Initial Arka plugin registry: Official plugins mirror + Arka-signed index

11 plugins from github.com/librefang/librefang-registry plugins/.
index.json / index.json.sig are signed with Arka's Ed25519 key
(not upstream stats.librefang.ai). Private key is not in this repo.
This commit is contained in:
ixoblakp committed 2026-09-01 10:22:07 +03:00
commit 8dec8f6038
62 files changed
+5189

No files matched your search

+33
View File
@@ -0,0 +1,33 @@
# Arka plugin registry
Hosted at **https://git.arka-ai.ru/arka/plugin-registry**.
This is Arka’s plugin marketplace registry: browse via Gitea Contents API,
install gated on a **signed** `index.json` (not `stats.librefang.ai`).
Plugin code is a mirror of Official
[`librefang/librefang-registry`](https://github.com/librefang/librefang-registry)
`plugins/` (MIT). The **index signature is Arka’s**, not upstream’s.
| File | Role |
| --- | --- |
| `plugins/<name>/` | Plugin tree (`plugin.toml` + hooks) |
| `index.json` | Signed membership list (what Agent Arka forge-host fetches) |
| `index.json.sig` | Ed25519 signature over the exact bytes of `index.json` |
| `plugins-index.json` | Same bytes as `index.json` (upstream filename, convenience) |
## Trust
- Public key (base64 32-byte Ed25519): see `PUBKEY` in this repo.
- Daemon: `LIBREFANG_REGISTRY_PUBKEY=<that value>`. Do **not** set `LIBREFANG_REGISTRY_VERIFY=0` in production.
- Private key is **not** in git. Re-sign after every plugin add/remove:
```bash
bash /path/to/sign-plugin-index.sh index.json ~/.arka-registry-keys/privkey.pem
cp index.json plugins-index.json
cp index.json.sig plugins-index.json.sig
```
Anonymous raw (no token):
`https://git.arka-ai.ru/arka/plugin-registry/raw/branch/main/index.json`