Commit Graph
13 Commits
Author SHA1 Message Date
Evan Hu 74745f1f20 ci: sign plugins-index.json in-repo, drop worker signing dependency
Pair with the worker-side simplification on the librefang PR — the
worker is now a pure transport (no key material, no signing) and this
repo's CI takes over signature production.

scripts/sign-plugins-index.mjs reads REGISTRY_PRIVATE_KEY from a GitHub
Actions secret, signs plugins-index.json with Ed25519, and writes
plugins-index.json.sig alongside it. Aborts loudly when the secret is
missing so a misconfigured CI can't silently ship an unsigned payload.

The workflow now runs build → sign → commit (.json + .sig) → push →
poke worker /refresh. The worker fetches the committed .json + .sig
verbatim and stores both — the daemon then verifies against the
embedded pubkey it ships with.

Closes PR review CRITICAL #1: the worker is no longer a sign-anything
oracle reachable via REGISTRY_REFRESH_TOKEN. Trust root is now this
repo's branch protection + Actions secret scope, not a token any CI
job that can talk to stats.librefang.ai can use to mint signatures.

Note: the keypair was rotated as part of this change (PR not yet
merged so no daemon TOFU pins exist). New pubkey:
  ClGa0Ucap8NdrKAy1rw9Tt6A9I8eg4zJ53+xIuKMuq0=
The plugins-index.json.sig committed here is signed with the matching
new private key, in lockstep with the daemon EMBEDDED_REGISTRY_PUBKEY
constant and all three worker [vars] entries.
2026-05-05 01:02:58 +09:00
Evan Hu ff6f3f2b25 ci: build registry-index.json in-repo for dashboard real-time updates
Pair with the existing plugins-index.json path (which feeds the
daemon's signed install lane). registry-index.json mirrors the
dict-shaped payload the registry-worker's cron currently builds via
40+ GitHub Contents API calls — but built locally from the checked-out
tree by scripts/build-registry-index.mjs, so the worker only fetches
ONE file per category type (2 total: plugins + registry) on refresh.

Workflow now picks up content changes across all 8 category dirs
(was: plugins/ only) so dashboard updates land within seconds of a
push instead of waiting for the 02:00 UTC cron tick.

The dashboard's /api/registry endpoint reads kv_store('registry_data');
the worker's forced-refresh now writes that key with these bytes and
purges the Cache-API entry, so the next dashboard hit sees fresh
data instead of the 1h-cached previous payload.

Generated counts on first build: 11p 17h 32a 60s 44c 57pr 22w 33mcp.
2026-05-05 00:43:30 +09:00
Evan Hu f9821d5867 ci: build plugins-index.json in-repo so worker refresh stays under budget
Walking ~40+ plugin TOMLs via the GitHub Contents API from the worker
exceeded the Workers Free 50-subrequest-per-invocation limit, leaving
the daemon's signed plugins index either empty or partial after every
forced refresh.

Move the walk into the repo: scripts/build-plugins-index.mjs reads each
plugins/<name>/plugin.toml directly from the checked-out tree and emits
a sorted flat array (name, version?, description?, needs?) at
plugins-index.json. The CI workflow regenerates and commits this file
on every push under plugins/, then pokes the worker's
/api/registry/refresh — which now fetches the single committed
plugins-index.json (1 subrequest), validates the JSON shape, and
re-signs it with Ed25519. Refresh cost is now constant in registry
size, not linear.

The dashboard's dict-shaped /api/registry payload is unchanged — that
still rebuilds via the daily 02:00 UTC cron.
2026-05-05 00:37:50 +09:00
Evan Hu 14a576671d ci: trigger registry-worker refresh on push to main
Without this, dashboard / daemon see content changes only after the
next 02:00 UTC cron tick (up to ~24h delay). The action POSTs to
stats.librefang.ai/api/registry/refresh with a bearer token shared
with the worker secret of the same name; until both secrets exist on
their respective sides, the endpoint returns 503 and the action fails
loud — no silent half-deploy.

Filters on directories the worker actually reads (plugins/, agents/,
skills/, hands/, channels/, providers/, workflows/, mcp/) so README
edits don't burn worker invocations.

Known limitation: the worker rebuild walks ~40+ GitHub Contents API
subrequests, which on Workers Free truncates partway through and
leaves some categories empty. This action fires the right path; the
underlying budget fix (Workers Paid, or pre-building the index in
this repo) is tracked separately.
2026-05-05 00:35:04 +09:00
Evan f23af64eea fix: download taplo 0.10.0 directly instead of using broken action (#35) 2026-03-31 23:41:44 +08:00
Evan 78960471cc fix: use uncenter/setup-taplo action with latest version (#33)
* fix: add shell execution rules to collector hand system prompt

* fix: use latest taplo instead of hardcoded version

* fix: use uncenter/setup-taplo action with latest version
2026-03-31 23:31:37 +08:00
Evan fc37ce253b fix: correct invalid tier "free" and teams-mcp id with version (#29)
- Replace tier "free" with "fast" (valid tiers: frontier/smart/balanced/fast/local)
- Remove version suffix from teams-mcp integration id field
- Update sync-pricing.py to not generate invalid tier values
2026-03-25 23:49:39 +09:00
Evan 553ecc6947 feat: add pricing sync script and update model prices from OpenRouter (#27)
* fix: pin npm package versions in MCP integration templates

Prevent supply chain attacks by pinning exact versions instead of
using unpinned `npx -y @package` which pulls latest on every run.

23 of 25 integrations pinned. sqlite-mcp and aws skipped (packages
not found on npm registry).

* fix: use stable azure/mcp version instead of beta

* feat: add pricing sync script and update model prices from OpenRouter API

- scripts/sync-pricing.py fetches real-time pricing from OpenRouter
- Updated 64 price fields across 13 provider files
- Run periodically or in CI to keep prices current
2026-03-25 23:43:13 +09:00
Evan Hu 994b60c0d9 fix(ci): pin taplo version and fix glob pattern in format check 2026-03-21 02:48:31 +09:00
Evan Hu a8b7c9d08b feat: comprehensive registry improvements
Community docs:
- CODE_OF_CONDUCT.md (Contributor Covenant v2.1)
- SECURITY.md (vulnerability reporting policy)
- CHANGELOG.md (initial release notes)
- CODEOWNERS (per-type review ownership)

GitHub config:
- Issue templates: bug-report, pricing-correction, documentation
- FUNDING.yml (GitHub Sponsors)

Validation enhancements:
- Cross-reference check: hand [[requires]] → integration existence
- Routing alias collisions as warnings (errors with --strict)
- --strict flag to promote warnings to errors
- --type filter to validate single content type
- CI: add taplo format check and lychee link check jobs

Developer experience:
- Makefile with validate, fmt, and scaffold targets
- Scaffold templates for all 5 content types
- .pre-commit-config.yaml (trailing whitespace, TOML check, validate)
- docs/content-guide.md (naming, descriptions, prompts, decision guide)

Content quality:
- schema.toml: add last_verified field for model pricing
- CONTRIBUTING.md: add pricing verification guide with source links
2026-03-21 02:46:04 +09:00
Evan Hu 1f3ef406ee docs: rewrite README and CONTRIBUTING for full registry scope
- README now covers all 5 content types (agents, hands, integrations, skills, providers)
- CONTRIBUTING has per-type instructions and checklists
- validate.py expanded to validate agents, hands, integrations, and skills
- PR template covers all content types
- Added new-content.yml issue template for non-model contributions
- CI workflow updated to Python 3.12
2026-03-21 02:10:12 +09:00
Evan 21f59f0ab8 ci: upgrade to Node.js 24 compatible action versions 2026-03-14 11:58:15 +09:00
Evan a8b180ac95 ci: add GitHub Actions workflow for catalog validation 2026-03-14 11:57:24 +09:00