Skip to content

ci: claim the Context7 library and refresh it - #64

Merged
cardmagic merged 1 commit into
mainfrom
chore/context7-claim
Oct 8, 2026
Merged

cardmagic merged 1 commit into
mainfrom
chore/context7-claim

Conversation

@cardmagic

Copy link
Copy Markdown
Owner

Why

Context7 indexed this repository on October 8, 2026, as part of the agent discoverability plan (R4). Claiming the library unlocks its admin panel and higher refresh limits. Context7 verifies a claim through the url and public_key fields in context7.json. The public_key is the maintainer's public account key, and Context7 designs it to be committed.

What changes

  • context7.json adds url and public_key. The other fields do not change.
  • .github/workflows/context7-refresh.yml asks Context7 to refresh the index after each push to main that changes the README, context7.json, docs/, or examples/. It reads the CONTEXT7_API_KEY repository secret, which is set. It uses no third-party action, and it runs with contents: read.
  • The release docs now say to confirm the workflow run instead of refreshing by hand.

Validation

  • actionlint passes on the new workflow.
  • The workflow's run: script, run locally with the same key, returned {"message":"Refresh started successfully"}.
  • context7.json parses, and the new fields come before projectTitle.

After merge, the maintainer clicks Claim Library on the Context7 admin page to finish the claim.

Context7 indexed this repository on October 8, 2026. A claimed library
has an admin panel and higher refresh limits, and Context7 verifies
the claim through the url and public_key in context7.json. The
public_key is the maintainer's public account key, which Context7
designs to be committed.

Add a workflow that asks Context7 to refresh the index after each push
to main that changes the README, context7.json, docs/, or examples/.
The release docs no longer ask for a manual refresh. The workflow's
request was run locally against the API and returned "Refresh started
successfully". It reads the CONTEXT7_API_KEY repository secret, which
is set.
@greptile-apps

greptile-apps Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Adds CI workflow that calls external API with a repository secret.

The PR appears safe to merge.

What we checked:

  • Refreshing the wrong library: The claim URL and repository URL identify the same library that LIBRARY_NAME selects.
  • Missing documentation changes: Both folders listed in context7.json appear in the workflow’s path filters.

Summary

Adds Context7 claim fields and a workflow that requests a refresh when documentation changes on main.

  • The workflow reads CONTEXT7_API_KEY from repository secrets and sends it to a fixed HTTPS endpoint.
  • Release instructions now ask the maintainer to confirm the workflow succeeded.
  • cardmagic explicitly states that the account key is public and that finishing the claim after merge is intentional.
  • No actionable issues were found.

Reviews (1) · Last reviewed commit: "ci: claim the Context7 library and refre..." · Reviewed by Greptile

@cardmagic
cardmagic merged commit befffef into main Oct 8, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant