feat(catalog): enforce add-on admission gate + carry provisions_scopes #33

Merged
piersdd merged 1 commit from feat/add-on-provisions-scopes into main 2026-07-25 06:50:08 +00:00
piersdd commented 2026-06-27 13:29:10 +00:00 (Migrated from github.com)

CI fail-fast mirror of the registry add-on admission gate, so violations fail the catalog build before R2 upload.

What

  • build-catalog.js: assertAddOnAdmission() on add_on entries — first-party only, scopes within the reviewed allowlist, credential scopes a subset of the provisions_scopes envelope. Carries provisions_scopes through addOnToCatalogEntry into the served catalog.
  • catalog-entry schema: adds provisions_scopes.
  • Synced vendored add-on schema.

The allowlist mirrors the canonical gate in the registry worker.

Test

Verified live against throwaway add-on sources: a valid first-party add-on flows into the catalog with provisions_scopes; allowlist / third-party / subset violations each fail the build. Clean build = 70 entries.

🤖 Generated with Claude Code

CI fail-fast mirror of the registry add-on admission gate, so violations fail the catalog build before R2 upload. ## What - **`build-catalog.js`**: `assertAddOnAdmission()` on `add_on` entries — first-party only, scopes within the reviewed allowlist, credential scopes a subset of the `provisions_scopes` envelope. Carries `provisions_scopes` through `addOnToCatalogEntry` into the served catalog. - **catalog-entry schema**: adds `provisions_scopes`. - Synced vendored add-on schema. The allowlist mirrors the canonical gate in the registry worker. ## Test Verified live against throwaway add-on sources: a valid first-party add-on flows into the catalog with `provisions_scopes`; allowlist / third-party / subset violations each fail the build. Clean build = 70 entries. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Stallari/plugins!33
No description provided.