feat(catalog): enforce add-on admission gate + carry provisions_scopes #33
No reviewers
Labels
No labels
boundary:crosses
boundary:none
bug
devfu
documentation
duplicate
enhancement
epic
good first issue
help wanted
invalid
needs-info
needs-triage
question
ready-for-agent
ready-for-human
svd:fire
svd:go
svd:hold
svd:respec
svd:skip
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Stallari/plugins!33
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/add-on-provisions-scopes"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
CI fail-fast mirror of the registry add-on admission gate, so violations fail the catalog build before R2 upload.
What
build-catalog.js:assertAddOnAdmission()onadd_onentries — first-party only, scopes within the reviewed allowlist, credential scopes a subset of theprovisions_scopesenvelope. Carriesprovisions_scopesthroughaddOnToCatalogEntryinto the served catalog.provisions_scopes.The allowlist mirrors the canonical gate in the registry worker.
Test
Verified live against throwaway add-on sources: a valid first-party add-on flows into the catalog with
provisions_scopes; allowlist / third-party / subset violations each fail the build. Clean build = 70 entries.🤖 Generated with Claude Code