Files
plugin-registry/README.md
T
ixoblakp 8dec8f6038 Initial Arka plugin registry: Official plugins mirror + Arka-signed index
11 plugins from github.com/librefang/librefang-registry plugins/.
index.json / index.json.sig are signed with Arka's Ed25519 key
(not upstream stats.librefang.ai). Private key is not in this repo.
2026-09-01 10:22:07 +03:00

34 lines
1.3 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Arka plugin registry
Hosted at **https://git.arka-ai.ru/arka/plugin-registry**.
This is Arka’s plugin marketplace registry: browse via Gitea Contents API,
install gated on a **signed** `index.json` (not `stats.librefang.ai`).
Plugin code is a mirror of Official
[`librefang/librefang-registry`](https://github.com/librefang/librefang-registry)
`plugins/` (MIT). The **index signature is Arka’s**, not upstream’s.
| File | Role |
| --- | --- |
| `plugins/<name>/` | Plugin tree (`plugin.toml` + hooks) |
| `index.json` | Signed membership list (what Agent Arka forge-host fetches) |
| `index.json.sig` | Ed25519 signature over the exact bytes of `index.json` |
| `plugins-index.json` | Same bytes as `index.json` (upstream filename, convenience) |
## Trust
- Public key (base64 32-byte Ed25519): see `PUBKEY` in this repo.
- Daemon: `LIBREFANG_REGISTRY_PUBKEY=<that value>`. Do **not** set `LIBREFANG_REGISTRY_VERIFY=0` in production.
- Private key is **not** in git. Re-sign after every plugin add/remove:
```bash
bash /path/to/sign-plugin-index.sh index.json ~/.arka-registry-keys/privkey.pem
cp index.json plugins-index.json
cp index.json.sig plugins-index.json.sig
```
Anonymous raw (no token):
`https://git.arka-ai.ru/arka/plugin-registry/raw/branch/main/index.json`