Skip to content

[CTX-0026] fix(registry): bind cached metadata to repository identity + validate recorded gitlinks - #58

Merged
Xuepoo merged 1 commit into
mainfrom
ctx-0026/fix-metadata-gitlink
Sep 26, 2026
Merged

Xuepoo merged 1 commit into
mainfrom
ctx-0026/fix-metadata-gitlink

Conversation

@Xuepoo

@Xuepoo Xuepoo commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Priority: P2 | Area: package, plugins | Labels: fix, P2, area:package, area:plugins | Milestone: v0.1.0 | RFC: OQ-053 | Task: CTX-0026

Closes #50
Closes #52

Summary

Implements two registry validation improvements:

  1. [PLUG-REG-003] fix(registry): bind cached metadata to repository identity #50 (PLUG-REG-003): Bind cached metadata to repository identity

    • Adds repository_source field to IndexMetadata to track the source repository
    • Invalidates cached metadata when repository URL changes (using normalized comparison)
    • Preserves metadata for equivalent URL spellings (e.g., .git suffix variations)
  2. [PLUG-REG-005] fix(registry): validate recorded gitlinks instead of checkout revisions #52 (PLUG-REG-005): Validate recorded gitlinks instead of checkout revisions

    • Changes readSubmodulePins() to use git ls-tree HEAD plugins instead of git submodule status
    • Reads the gitlinks recorded in the parent commit rather than checkout status
    • Prevents local checkout drift from replacing the reviewed SHA in validation

Testing

  • Added test for metadata invalidation when repository changes
  • Added test for metadata preservation with equivalent URL spellings
  • Updated all existing tests to include repository_source field
  • All checks pass (just check)

… + validate recorded gitlinks

Fixes #50 (PLUG-REG-003): bind cached metadata to repository identity
- Add repository_source field to IndexMetadata to track the source repository
- Invalidate cached metadata when repository URL changes (normalized comparison)
- Preserve metadata for equivalent URL spellings (e.g., .git suffix variations)
- Update sync-metadata.ts to store repository_source and check it for equality

Fixes #52 (PLUG-REG-005): validate recorded gitlinks instead of checkout revisions
- Change readSubmodulePins() to use 'git ls-tree HEAD plugins' instead of 'git submodule status'
- This reads the gitlinks recorded in the parent commit rather than checkout status
- Prevents local checkout drift from replacing the reviewed SHA in validation

Tests:
- Add test for metadata invalidation when repository changes
- Add test for metadata preservation with equivalent URL spellings
- Update all existing tests to include repository_source field
@Xuepoo Xuepoo added this to the v0.1.0 milestone Sep 26, 2026
@Xuepoo Xuepoo added fix Bug fix area:package Area: package lifecycle P2 Priority: medium area:plugins labels Sep 26, 2026
@Xuepoo
Xuepoo merged commit d80bb8c into main Sep 26, 2026
6 checks passed
@Xuepoo
Xuepoo deleted the ctx-0026/fix-metadata-gitlink branch September 26, 2026 06:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:package Area: package lifecycle area:plugins fix Bug fix P2 Priority: medium

Projects

None yet

1 participant