Repository navigation
chore(deps): update dependency universal-plugin to ^0.11.0 - #12
Merged
Merged
Conversation
|
renovate
Bot
force-pushed
the
renovate/universal-plugin-0.x
branch
from
September 18, 2026 02:33
ad1e46f to
2372996
Compare
renovate
Bot
force-pushed
the
renovate/universal-plugin-0.x
branch
3 times, most recently
from
September 28, 2026 22:31
e98e36b to
28169bc
Compare
renovate
Bot
force-pushed
the
renovate/universal-plugin-0.x
branch
from
September 29, 2026 15:44
28169bc to
e947aff
Compare
renovate
Bot
force-pushed
the
renovate/universal-plugin-0.x
branch
from
October 1, 2026 05:26
e947aff to
02df1c8
Compare
renovate
Bot
force-pushed
the
renovate/universal-plugin-0.x
branch
from
October 4, 2026 08:31
02df1c8 to
2238c46
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.7.0→^0.11.0Release Notes
cyberuni/universal-plugin (universal-plugin)
v0.11.3Compare Source
Patch Changes
4a0e9ac:doctorno longer reportscom.github.copilot/as stale after a rebuild. It compares the newest file in the directory againstplugin.json, because a directory's own mtime does not move when its files are rewritten in place.4a0e9ac:publish sync-versionnow re-derives the vendor manifests after it moves the version, the same wayplugin versiondoes, so they no longer keep the old number. Pass--no-buildto skip that step when your release script runsplugin builditself. Theversionanddoctor-universal-pluginskills now namebuild-pluginas the follow-up step.v0.11.2Compare Source
Patch Changes
c8b81c8:plugin buildno longer writes Codex custom prompts to~/.codex/prompts/. Codex invokes plugin skills natively with$nameor/skills, and its custom prompts are deprecated and no longer read, so the build now writes nothing outside the plugin tree. You can delete prompts that an earlier build left in~/.codex/prompts/.642f70e:plugin buildnow leaves a component path out of a vendor's derived manifest when that vendor has no such component, and warns:codex has no "agents" component — the path is left out of .codex-plugin/plugin.json. Codex readsskills,commands,apps,hooks, andmcpServers; Cursor readsskills,commands,agents,rules,hooks, andmcpServers; Claude Code reads every component exceptrulesandapps. Aharnesses.<vendor>override is never filtered.doctorreports the case asunsupported-component.v0.11.1Compare Source
Patch Changes
d8bfd5b: Skills now load references with thereferenceskill in thebuddy-agent-harnessplugin, which replaces itsload-referenceskill. The line reads "Loadplugin-designwith thereferenceskill in thebuddy-agent-harnessplugin."v0.11.0Compare Source
Minor Changes
55fdc24: Remove the retiredgovernancecommand.governance showandgovernance listare now unknown commands. Usebuddy-agent-harness reference show|list|search, or theload-referenceskill in thebuddy-agent-harnessplugin, to read the same documents.Patch Changes
dd275ba:plugin init --scaffoldcreatesreferences/instead ofgovernances/, the folderbuddy-agent-harness referencereads.4ad2dc8:preparenow reads installed plugins the way each harness records them. It reads Claude Code's version 2installed_plugins.jsonby plugin name and scope, and it reads Copilot CLI'sinstalled-pluginsfolders and the Codex plugin cache. Plugin paths come from@cyberuni/agent-harness, which honorsCLAUDE_CONFIG_DIR,CODEX_HOME, andCOPILOT_HOME.4ad2dc8: The vendor registry no longer carriesglobalManifestorglobalPluginDir, and Cursor's local plugin folder now comes from@cyberuni/agent-harness.plugin installfor Cursor therefore honors the harness's config directory. AlocalPluginDirin~/.agents/universal-plugin-vendors.jsonstill wins.v0.10.0Compare Source
Minor Changes
e0b672d: A newbuild-pluginskill is the entry point forplugin build. It runs the project's own build script when one exists, and otherwise the CLI shipped beside it throughscripts/build.mjs, so nothing is downloaded. It reads the vendor and catalog rows back, reports each warning about something a vendor cannot represent, and hands abuilt 0result todoctor-universal-plugin.738df81:marketplace addlists a plugin the repository does not hold, so a repository can curate a marketplace instead of only publishing its own plugins. One positional says where the plugin lives and is read by shape: a./path, anowner/reposlug, a git URL, an npm package (npm:pkgor@scope/pkg), or<plugin>@<marketplace>— with--path,--npm,--github,--url, and--from-marketplaceto force the reading whereowner/repoand a relative path collide. Nothing is fetched: metadata comes from a path's ownplugin.json, an installednode_modulescopy, the entry being copied, or the--description/--version/--homepage/--repository/--license/--keywordsflags. A<plugin>@<marketplace>entry is resolved from a marketplace the runtime has already added, or from--from <dir>. A source that is relative to that marketplace is rewritten rather than copied, against the origin the runtime recorded for it or its clone's own git remote:./plugins/acedincyberuni/cyberplacebecomes{ "source": "git-subdir", "url": "https://github.com/cyberuni/cyberplace.git", "path": "plugins/aced" }, and an entry at the marketplace root becomesgithuborurl. An entry only reaches a catalog whose runtime resolves that source — npm goes to Claude Code and Codex, and Copilot CLI and Cursor are reportedskippedwith the reason rather than written a source they refuse.A regeneration no longer discards the entries it did not derive.
marketplace init,plugin build, andplugin initkeep an entry whose source is not a local path, and keep a non-local source on a plugin they do discover while refreshing its derived metadata — so a plugin distributed through npm is not rewritten to a repository path holding gitignored build output, andaddandinitcompose on one repository. A local-path entry discovery no longer finds is still dropped.The
marketplaceskill is now a gateway over three routes (init,add,validate), each with its own reference, and ships ascripts/add.mjswrapper.2ba0e9c: Retiregovernanceand the build's governance copies in favor ofbuddy-agent-harness referenceand itsload-referenceskill.governance showandgovernance listno longer read documents. For this release they print the replacement (buddy-agent-harness reference show <name>, or theload-referenceskill in thebuddy-agent-harnessplugin) and exit 1. The next release removes the command.plugin buildno longer copies governances intoskills/*/references/governances/, andplugin build --checkis gone. Remove--checkfrom CI; it now fails as an unknown option.plugin-design,slash-invocation, and auniversal-pluginpointer toplugin-design) ship underreferences/instead ofgovernances/, soreference showfinds them in any project that depends onuniversal-plugin.init-universal-pluginskill loadsplugin-designthrough theload-referenceskill.Patch Changes
c430c4a:publish sync-versionno longer requirespackagePath. With none set in.agents/universal-plugin.json, it reads thepackage.jsonat the plugin root, so a single-package repository wherepackage.jsonsits besideplugin.jsonneeds no config file. It fails only when that file is missing too, and the error names both places it looked. An explicitpackagePathstill wins.v0.9.0Compare Source
Minor Changes
8fde5f7:plugin buildcopies each governance into the skills that use it, so a skill reads its rule sets from disk instead of runningnpx <pkg> governance show <name>at run time — no registry lookup per read, and no network while the skill works. The.mdfiles already in<skill>/references/governances/declare which governances that skill uses; the build rewrites each from the package that owns it, copies the governances those reference, transitively, and rewrites everygovernance show <other>pointer inside a copy into an instruction to load the sibling copy. The build fails when a declared file names no governance, when a referenced one has no copy to point at, or whenSKILL.mddoes not list a copy under References. Commit the copies — a git-sourced install has no build step — and run the newplugin build --checkin CI, which writes nothing and exits non-zero naming each copy that differs from its source.7836787: Rename thedoctorskill todoctor-universal-plugin. Other plugins ship their owndoctorskill, and the bare name collided when more than one was installed —buddy-agent-harnessalready resolved this by namespacing its own asdoctor-buddy-agent-harness. Invoke it as/universal-plugin:doctor-universal-plugin; the CLI's own next-step hints now name that too.v0.8.0Compare Source
Minor Changes
cbda7c2:config get --key packagePathnow readspackagePathinstead of rejecting it.--format jsonprints the declared path as a JSON string, relative to the plugin root, ornullwhen no npm package is declared.plugin version,publish sync-version, andconfig getshare one reader, so they cannot disagree about a declaration.config add --key packagePathis still rejected: the key is a string, not a plugin-registered array.1eab810: Move theupxrunner into its own package,@repobuddy/upx.A generic package runner is broader than this package's build/derivation charter — a placement note
in the spec has said so since it landed. It also made the wrong trade for
upxitself: the runner'svalue is install once globally, use everywhere, and that install should be small, so requiring
npm i -g universal-pluginto get a runner word worked against it.Nothing about
upx's behavior changed, and the emitter side stays here:plugin bundle --runner upx,the
adopt-upxskill, andupgrade-plugin's runner-word handling all still live in this package.Their coupling was always to the word
upx, never to its code.Install
@repobuddy/upxdirectly —npm i -g @repobuddy/upx. Theupxbin on this package nowre-exports it so existing global installs keep working, and prints a deprecation notice on
--help(never on a normal call —
upxis a transparent exec wrapper). It will be removed in the next major.49f1036: Adduniversal-plugin plugin validate, which checks the rootplugin.jsonwithout building anything. It reports every problem in one pass, in two groups:$schemaandnameare required,namemust match the schema's pattern, fields must have the right types, and top-level keys the standard does not define are rejected.descriptionandversion.--vendor <id>limits these checks to one vendor.An unknown vendor key in
harnessesis a warning, and--strictmakes it a violation. Output is TOON by default, with--format jsonand--fullavailable. Runninguniversal-plugin pluginwith no subcommand now validates the current project and lists its declared harnesses, instead of printing help.A manifest without
$schemanow failsplugin validate.plugin builddoes not check$schemaand still accepts it.plugin initalready writes$schema.Patch Changes
a40d5b0:doctornow readspackagePathonly from.agents/universal-plugin.json, resolved from the plugin root — the same file and baseplugin versionandpublish sync-versionuse. It no longer falls back toextensions["org.cyberuni.universal-plugin"].packagePath, which the CLI never honored, so doctor could pass a plugin thatversionstill treated as not shipping to npm. ApackagePathdeclared in the manifest extension is now reported asmisplaced-package-path.f0be1fa:doctornow accepts a repeatable--marketplace-root <path>flag to also validate a separately-cloned shared marketplace repository (e.g. a local clone ofcyberuni/marketplace) — previously only the plugin's own repository root was checked, so a bad entry that reached the shared catalog another way went unnoticed. A named--marketplace-rootthat does not exist is reported asmarketplace-root-missinginstead of being silently skipped.0211cae: State the CLI's dependency bundling explicitly in the build config.dist/cli.mjsalready shipped with its runtime dependencies inlined, and that is what lets theshipped skill launchers run from an installed plugin directory at all — those directories are copies
of a source checkout, so their
node_modulesis absent or incomplete. The build now declares thatintent through an explicit
deps.alwaysBundleblock rather than relying on it incidentally, so adependency added later cannot quietly become external and break the launchers.
@repobuddy/upxis deliberately excluded. It is reachable only from the separatebin/upx.mjsshim,which is not a build entry, so the
upxbin still resolves it at runtime from an installed tree.becd7ef: Fixplugin buildending with a next-step hint foruniversal-plugin plugin validate, a command that does not exist yet. A build that refreshed a marketplace catalog now points atuniversal-plugin marketplace validate(with--rootfor that repository), and any other successful build points at/universal-plugin:doctor.2469986: Fixuniversal-plugin --version(and-V) always printing0.0.0instead of the installed package's actual version.c6304c5:migrate-pluginnow bundles the package's CLI with tsdown as part of the migration, so the CLI runs from an installed plugin directory that has nonode_modules. It splitstsdown.config.tsinto a library config that keeps dependencies external and a CLI config that inlines them throughdeps.alwaysBundle. It then proves the result by running the CLI from an extracted tarball.The skill also covers plugins that live in a sibling workspace member such as
plugins/<name>/, merges a colliding readme instead of overwriting it, and notes thatpublish sync-versionreadspackagePathfrom.agents/universal-plugin.json, not from the manifest. It also repoints lint excludes, marketplace sources, and spec paths.1f82ccd:schema/extension.schema.jsonand theinit-universal-pluginstandard reference no longer advertisepackagePathunderextensions["org.cyberuni.universal-plugin"]. The CLI never read it there, so a plugin that declared it where the schema said silently fell back to the author-picks release model.packagePathlives in.agents/universal-plugin.jsonbesideplugin.json, as a path relative to the plugin root; a namespacepackagePathnow fails schema validation.4161472: Thedoctorandpublish-pluginskills now ask the CLI forpackagePath(config get --key packagePath) instead of reading.agents/universal-plugin.jsonthemselves, so they cannot drift fromplugin version. When the CLI is too old to answer, doctor reportspackage-path-unknownand skipsversion-driftandunreleased-contentrather than guessing.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.