Morgan Lunt b822a2974d
receipts: show a sample receipt in the README (#4295)
You can't tell what this produces from a description, and the obvious
way to show it — screenshot a real run — would put someone's actual repo
names in a public README.

So the sample is generated: assets/make-sample.mjs builds a throwaway
HOME of invented repos, invented files and invented sessions, and the
real miner runs against that. The picture is what the tool genuinely
produces, from data that never existed. The generator ships next to the
asset so the next person can regenerate rather than edit a screenshot.

Also widen validate's path filter. It's a required check, so a PR that
only touches a plugin's README or assets matched no pattern, never
reported, and could not be merged — the same trap the workflow-file and
policy-file entries above already work around. Adding the plugin doc
paths lets this PR (and the next one) clear the gate on its own.

No-Verification-Needed: docs asset, dev-only generator, and CI trigger paths — no plugin runtime surface
2026-07-20 19:05:45 -05:00

63 lines
2.7 KiB
YAML

name: Validate Plugins
on:
pull_request:
paths:
- '.claude-plugin/**'
- '*/.claude-plugin/**'
- '*/agents/**'
- '*/skills/**'
- '*/commands/**'
# `validate` is a required status check, so a PR that touches ONLY workflow
# files (e.g. an action-SHA re-pin) would otherwise never trigger validate
# and sit "Expected — Waiting for status to be reported" forever (workflow_dispatch
# check runs aren't associated with the PR, so they don't satisfy it). Run
# validate on workflow changes too so those PRs can clear the gate in-context.
- '.github/workflows/**'
# Same rationale for the scan policy prompt: a policy-only PR (.github/policy/**)
# touches none of the plugin paths above, so validate would never trigger via
# pull_request and the required check would sit "Expected" forever (a dispatch
# check run isn't associated with the PR, so it can't satisfy the gate either).
- '.github/policy/**'
# And once more for a plugin's own docs: a PR that only edits a README or
# adds a screenshot matches nothing above, so the required check never
# reports and the PR can't be merged. Spelled out per level because `*`
# doesn't cross a `/` — plugins live at plugins/<name>/, so `*/README.md`
# would not match one.
- 'plugins/*/README.md'
- 'plugins/*/assets/**'
- 'external_plugins/*/README.md'
- 'external_plugins/*/assets/**'
push:
branches: [main]
paths:
- '.claude-plugin/**'
# `validate` is a required status check on main. Bump PRs are opened with
# GITHUB_TOKEN, which doesn't fire on:pull_request (recursion guard), so the
# path-filtered trigger above never reports on them and the PR would be
# blocked forever. The bump workflow dispatches this against each per-entry
# bump branch instead; the check run lands on the branch HEAD (= PR head)
# and satisfies the required check. The validate job runs unconditionally,
# so a dispatch always reports.
workflow_dispatch:
permissions:
contents: read
jobs:
validate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: anthropics/claude-plugins-community/.github/actions/validate-plugins@426e469f322952061102b286b378c0c9733a0934
with:
marketplace-path: .claude-plugin/marketplace.json
# Official curated marketplace: SHA-pin (I5) is a HARD error.
# I8/I11 are warnings until the 15 known vendored-path/name issues
# are cleaned up (see PR body); tighten to "I1 I3" after.
warn-invariants: "I1 I3 I8 I11"
claude-cli-version: latest