You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PR #4590 ("feat(attribution)!: rename the provenance plugin to attribution") implements the rename and closes #4589 when it merges. The consumers that live outside this repository are not covered. #4589's triage marks them "out of scope here (owner)", and #4590's Related section lists them as USER-RESERVED. Once #4590 merges, #4589 closes and nothing tracks them. The PR itself also has not been merge-gated: its Verification section still reads PENDING.
Evidence
The rename itself is settled: the operator decided on 2026-09-11 to rename provenance@melodic-software to attribution@melodic-software. The reasons: the plugin's one rule is that restated prose must be attributed, and "provenance" also means an origin note to delete in code-tidying and docs-hygiene.
Rule ids become attribution/audit/rule-*, the config file becomes .claude/attribution.json, and the findings file becomes <ts>-attribution.md.
A leftover provenance*.json prints a warning and is never read.
renames in marketplace.json is unchanged.
Commit 1bc1c2584 on the branch records the one-release shim in docs/migration-playbook.md. That resolves the conflict the PR body flags (the playbook previously said a rename is a clean break with no tombstone).
Commit e84d5d72b on the branch enables attribution in this repository's .claude/settings.json "until the fleet list names it". That is a temporary line to revert later.
Out-of-repo consumers (read-only checks):
melodic-software/standardscomponents/cloud-environment/fleet-plugins.json:68 has "provenance@melodic-software": true.
melodic-software/dotfiles.chezmoidata/claude.json:600 has "provenance@melodic-software": false, so there is a decision to make about whether attribution should be enabled there.
Plugin data directory: no file under plugins/attribution/ or plugins/provenance/ on the PR head references CLAUDE_PLUGIN_DATA or plugins/data (git grep at d1ba6d1a5). The plugin keeps its config in .claude/attribution.json layers, not the data directory. So there is probably nothing to move. Verify on each machine that ~/.claude/plugins/data/provenance-melodic-software/ is absent or empty before deleting it.
Not verified: the result of the CI run on c6e962623; whether the review lanes ran on it.
Whether to add a renames entry provenance -> attribution. Upstream calls the map append-only, and the repo's frozen-map doctrine argues against it. The shim covers the one-release window without it.
Whether dotfiles should enable attribution (today provenance is false there).
Migrate consumers, each in its own repository under that repository's identity:
standards fleet-plugins.json: replace the provenance row with "attribution@melodic-software": true.
dotfiles .chezmoidata/claude.json: rename the row and apply the decision from step 2.
Each machine's ~/.claude/settings.jsonenabledPlugins: enable attribution, disable provenance after the update lands.
Any ~/.claude/provenance.json or repo .claude/provenance*.json: rename to attribution*.json (/attribution:setup reports leftovers).
Data directory: remove ~/.claude/plugins/data/provenance-melodic-software/ only if the per-machine check finds it absent or empty.
In this repository, after the fleet list names attribution: revert e84d5d72b's settings line.
Next release: remove the provenance shim, meaning its directory, its marketplace entry, the cheat-sheet exclusion, and the owner row in scripts/skill-leaf-name-registry.txt.
The renames decision and the dotfiles enablement decision are recorded in this issue.
The standards fleet-plugins.json names attribution@melodic-software, not provenance@melodic-software.
The dotfiles claude.json names attribution@melodic-software per the recorded decision.
Every fleet machine's enabledPlugins has attribution in the intended state, and no machine still enables only provenance.
This repository's temporary .claude/settings.json line from e84d5d72b is gone once the fleet list carries attribution.
A later release removes the provenance shim (tracked here or in a follow-up).
Constraints and gotchas
Writes to standards and dotfiles belong to those repositories and their own PRs. Do not edit them from this repository's session.
Removing the shim before machines update would reintroduce Plugin "provenance" not found in marketplace for anyone still enabling it.
Keep docs/specs/provenance-* and past CHANGELOG sections as history. "Provenance" in the sense of origin stays.
Context
Source: local handoff item 20260911-232631-rename-provenance-plugin-to-attribution.md, which this issue retires. Related: #4589 (closed by #4590 on merge), #4590, #3232 (a precedent hard rename, bug-report to bugs).
Problem
PR #4590 ("feat(attribution)!: rename the provenance plugin to attribution") implements the rename and closes #4589 when it merges. The consumers that live outside this repository are not covered. #4589's triage marks them "out of scope here (owner)", and #4590's Related section lists them as USER-RESERVED. Once #4590 merges, #4589 closes and nothing tracks them. The PR itself also has not been merge-gated: its Verification section still reads
PENDING.Evidence
The rename itself is settled: the operator decided on 2026-09-11 to rename
provenance@melodic-softwaretoattribution@melodic-software. The reasons: the plugin's one rule is that restated prose must be attributed, and "provenance" also means an origin note to delete incode-tidyinganddocs-hygiene.Verified this pass (2026-09-27):
c6e962623and a CI run in progress on that head. The headd1ba6d1a5named in the handoff is stale: a later commit landed.plugins/provenance/toplugins/attribution/at 0.6.0. It keepsplugins/provenance/0.6.0 as a one-release deprecation shim, with stub skills set todisable-model-invocation: true. Other changes:attribution/audit/rule-*, the config file becomes.claude/attribution.json, and the findings file becomes<ts>-attribution.md.provenance*.jsonprints a warning and is never read.renamesinmarketplace.jsonis unchanged.1bc1c2584on the branch records the one-release shim indocs/migration-playbook.md. That resolves the conflict the PR body flags (the playbook previously said a rename is a clean break with no tombstone).e84d5d72bon the branch enablesattributionin this repository's.claude/settings.json"until the fleet list names it". That is a temporary line to revert later.melodic-software/standardscomponents/cloud-environment/fleet-plugins.json:68has"provenance@melodic-software": true.melodic-software/dotfiles.chezmoidata/claude.json:600has"provenance@melodic-software": false, so there is a decision to make about whetherattributionshould be enabled there.plugins/attribution/orplugins/provenance/on the PR head referencesCLAUDE_PLUGIN_DATAorplugins/data(git grepatd1ba6d1a5). The plugin keeps its config in.claude/attribution.jsonlayers, not the data directory. So there is probably nothing to move. Verify on each machine that~/.claude/plugins/data/provenance-melodic-software/is absent or empty before deleting it.Not verified: the result of the CI run on
c6e962623; whether the review lanes ran on it.Proposed approach
/source-control:pull-request ready(merge the base, security review, fresh-context verify). Fill in the Verification section; it currently saysPENDING. Merge onceci-statusis green.renamesentryprovenance -> attribution. Upstream calls the map append-only, and the repo's frozen-map doctrine argues against it. The shim covers the one-release window without it.attribution(todayprovenanceisfalsethere).fleet-plugins.json: replace the provenance row with"attribution@melodic-software": true..chezmoidata/claude.json: rename the row and apply the decision from step 2.~/.claude/settings.jsonenabledPlugins: enableattribution, disableprovenanceafter the update lands.~/.claude/provenance.jsonor repo.claude/provenance*.json: rename toattribution*.json(/attribution:setupreports leftovers).~/.claude/plugins/data/provenance-melodic-software/only if the per-machine check finds it absent or empty.e84d5d72b's settings line.provenanceshim, meaning its directory, its marketplace entry, the cheat-sheet exclusion, and the owner row inscripts/skill-leaf-name-registry.txt.Acceptance criteria
ci-status.renamesdecision and the dotfiles enablement decision are recorded in this issue.fleet-plugins.jsonnamesattribution@melodic-software, notprovenance@melodic-software.claude.jsonnamesattribution@melodic-softwareper the recorded decision.enabledPluginshasattributionin the intended state, and no machine still enables onlyprovenance..claude/settings.jsonline frome84d5d72bis gone once the fleet list carries attribution.provenanceshim (tracked here or in a follow-up).Constraints and gotchas
Plugin "provenance" not found in marketplacefor anyone still enabling it.docs/specs/provenance-*and past CHANGELOG sections as history. "Provenance" in the sense of origin stays.Context
Source: local handoff item
20260911-232631-rename-provenance-plugin-to-attribution.md, which this issue retires. Related: #4589 (closed by #4590 on merge), #4590, #3232 (a precedent hard rename, bug-report to bugs).