Repository navigation
Conversation
Contributor
Author
|
Live integration validation found an editor marketplace identity mismatch. Signed commit cbe8792 preserves the receipt marketplace reference instead of overwriting it with the catalog display name; a regression assertion covers the ID/name contract. Synced current main in signed ba5df7e so the full existing workflow uses a compatible candidate, including already-merged Go inventory. Full race tests, lint, vet, 45 smoke checks and three-platform builds passed. Full three-platform Developer MDM V1 run: https://github.com/step-security/integration-test/actions/runs/37526699915. Live acceptance remains in progress; this PR is not merged. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Adds Copilot CLI, standalone Copilot app and VS Code Agent Plugins inventory to the existing plugin scan phase. Collects recorded installations and persistent local-marketplace selections, their supplied skills, custom-agent declarations and sanitized MCP definitions, plus standalone user/project MCP configurations. Preserves source, scope, enablement observations and parent relationships without treating cached directories as installed plugins.
Reuses bounded, file-only readers and TCC protection. Git/GitHub catalogs support complete component coverage when matching evidence is readable; failed reads remain partial. Regression tests preserve shared MCP symlinks and unrelated project MCP configurations. Copilot cases are consolidated into the common Agent Plugins golden fixture with Claude/Codex. Matching API fixture/test updates are in main PR #11029 and integration follow-up #11093. Existing AITool inventory and internal/aiagents are unchanged.
Copilot tests use the existing shared plugin, MCP and model test files. Production adapters retain the existing per-agent file pattern.
Type of change
Testing
go test -race ./..., plus affected-package regression testsgo vet ./...,golangci-lint run ./..., formatting and whitespace checksgo mod tidy -diffwith no dependency driftmake smoke: 45/45 checks passedGosec completed with no package-load errors and the same 24 pre-existing findings. The four original local review findings were fixed and revalidated. Expanded native-surface limitations are tracked in the live runbook.
Native CLI core lifecycle was checked on macOS, Linux and Windows. Expanded Mac checks cover five app marketplace plugins, three editor/Agents marketplace selections, project local-source registration, toggles/removal and integration Skills/MCP supplier links. Commands, rules and LSP declarations were added with regression tests and a native packaged-fixture check. Rules carry declaration metadata only; CLI runtime activation is not claimed. Expanded Windows/Linux app/editor checks and app-only local GUI lifecycle remain pending. Deployed rule-kind acceptance passed on Mac. Editor activation stays unknown where its private state is not collected. TCC-protected paths remain guarded.
Follow-up commit: 8b8e85c, signature verified. Shared fixture SHA-256: 4aa872e1df3d2c33326cd43193d17f7c0b1d36ce0a4e4f3734af8e0b3144215b. Backend rule-kind acceptance from #11093 is deployed and verified on integration. Release the matching backend changes before this candidate in production.
Custom-catalog follow-up: signed commit dcdb8fb resolves editor file-URI catalogs to their validated Git payload provenance. Native VS Code installation from the owned private catalog, stable identity across CLI/editor, four linked skill/command rows, unselected-entry exclusion and post-uninstall API restoration passed. Missing/mismatched/protected catalogs have regression coverage. Full local gates passed. Latest DMG CI passed Test; remaining jobs were cancelled before execution because hosted runners were not acquired. DMG/main release PRs remain unmerged; API integration follow-up #11093 is merged and deployed.
Post-deployment Mac retest: exact skill/command/rule/LSP details, all four kind filters and skill/command supplier refs passed. Native CLI uninstall and restored API checks passed: six plugin groups, nine installations, 23 linked skills and exact MCP supplier refs. Claude/Codex control IDs and skill hashes match the earlier baseline. No new product fix was needed. Latest DMG CI passed tests, but other jobs could not acquire hosted runners; full CI is not green.
Standalone Mac app custom local-catalog selection passed: the user enabled incident-review through the app. DMG and deployed APIs agree on its single local installation, complete skill component, identity and content hash. Native uninstall for this live plugin only disables it; the backend correctly retained the same installation/skill with configured_enabled=false. This is not a GUI uninstall pass. The app's private Git clone failed authentication despite working shell Git/GitHub access; that native-app/setup limitation remains logged, not reported as a collector defect. Existing Claude/Codex control records remain unchanged.