Files
fkysly 88c8ce33ad chore: validate the live catalog, and stop committing a copy of it (#545) (#557)
* chore: validate the live catalog, and stop committing a copy of it (#545)

@Icstick asked why `data/registry-snapshot.json` was eleven days behind
the catalog and how to request a refresh. The answer turned out to be
that nothing depends on it being fresh, and that the file's main effect
was to mislead.

What it was not:

- Not what the market reads. The bundled fallback was removed on purpose
  (see loadRegistry: for a catalog, stale is not a degraded answer, it is
  a wrong one). A build-site.yml comment still called it "the plugin's
  runtime fallback"; that was left over.
- Not shipped. `data/` is not in package.json `files`.
- Not what the site serves. The site build downloads its own copy into a
  checkout it throws away.

What it was: a 2.1MB file that gated merges on an 11-day-old copy of data
this repository does not own — 2452 entries against 3408 live — while
looking enough like the source of truth that people tried to add plugins
to it. The CI guard refusing hand edits exists because that had already
happened.

So the gate now reads what users actually get: validate-registry fetches
the live catalog, prefers a local file when one is present (offline runs
still work by dropping one in), and SKIPS with a notice when the origin
is unreachable — failing unrelated PRs on someone else's outage is how a
gate gets ignored.

The guard stays, retargeted: adding the file back is now the mistake it
was always trying to prevent.

One test read the snapshot as a corpus, cross-checking pluginSlug against
the site builder's slugOf so two plugins can never share a comment
thread. It now reads a committed corpus of every URL SHAPE the catalog
publishes — 108 of them across 3408 entries, sampled with real URLs, 24KB
instead of 2.1MB. Whether the catalog only ever publishes those shapes is
gated where it belongs: against the live catalog, by validate-registry's
E5.

@Icstick's three plugins were already visible in the market; verified
against the catalog package the market actually reads.

* ci: let the catalog-copy guard tell an addition from a removal

The guard fired on the PR that deletes the file it was written to
protect: it matched any diff touching that path, and a removal is a diff.
--diff-filter=AM narrows it to what it actually means — adding the file
back, or editing it in place.
2026-09-08 23:16:10 +08:00

17 lines
374 B
Plaintext

node_modules/
lib/
research/
*.tgz
.DS_Store
npm-cache/
docs/
data/readmes-snapshot.json
# Generated when a local build enables sourcemaps; never committed (#533).
client/*.map
# Catalog copies: downloaded when needed, never committed (#545). The site
# build fetches its own into a throwaway checkout, and the market reads the
# live catalog.
data/registry-snapshot.json