Skip to content

chore(deps): update dependency universal-plugin to ^0.11.0 - #12

Merged
unional merged 1 commit into
mainfrom
renovate/universal-plugin-0.x
Oct 4, 2026
Merged

unional merged 1 commit into
mainfrom
renovate/universal-plugin-0.x

Conversation

@renovate

@renovate renovate Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
universal-plugin (source) ^0.7.0 → ^0.11.0 age confidence

Release Notes

cyberuni/universal-plugin (universal-plugin)

v0.11.3

Compare Source

Patch Changes
  • 4a0e9ac: doctor no longer reports com.github.copilot/ as stale after a rebuild. It compares the newest file in the directory against plugin.json, because a directory's own mtime does not move when its files are rewritten in place.
  • 4a0e9ac: publish sync-version now re-derives the vendor manifests after it moves the version, the same way plugin version does, so they no longer keep the old number. Pass --no-build to skip that step when your release script runs plugin build itself. The version and doctor-universal-plugin skills now name build-plugin as the follow-up step.

v0.11.2

Compare Source

Patch Changes
  • c8b81c8: plugin build no longer writes Codex custom prompts to ~/.codex/prompts/. Codex invokes plugin skills natively with $name or /skills, and its custom prompts are deprecated and no longer read, so the build now writes nothing outside the plugin tree. You can delete prompts that an earlier build left in ~/.codex/prompts/.
  • 642f70e: plugin build now leaves a component path out of a vendor's derived manifest when that vendor has no such component, and warns: codex has no "agents" component — the path is left out of .codex-plugin/plugin.json. Codex reads skills, commands, apps, hooks, and mcpServers; Cursor reads skills, commands, agents, rules, hooks, and mcpServers; Claude Code reads every component except rules and apps. A harnesses.<vendor> override is never filtered. doctor reports the case as unsupported-component.

v0.11.1

Compare Source

Patch Changes
  • d8bfd5b: Skills now load references with the reference skill in the buddy-agent-harness plugin, which replaces its load-reference skill. The line reads "Load plugin-design with the reference skill in the buddy-agent-harness plugin."

v0.11.0

Compare Source

Minor Changes
  • 55fdc24: Remove the retired governance command. governance show and governance list are now unknown commands. Use buddy-agent-harness reference show|list|search, or the load-reference skill in the buddy-agent-harness plugin, to read the same documents.
Patch Changes
  • dd275ba: plugin init --scaffold creates references/ instead of governances/, the folder buddy-agent-harness reference reads.
  • 4ad2dc8: prepare now reads installed plugins the way each harness records them. It reads Claude Code's version 2 installed_plugins.json by plugin name and scope, and it reads Copilot CLI's installed-plugins folders and the Codex plugin cache. Plugin paths come from @cyberuni/agent-harness, which honors CLAUDE_CONFIG_DIR, CODEX_HOME, and COPILOT_HOME.
  • 4ad2dc8: The vendor registry no longer carries globalManifest or globalPluginDir, and Cursor's local plugin folder now comes from @cyberuni/agent-harness. plugin install for Cursor therefore honors the harness's config directory. A localPluginDir in ~/.agents/universal-plugin-vendors.json still wins.

v0.10.0

Compare Source

Minor Changes
  • e0b672d: A new build-plugin skill is the entry point for plugin build. It runs the project's own build script when one exists, and otherwise the CLI shipped beside it through scripts/build.mjs, so nothing is downloaded. It reads the vendor and catalog rows back, reports each warning about something a vendor cannot represent, and hands a built 0 result to doctor-universal-plugin.

  • 738df81: marketplace add lists a plugin the repository does not hold, so a repository can curate a marketplace instead of only publishing its own plugins. One positional says where the plugin lives and is read by shape: a ./ path, an owner/repo slug, a git URL, an npm package (npm:pkg or @scope/pkg), or <plugin>@<marketplace> — with --path, --npm, --github, --url, and --from-marketplace to force the reading where owner/repo and a relative path collide. Nothing is fetched: metadata comes from a path's own plugin.json, an installed node_modules copy, the entry being copied, or the --description/--version/--homepage/--repository/--license/--keywords flags. A <plugin>@<marketplace> entry is resolved from a marketplace the runtime has already added, or from --from <dir>. A source that is relative to that marketplace is rewritten rather than copied, against the origin the runtime recorded for it or its clone's own git remote: ./plugins/aced in cyberuni/cyberplace becomes { "source": "git-subdir", "url": "https://github.com/cyberuni/cyberplace.git", "path": "plugins/aced" }, and an entry at the marketplace root becomes github or url. An entry only reaches a catalog whose runtime resolves that source — npm goes to Claude Code and Codex, and Copilot CLI and Cursor are reported skipped with the reason rather than written a source they refuse.

    A regeneration no longer discards the entries it did not derive. marketplace init, plugin build, and plugin init keep an entry whose source is not a local path, and keep a non-local source on a plugin they do discover while refreshing its derived metadata — so a plugin distributed through npm is not rewritten to a repository path holding gitignored build output, and add and init compose on one repository. A local-path entry discovery no longer finds is still dropped.

    The marketplace skill is now a gateway over three routes (init, add, validate), each with its own reference, and ships a scripts/add.mjs wrapper.

  • 2ba0e9c: Retire governance and the build's governance copies in favor of buddy-agent-harness reference and its load-reference skill.

    • governance show and governance list no longer read documents. For this release they print the replacement (buddy-agent-harness reference show <name>, or the load-reference skill in the buddy-agent-harness plugin) and exit 1. The next release removes the command.
    • plugin build no longer copies governances into skills/*/references/governances/, and plugin build --check is gone. Remove --check from CI; it now fails as an unknown option.
    • The documents this package owns (plugin-design, slash-invocation, and a universal-plugin pointer to plugin-design) ship under references/ instead of governances/, so reference show finds them in any project that depends on universal-plugin.
    • The init-universal-plugin skill loads plugin-design through the load-reference skill.
Patch Changes
  • c430c4a: publish sync-version no longer requires packagePath. With none set in .agents/universal-plugin.json, it reads the package.json at the plugin root, so a single-package repository where package.json sits beside plugin.json needs no config file. It fails only when that file is missing too, and the error names both places it looked. An explicit packagePath still wins.

v0.9.0

Compare Source

Minor Changes
  • 8fde5f7: plugin build copies each governance into the skills that use it, so a skill reads its rule sets from disk instead of running npx <pkg> governance show <name> at run time — no registry lookup per read, and no network while the skill works. The .md files already in <skill>/references/governances/ declare which governances that skill uses; the build rewrites each from the package that owns it, copies the governances those reference, transitively, and rewrites every governance show <other> pointer inside a copy into an instruction to load the sibling copy. The build fails when a declared file names no governance, when a referenced one has no copy to point at, or when SKILL.md does not list a copy under References. Commit the copies — a git-sourced install has no build step — and run the new plugin build --check in CI, which writes nothing and exits non-zero naming each copy that differs from its source.
  • 7836787: Rename the doctor skill to doctor-universal-plugin. Other plugins ship their own doctor skill, and the bare name collided when more than one was installed — buddy-agent-harness already resolved this by namespacing its own as doctor-buddy-agent-harness. Invoke it as /universal-plugin:doctor-universal-plugin; the CLI's own next-step hints now name that too.

v0.8.0

Compare Source

Minor Changes
  • cbda7c2: config get --key packagePath now reads packagePath instead of rejecting it. --format json prints the declared path as a JSON string, relative to the plugin root, or null when no npm package is declared. plugin version, publish sync-version, and config get share one reader, so they cannot disagree about a declaration. config add --key packagePath is still rejected: the key is a string, not a plugin-registered array.

  • 1eab810: Move the upx runner into its own package, @repobuddy/upx.

    A generic package runner is broader than this package's build/derivation charter — a placement note
    in the spec has said so since it landed. It also made the wrong trade for upx itself: the runner's
    value is install once globally, use everywhere, and that install should be small, so requiring
    npm i -g universal-plugin to get a runner word worked against it.

    Nothing about upx's behavior changed, and the emitter side stays here: plugin bundle --runner upx,
    the adopt-upx skill, and upgrade-plugin's runner-word handling all still live in this package.
    Their coupling was always to the word upx, never to its code.

    Install @repobuddy/upx directly — npm i -g @repobuddy/upx. The upx bin on this package now
    re-exports it so existing global installs keep working, and prints a deprecation notice on --help
    (never on a normal call — upx is a transparent exec wrapper). It will be removed in the next major.

  • 49f1036: Add universal-plugin plugin validate, which checks the root plugin.json without building anything. It reports every problem in one pass, in two groups:

    • Schema violations against the Agent Plugins 1.0.0 schema: $schema and name are required, name must match the schema's pattern, fields must have the right types, and top-level keys the standard does not define are rejected.
    • Vendor violations: for example, Codex requires description and version. --vendor <id> limits these checks to one vendor.

    An unknown vendor key in harnesses is a warning, and --strict makes it a violation. Output is TOON by default, with --format json and --full available. Running universal-plugin plugin with no subcommand now validates the current project and lists its declared harnesses, instead of printing help.

    A manifest without $schema now fails plugin validate. plugin build does not check $schema and still accepts it. plugin init already writes $schema.

Patch Changes
  • a40d5b0: doctor now reads packagePath only from .agents/universal-plugin.json, resolved from the plugin root — the same file and base plugin version and publish sync-version use. It no longer falls back to extensions["org.cyberuni.universal-plugin"].packagePath, which the CLI never honored, so doctor could pass a plugin that version still treated as not shipping to npm. A packagePath declared in the manifest extension is now reported as misplaced-package-path.

  • f0be1fa: doctor now accepts a repeatable --marketplace-root <path> flag to also validate a separately-cloned shared marketplace repository (e.g. a local clone of cyberuni/marketplace) — previously only the plugin's own repository root was checked, so a bad entry that reached the shared catalog another way went unnoticed. A named --marketplace-root that does not exist is reported as marketplace-root-missing instead of being silently skipped.

  • 0211cae: State the CLI's dependency bundling explicitly in the build config.

    dist/cli.mjs already shipped with its runtime dependencies inlined, and that is what lets the
    shipped skill launchers run from an installed plugin directory at all — those directories are copies
    of a source checkout, so their node_modules is absent or incomplete. The build now declares that
    intent through an explicit deps.alwaysBundle block rather than relying on it incidentally, so a
    dependency added later cannot quietly become external and break the launchers.

    @repobuddy/upx is deliberately excluded. It is reachable only from the separate bin/upx.mjs shim,
    which is not a build entry, so the upx bin still resolves it at runtime from an installed tree.

  • becd7ef: Fix plugin build ending with a next-step hint for universal-plugin plugin validate, a command that does not exist yet. A build that refreshed a marketplace catalog now points at universal-plugin marketplace validate (with --root for that repository), and any other successful build points at /universal-plugin:doctor.

  • 2469986: Fix universal-plugin --version (and -V) always printing 0.0.0 instead of the installed package's actual version.

  • c6304c5: migrate-plugin now bundles the package's CLI with tsdown as part of the migration, so the CLI runs from an installed plugin directory that has no node_modules. It splits tsdown.config.ts into a library config that keeps dependencies external and a CLI config that inlines them through deps.alwaysBundle. It then proves the result by running the CLI from an extracted tarball.

    The skill also covers plugins that live in a sibling workspace member such as plugins/<name>/, merges a colliding readme instead of overwriting it, and notes that publish sync-version reads packagePath from .agents/universal-plugin.json, not from the manifest. It also repoints lint excludes, marketplace sources, and spec paths.

  • 1f82ccd: schema/extension.schema.json and the init-universal-plugin standard reference no longer advertise packagePath under extensions["org.cyberuni.universal-plugin"]. The CLI never read it there, so a plugin that declared it where the schema said silently fell back to the author-picks release model. packagePath lives in .agents/universal-plugin.json beside plugin.json, as a path relative to the plugin root; a namespace packagePath now fails schema validation.

  • 4161472: The doctor and publish-plugin skills now ask the CLI for packagePath (config get --key packagePath) instead of reading .agents/universal-plugin.json themselves, so they cannot drift from plugin version. When the CLI is too old to answer, doctor reports package-path-unknown and skips version-drift and unreleased-content rather than guessing.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@changeset-bot

changeset-bot Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 2238c46

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@renovate
renovate Bot force-pushed the renovate/universal-plugin-0.x branch from ad1e46f to 2372996 Compare September 18, 2026 02:33
@renovate renovate Bot changed the title chore(deps): update dependency universal-plugin to ^0.8.0 chore(deps): update dependency universal-plugin to ^0.9.0 Sep 18, 2026
@renovate
renovate Bot force-pushed the renovate/universal-plugin-0.x branch 3 times, most recently from e98e36b to 28169bc Compare September 28, 2026 22:31
@renovate renovate Bot changed the title chore(deps): update dependency universal-plugin to ^0.9.0 chore(deps): update dependency universal-plugin to ^0.10.0 Sep 28, 2026
@renovate
renovate Bot force-pushed the renovate/universal-plugin-0.x branch from 28169bc to e947aff Compare September 29, 2026 15:44
@renovate renovate Bot changed the title chore(deps): update dependency universal-plugin to ^0.10.0 chore(deps): update dependency universal-plugin to ^0.11.0 Sep 29, 2026
@renovate
renovate Bot force-pushed the renovate/universal-plugin-0.x branch from e947aff to 02df1c8 Compare October 1, 2026 05:26
@renovate
renovate Bot force-pushed the renovate/universal-plugin-0.x branch from 02df1c8 to 2238c46 Compare October 4, 2026 08:31
@unional
unional merged commit bf3cb4a into main Oct 4, 2026
1 check passed
@renovate
renovate Bot deleted the renovate/universal-plugin-0.x branch October 4, 2026 22:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant