Follow-up from #635 (@connor-grady). The daily cron in .github/workflows/update-plugins.yml is a stopgap — the right trigger is event-driven:
- Create a fine-grained PAT with
contents: write (or a GitHub App) authorized for this repo, stored as a secret in each plugin repo (meridian-plugin-hermes-scrub, meridian-plugin-opencode-scrub, meridian-plugin-pi-scrub).
- Each plugin repo gains a small workflow that fires
repository_dispatch (e.g. event_type: plugin-updated) at rynfar/meridian on push to its default branch.
update-plugins.yml adds repository_dispatch: { types: [plugin-updated] } to its on: block — the update logic needs no changes and the cron stays as a safety net.
Only the repo owner can mint the PAT/App credentials, which is why this didn't ship with #649.
Follow-up from #635 (@connor-grady). The daily cron in
.github/workflows/update-plugins.ymlis a stopgap — the right trigger is event-driven:contents: write(or a GitHub App) authorized for this repo, stored as a secret in each plugin repo (meridian-plugin-hermes-scrub,meridian-plugin-opencode-scrub,meridian-plugin-pi-scrub).repository_dispatch(e.g.event_type: plugin-updated) atrynfar/meridianon push to its default branch.update-plugins.ymladdsrepository_dispatch: { types: [plugin-updated] }to itson:block — the update logic needs no changes and the cron stays as a safety net.Only the repo owner can mint the PAT/App credentials, which is why this didn't ship with #649.