a retired name never resolves for install, and that it points at a plugin the marketplace actually ships. Without that last check the table could name a replacement that doesn't exist and nothing would notice until someone followed the advice.

Both READMEs carry the two-line migration, since anyone who installed before today needs it and will look there first.

Verification

  • Full suite: 1387 tests, 0 failures (one new test for the retired-plugin path).
  • Ran live: moshcode plugin list (now shows stocks@moshcode), plugin install ticker (refuses with the pointer), plugin install nonsense (unchanged error).
  • Verified plugin remove ticker plans claude plugin uninstall ticker@moshcode by inspecting the plan rather than executing it — running it for real would have uninstalled a plugin on my machine, which is not this PR's business.

🤖 Generated with Claude Code

BREAKING CHANGE: `ticker@moshcode` is no longer published. The plugin is
`stocks@moshcode`, shipping the same six commands from plugins/stocks/.

v0.28.0 renamed the verb but deliberately left the plugin id alone, to spare
existing installs an uninstall/reinstall. That left `ticker@moshcode` serving a
command called `/stocks`, which is the kind of mismatch that reads as a bug.
Finishing the rename costs one migration; not finishing it costs an explanation
forever.

The migration is the part worth getting right. A renamed *plugin* is not a
renamed command: the old one is still installed in someone's engine, still
serving `/stocks`, and installing the new one puts a second copy beside it
rather than over it — so `/stocks` would resolve to two plugins at once. The old
id therefore has to stay reachable by `remove` while being refused by `install`:

  $ moshcode plugin install ticker
  ✗ "ticker" is now "stocks" — install stocks@moshcode
  · already have the old one? moshcode plugin remove ticker first

  $ moshcode plugin remove ticker      # still plans: claude plugin uninstall ticker@moshcode

RETIRED_PLUGINS in src/plugins.mjs records the rename, resolveRetiredPlugin
reads it, and a test asserts the asymmetry in both directions — that a retired
name never resolves for install, and that it points at a plugin the marketplace
actually ships. Without that last check the table could name a replacement that
does not exist and nothing would notice until someone followed the advice.

Both READMEs carry the two-line migration, since anyone who installed before
today needs it and will look there first.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

91 finding(s)

HIGH/CRITICAL: 2 | MEDIUM: 41 | LOW: 48

Severity Rule Location
HIGH manifest-typosquat apps/pwa/package.json:19
HIGH js-ssrf-outbound-request apps/pwa/public/sw.js:45
MEDIUM tls-verification-disabled apps/pwa/src/lib/moshpit-gateway.mjs:299
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:61
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:75
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:101
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:265
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:269
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:314
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:499
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:675
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:677
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:736
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:782
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:852
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:955
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:1063
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:1199
MEDIUM js-unescaped-html-sink apps/pwa/src/routes/moshpit.mjs:1419
MEDIUM js-dynamic-code-execution apps/pwa/test/apikey-mask.test.mjs:129
MEDIUM sql-template-interpolation apps/pwa/test/credits-webhook-event-match.test.mjs:111
MEDIUM sql-template-interpolation apps/pwa/test/credits-webhook-event-match.test.mjs:131
MEDIUM sql-template-interpolation apps/pwa/test/moshpit-terms.test.mjs:192
MEDIUM sql-template-interpolation src/dns.mjs:2439
MEDIUM sql-template-interpolation src/selfupdate.mjs:166
MEDIUM sql-template-interpolation src/selfupdate.mjs:170
MEDIUM sql-template-interpolation src/selfupdate.mjs:208
MEDIUM sql-template-interpolation src/selfupdate.mjs:209
MEDIUM insecure-temp-file test/dns-disable-restore.test.mjs:93
MEDIUM insecure-temp-file test/dns-disable-restore.test.mjs:310
MEDIUM insecure-temp-file test/plugins.test.mjs:110
MEDIUM insecure-temp-file test/pty.test.mjs:28
MEDIUM insecure-temp-file test/pty.test.mjs:31
MEDIUM insecure-temp-file test/pty.test.mjs:40
MEDIUM insecure-temp-file test/pty.test.mjs:42
MEDIUM insecure-temp-file test/pty.test.mjs:47
MEDIUM insecure-temp-file test/pty.test.mjs:48
MEDIUM insecure-temp-file test/pty.test.mjs:49
MEDIUM insecure-temp-file test/tabs.test.mjs:8
MEDIUM insecure-temp-file test/tabs.test.mjs:13
MEDIUM insecure-temp-file test/tabs.test.mjs:14
MEDIUM insecure-temp-file test/tabs.test.mjs:22
MEDIUM insecure-temp-file test/trust.test.mjs:240
LOW secret-generic-credential apps/pwa/test/apikey-bearer-scheme.test.mjs:30
LOW secret-generic-credential apps/pwa/test/apikey-mask.test.mjs:38
LOW secret-generic-credential apps/pwa/test/apikey-reveal.test.mjs:35
LOW secret-generic-credential apps/pwa/test/approvals-context.test.mjs:28
LOW secret-generic-credential apps/pwa/test/approvals-credits.test.mjs:28
LOW secret-generic-credential apps/pwa/test/approvals-notify.test.mjs:26
LOW secret-generic-credential apps/pwa/test/approvals-resolve-race.test.mjs:20

…and 41 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit b526358 into main Aug 8, 2026
4 checks passed
@ralyodio ralyodio mentioned this pull request Aug 8, 2026
ralyodio added a commit that referenced this pull request Aug 8, 2026
Bump to v0.29.0, releasing the rename of the `ticker` plugin to `stocks` (#326).

Breaking, and the second in a row: `ticker@moshcode` is no longer published.
The plugin is `stocks@moshcode`, shipping the same six commands.

v0.28.0 renamed the verb and left the plugin id alone on purpose, to spare
existing installs a migration. That left `ticker@moshcode` serving a command
called `/stocks`, so this finishes the job — one migration now instead of an
explanation forever.

Anyone who installed the old plugin needs both halves, because engines install
plugins side by side rather than over each other:

  moshcode plugin remove ticker
  moshcode plugin install stocks

`plugin remove ticker` keeps working for exactly that reason, even though
`plugin install ticker` now refuses and points at the new id. The README
migration note added in #326 names this version, so it is accurate as of this
commit and not before.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@ralyodio
ralyodio deleted the rename-plugin-to-stocks branch August 8, 2026 17:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant