Skip to content

fix(pstack): include licenses and attribution in plugin packages - #83

Merged
arjitj2 merged 1 commit into
mainfrom
arjit/package-attribution
Sep 28, 2026
Merged

arjitj2 merged 1 commit into
mainfrom
arjit/package-attribution

Conversation

@arjitj2

@arjitj2 arjitj2 commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Closes #82

What changed

Plugin installations now include the full MIT license texts and attribution notice. Eric Litman's Open Pstack port is explicitly credited in Included Sources. A static CI check rejects missing, symlinked, or divergent package copies. Package version is 1.9.1.

The contributor guide documents the now-active main branch rules: pull requests and an up-to-date GitHub Actions verify check are required, including for the owner. Force pushes and branch deletion are blocked; external approvals remain optional.

Verification

  • GitHub Actions CI passed the complete test suite, strict typechecking, maintenance and documentation tests, ledger check, and static invariants. Local checks also passed after routing Node-dependent tests through the bundled runtime because the system Node executable has a missing library.
  • 27 maintenance tests, 16 documentation tests, documentation checks, static invariants, and Claude plugin validation passed.
  • Installed the exact candidate through local marketplaces in isolated Codex CLI 0.158.0 and Claude Code 2.1.282 profiles. Both installed 1.9.1 and matched all 212 candidate files byte-for-byte, excluding generated dependencies. The four license/notice files and Eric's credit were present in both caches.
  • Ran the actual static checker against disposable fixtures. Missing LICENSE, altered NOTICE, and symlinked LICENSE each failed; the restored fixture passed.
  • Read back the live branch protection API to verify required PRs, GitHub Actions app-bound verify checks, strict up-to-date checks, admin enforcement, and blocked force pushes/deletion.

No provider behavior changed. Personal plugin installations were not modified.

Documentation impact

Updated canonical NOTICE.md, CONTRIBUTING.md, CHANGELOG.md, and the version in UPSTREAM.md. License texts retain the upstream copyright statements.

Copilot review was requested but could not run because the requesting account has exhausted its review quota.

@arjitj2
arjitj2 requested a lite review from Copilot September 28, 2026 19:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@arjitj2

arjitj2 commented Sep 28, 2026

Copy link
Copy Markdown
Owner Author

Independent verification passed for 23f2e2a.

Both Codex and Claude marketplace installers produced version 1.9.1 in isolated profiles. All 212 installed files matched the candidate. Full license texts and the attribution notice were retained, including Eric Litman's Included Sources credit. Static checks, documentation validation, and Claude plugin validation passed. The new guard rejected missing, changed, and symlinked license fixtures. No correctness findings.

GitHub Actions CI also passed. Copilot could not review because the requesting account reached its review quota; there are no inline review threads to address.

@arjitj2
arjitj2 merged commit 3cd847b into main Sep 28, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Protect main and include attribution in plugin installations

2 participants