Skip to content

chore(attribution): drop the temporary settings enablement - #5430

Merged
kyle-sexton merged 5 commits into
mainfrom
chore/4668-revert-attribution-settings-line
Oct 1, 2026
Merged

kyle-sexton merged 5 commits into
mainfrom
chore/4668-revert-attribution-settings-line

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Refs: #4668

Summary

.claude/settings.json carried attribution@melodic-software: true as a temporary enablement, because the fleet plugin list in standards still named the old provenance@melodic-software id. standards#654 now enables attribution@melodic-software in that list (merged as 8f4b91a), so this line is redundant.

Fix

  • Remove "attribution@melodic-software": true from enabledPlugins in .claude/settings.json.
  • Add "provenance@melodic-software": false, in byte-sorted position. The catalog still ships the deprecated plugins/provenance shim, and scripts/check-plugin-catalog-enablement.sh fails on a catalogued plugin that neither the fleet list nor settings names. An explicit false is a recorded decision and passes the gate.

Not touched, per the owner decision on #4668: the renames map in .claude-plugin/marketplace.json, and the plugins/provenance shim (removed in a later release).

Verification

  • PLUGIN_CATALOG_ENABLEMENT_FLEET=<fleet-plugins.json from standards main after #654> bash scripts/check-plugin-catalog-enablement.sh exits 0 (84 catalogued plugins covered, none orphaned, keys sorted).
  • Without the provenance key the same run fails, so the explicit false is needed.
  • .claude/settings.json parses as JSON.
  • Merge order: dotfiles#963 (seed rename, b962d73), then standards#654 (fleet list, 8f4b91a), then this PR. standards plugin-seed-drift reads the dotfiles seed on its main branch, so the seed had to land first.

Related

🤖 Generated with Claude Code

Remove the attribution@melodic-software enablement from .claude/settings.json;
the fleet plugin list carries it. The catalog still ships the deprecated
provenance shim, so record it as an explicit false to keep
check-plugin-catalog-enablement.sh passing.

Refs #4668

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

PR body contract — issue linkage

This PR body conforms to the issue-linkage contract. Nothing to do.

Keep the docs-naming enablement main added; the attribution line stays dropped.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@kyle-sexton
kyle-sexton marked this pull request as ready for review October 1, 2026 20:56
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T20:58:53.266809Z 3b82606 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@claude

claude Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 27s —— View job


Security review — no issues found

  • Gather context (PR diff, changed files)
  • Apply skip-gate check
  • Review changed files for security-relevant issues
  • Check instruction-surface deletions against protected classes
  • Post findings / conclusion

Scope. The only change is in .claude/settings.json: it drops the "attribution@melodic-software": true key from enabledPlugins and adds "provenance@melodic-software": false in byte-sorted position. No other file changed.

Instruction-surface lens. enabledPlugins toggles are the kind of standing-config change this lane's deletion lens exists to catch, so I read it against the protected-class list in docs/conventions/instruction-exception-register/README.md (consulted — present in this checkout) rather than skipping on "it's just a config line":

  • Removing the explicit true for attribution@melodic-software doesn't disable the plugin. Per scripts/check-plugin-catalog-enablement.sh's documented coverage rule, a catalogued plugin is covered when either the fleet list in standards enables it or this file carries an explicit key — and standards#654 (merged, per the PR body) now enables it in the fleet list. If that merge order were ever wrong, the same gate's "UNENABLED PLUGIN" check fails loudly in CI rather than silently dropping coverage, so a deterministic validator still enforces the property the deleted line used to. That takes it out of the register's finding criteria ("a rule that a mechanism still enforces is not a finding").
  • "provenance@melodic-software": false is an explicit, recorded opt-out of a deprecated shim plugin — tightening, not loosening, and it's required for the same gate to pass (an uncovered catalog entry is the gate's other failure mode).

Other checks. No changes to permissions, hooks, env, or extraKnownMarketplaces; no secrets, tokens, or credential handling; no injection surface; no GitHub Actions workflow touched (this lane defers workflow-hardening findings to zizmor regardless).

No security findings to report.

@claude

claude Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 1m 25s —— View job


CI code review

  • Gather context (diff, PR body, check-plugin-catalog-enablement.sh, catalog)
  • Understand the request (/review:code-review lane)
  • Review the diff
  • Post results

Skip gate: this PR is a 2-line, mechanical .claude/settings.json edit — remove "attribution@melodic-software": true, add "provenance@melodic-software": false in byte-sorted position. No meaningful review surface beyond what's checked below, so no findings to report.

What I checked:

  • Diff matches the PR description exactly (verified via git diff origin/main HEAD -- .claude/settings.json and gh pr diff).
  • enabledPlugins keys stay in byte order after the edit (animation … playgrounds, provenance, retro-audio).
  • .claude/settings.json parses as valid JSON (jq empty).
  • Both attribution and provenance remain catalogued in .claude-plugin/marketplace.json (84 total catalogued plugins, matching the PR's claim), and both plugin directories still exist on disk — consistent with the PR's statement that the provenance shim removal is deferred to a later release.
  • Read scripts/check-plugin-catalog-enablement.sh: an explicit false key does count as coverage for a catalogued-but-unenabled plugin, so the added "provenance@melodic-software": false is the correct way to satisfy that gate for a plugin not named by the fleet list.

Not independently verified (author-claimed): whether melodic-software/standards#654 actually flips attribution@melodic-software to true in the fleet list, and the PR's merge-order claim. This sandbox has no network access to fetch components/cloud-environment/fleet-plugins.json from the standards repo, so I could not run check-plugin-catalog-enablement.sh myself. If the fleet list does not yet enable attribution@melodic-software, the same script (wired into .github/workflows/ci.yml) will fail CI with an UNENABLED PLUGIN error on this PR's head — so this is self-guarding rather than a silent risk, but I'm flagging it as unverified by me rather than confirmed.

No findings.

@kyle-sexton
kyle-sexton merged commit b04fd1f into main Oct 1, 2026
30 of 39 checks passed
@kyle-sexton
kyle-sexton deleted the chore/4668-revert-attribution-settings-line branch October 1, 2026 21:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant