Repository navigation
chore: address plugin scanner lint findings - #12
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4f9217c38d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "uninstall:codex": "node scripts/installer-cli.mjs uninstall", | ||
| "update:codex": "node scripts/installer-cli.mjs update" | ||
| "update:codex": "node scripts/installer-cli.mjs update", | ||
| "version": "npm run sync:plugin-version && npm run check:version-sync" |
There was a problem hiding this comment.
Stage synced plugin.json during npm version
The new version lifecycle script syncs .codex-plugin/plugin.json but never stages that change, so npm version will create a tag/commit without the synced plugin file. npm’s own npm-version command docs state that files generated in version scripts must be explicitly added (e.g., via git add) before the commit step, and without that this leaves a dirty working tree and can publish or push a commit where package.json and plugin metadata diverge.
Useful? React with 👍 / 👎.
|
|
||
| describe("version sync", () => { | ||
| it("asserts the live repo versions match", () => { | ||
| assert.equal(assertVersionsMatch(), "1.0.0"); |
There was a problem hiding this comment.
Remove hardcoded release version from version-sync test
This assertion hardcodes the repository version to 1.0.0, which makes normal version bumps fail test runs even when package.json and .codex-plugin/plugin.json are correctly synchronized. That introduces avoidable CI/release friction because every future release now requires manually editing this test instead of validating version equality dynamically.
Useful? React with 👍 / 👎.
Summary
Address the remaining
codex-plugin-scanner lintfindings so the plugin package is cleaner for marketplace/release distribution.Changes
SECURITY.md.codexignorefor local-only filesVerification
pipx run codex-plugin-scanner lint .pipx run codex-plugin-scanner verify .YAML.load_file