Skip to content

fix: close plugin lifecycle audit gaps - #924

Merged
kaitranntt merged 1 commit into
devfrom
kai/fix/914-917-lifecycle-audit-gaps
Jul 11, 2026
Merged

fix: close plugin lifecycle audit gaps#924
kaitranntt merged 1 commit into
devfrom
kai/fix/914-917-lifecycle-audit-gaps

Conversation

@kaitranntt

Copy link
Copy Markdown
Collaborator

Summary

  • remove and verify marketplace-only Claude plugin state while preserving unrelated plugins, caches, and marketplace entries
  • converge deprecated Engineer metadata only with exact staged-byte ownership proof and correct multi-kit boundaries
  • harden migration backup and rollback paths against symlink escapes, directory deletion, and unsafe snapshot restoration

Validation

  • 5,296 tests passed; 65 expected skips; 0 failures
  • 153 UI tests passed
  • typecheck, Biome, CLI/UI builds, help parity, npm tarball, and fresh packed install passed
  • real Claude/Codex provider canary: 7 passed; host state hash unchanged
  • independent lifecycle and rollback containment review: no findings

Docs impact

None. Existing installation documentation already describes the normal-default and explicit plugin opt-in contract; this PR corrects lifecycle enforcement without changing commands or choices.

Closes #914
Closes #917

@kaitranntt
kaitranntt merged commit fc1484d into dev Jul 11, 2026
3 checks passed
@kaitranntt
kaitranntt deleted the kai/fix/914-917-lifecycle-audit-gaps branch July 11, 2026 17:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant