Skip to content

Stamp manifest_fingerprint from the packed files at publish - #38

Merged
hopeatina merged 1 commit into
mainfrom
fix/plan-v3-manifest-fingerprint
Sep 23, 2026
Merged

hopeatina merged 1 commit into
mainfrom
fix/plan-v3-manifest-fingerprint

Conversation

@hopeatina

Copy link
Copy Markdown
Contributor

Plan v3 leftover (release identity). The peer heartbeats manifest_fingerprint and signature, but both shipped empty. The publish workflow now stamps the fingerprint (sha256 over the packed file set, computed after build) and signs it with ORGX_MANIFEST_SIGNING_KEY when that secret exists, matching the server's verifyManifest. Same script as useorgx/orgx-codex-plugin#60.

Checks: 3 stamp tests; full test suite; a local run stamps sha256:1a20fe… over the built package.

🤖 Generated with Claude Code

Plan v3 §2/§5.4 leftover. The peer heartbeats manifest_fingerprint and
signature, but both shipped empty. The publish workflow now stamps the
fingerprint (sha256 over the packed file set, after build) and signs it
when ORGX_MANIFEST_SIGNING_KEY is set, matching the server's
verifyManifest.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@hopeatina
hopeatina merged commit 287be8d into main Sep 23, 2026
1 check passed
hopeatina added a commit that referenced this pull request Sep 25, 2026
…est fingerprint (#39)

Ships #37 (pin the OpenCode work capture mode explicitly) and #38 (stamp
manifest_fingerprint from the packed files at publish). Versions aligned
across package.json, package-lock.json and plugin.manifest.json; the
peer test's gateway_version fixture follows the version.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant