🤖 Generated by the Agentic Engineer
Objective
Restore GitOps repository audits in the shared plugin and Platform once the complete upstream audit can be installed and validated safely. The maintainer requested restoration on 2026-10-01.
Current acceptance boundary
The literal dotenv repair has reached fluxcd/agent-skills revision 0d1fa6c46e553d2f264dfcc8c8630c628195f6e4. Its validator is vendored from the corrected flux-schema action and requires flux-schema 0.15 or newer. The catalogue source-pin fix is delivered in merged devantler-tech/agent-skills#268, commit a820cb996d3104491a4bf5f32653440b494b631e; native individual and batch installations from that merged catalogue both matched the declared revision and verified validator bytes.
Whole-audit restoration still has a reproduced prerequisite in #543. At that upstream revision, a failed deprecated-API scan can return success and report a clean audit. The three bundled helpers also lack the adjacent regression tests required by the marketplace's current CI. The earlier dotenv repair does not settle these separate checks.
Named prerequisite: #543 remains open. Its deprecated-API scan repair and the separate canonical traversal repair in #544 are prepared and tested locally; neither has been published, accepted upstream or installed into this marketplace. The traversal repair also passed a real local-backend permission probe and local dotenv evaluations, recorded in #544's evaluation. Flux permits AI-assisted contributions but requires human DCO certification before upstream publication. Do not edit synchronized resources locally or weaken helper-test requirements to bypass the prerequisite.
Delivery checklist
Evidence and ownership
The retirement was delivered in #184 and devantler-tech/platform#4138 following #164. The dotenv fix is upstream in flux-schema#128 and agent-skills#65. The remaining failure-discarding helper and marketplace helper-test requirement are separate restoration prerequisites.
Keep this parent open until the plugin and Platform acceptance paths are both delivered. A local regression patch, corrected catalogue pin or historical validator fixture result alone does not prove that restoration is complete.
Objective
Restore GitOps repository audits in the shared plugin and Platform once the complete upstream audit can be installed and validated safely. The maintainer requested restoration on 2026-10-01.
Current acceptance boundary
The literal dotenv repair has reached
fluxcd/agent-skillsrevision0d1fa6c46e553d2f264dfcc8c8630c628195f6e4. Its validator is vendored from the corrected flux-schema action and requires flux-schema 0.15 or newer. The catalogue source-pin fix is delivered in merged devantler-tech/agent-skills#268, commita820cb996d3104491a4bf5f32653440b494b631e; native individual and batch installations from that merged catalogue both matched the declared revision and verified validator bytes.Whole-audit restoration still has a reproduced prerequisite in #543. At that upstream revision, a failed deprecated-API scan can return success and report a clean audit. The three bundled helpers also lack the adjacent regression tests required by the marketplace's current CI. The earlier dotenv repair does not settle these separate checks.
Named prerequisite: #543 remains open. Its deprecated-API scan repair and the separate canonical traversal repair in #544 are prepared and tested locally; neither has been published, accepted upstream or installed into this marketplace. The traversal repair also passed a real local-backend permission probe and local dotenv evaluations, recorded in #544's evaluation. Flux permits AI-assisted contributions but requires human DCO certification before upstream publication. Do not edit synchronized resources locally or weaken helper-test requirements to bypass the prerequisite.
Delivery checklist
Evidence and ownership
The retirement was delivered in #184 and devantler-tech/platform#4138 following #164. The dotenv fix is upstream in flux-schema#128 and agent-skills#65. The remaining failure-discarding helper and marketplace helper-test requirement are separate restoration prerequisites.
Keep this parent open until the plugin and Platform acceptance paths are both delivered. A local regression patch, corrected catalogue pin or historical validator fixture result alone does not prove that restoration is complete.