Skip to content

Restore GitOps repository audits from the corrected upstream skill #292

Description

@devantler

🤖 Generated by the Agentic Engineer

Objective

Restore GitOps repository audits in the shared plugin and Platform once the complete upstream audit can be installed and validated safely. The maintainer requested restoration on 2026-10-01.

Current acceptance boundary

The literal dotenv repair has reached fluxcd/agent-skills revision 0d1fa6c46e553d2f264dfcc8c8630c628195f6e4. Its validator is vendored from the corrected flux-schema action and requires flux-schema 0.15 or newer. The catalogue source-pin fix is delivered in merged devantler-tech/agent-skills#268, commit a820cb996d3104491a4bf5f32653440b494b631e; native individual and batch installations from that merged catalogue both matched the declared revision and verified validator bytes.

Whole-audit restoration still has a reproduced prerequisite in #543. At that upstream revision, a failed deprecated-API scan can return success and report a clean audit. The three bundled helpers also lack the adjacent regression tests required by the marketplace's current CI. The earlier dotenv repair does not settle these separate checks.

Named prerequisite: #543 remains open. Its deprecated-API scan repair and the separate canonical traversal repair in #544 are prepared and tested locally; neither has been published, accepted upstream or installed into this marketplace. The traversal repair also passed a real local-backend permission probe and local dotenv evaluations, recorded in #544's evaluation. Flux permits AI-assisted contributions but requires human DCO certification before upstream publication. Do not edit synchronized resources locally or weaken helper-test requirements to bypass the prerequisite.

Delivery checklist

  • Verify that canonical upstream contains the corrected literal dotenv validator and documents its required flux-schema version.
  • Merge the catalogue pin correction in fix(catalogue): pin corrected GitOps audit source agent-skills#268 and verify installation from the merged catalogue.
  • Complete Preserve audit failures before restoring the GitOps bundle #543 and its Preserve audit failure when manifest traversal is incomplete #544 dependency: preserve scan and traversal failures and provide meaningful upstream tests for all three audit helpers. Cover literal dotenv handling, host-environment isolation and undefined-variable rejection in explicitly enabled strict mode, with documented default-expansion and default-expression controls.
  • Install the verified repaired skill with the native pinned installer, preserving source provenance and bundled resources unchanged.
  • Restore plugin membership, descriptions, catalogue and audit-specific CI validation; bump the GitOps plugin cache version and generate its changelog.
  • Evaluate the installed bundle through its native consumer path, including failed and partial scans. Pass current-head CI and substantive review before merging.
  • Restore Platform's installed skill from the same verified upstream revision and complete its separate required checks and consumer evaluation.

Evidence and ownership

The retirement was delivered in #184 and devantler-tech/platform#4138 following #164. The dotenv fix is upstream in flux-schema#128 and agent-skills#65. The remaining failure-discarding helper and marketplace helper-test requirement are separate restoration prerequisites.

Keep this parent open until the plugin and Platform acceptance paths are both delivered. A local regression patch, corrected catalogue pin or historical validator fixture result alone does not prove that restoration is complete.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions