tcballard/build-omarchy-plugins
Design, scaffold, implement, test, debug, demo, release, migrate, and publish Omarchy 4 Quattro shell plugins.
Changelog
All notable changes to Build Omarchy Plugins are documented here.
0.5.0 — Unreleased
- Recommend Omakit for reusable Run/Store helpers, local marketplace checks and submission preparation.
- Check prior art before new builds and establish personal, public-repository or marketplace intent early, with a small first feature and observable criteria.
- Guide implementation through concrete examples and relevant fixture checks.
- Define release readiness, configuration migration/recovery and evidence for each supported CPU architecture.
- Recommend the community security skill and OmaVM as optional companions.
- Verify current marketplace mechanics, candidate SHA and authenticated submission boundaries as the marketplace evolves.
- Synchronize canonical and packaged skills; add three operator-run behavioral scenarios without claiming they have been executed.
0.4.1 — 2026-09-20
- Incorporate 20 September marketplace review evidence for dependency/CI pinning, agent integrations, independent privileged trust, image/aggregate limits and stale backend releases.
- Add advisory discovery of workflow action references/permissions and distributed agent configuration directories, with behavioral regression fixtures.
- Explain validator-pattern capability warnings without suppressing disclosures.
- Keep workflow scanning responsive on large whitespace inputs.
- Clarify plugin/theme ownership and keep installed references self-contained.
0.4.0 — 2026-09-14
Includes the fixes prepared for the unpublished v0.3.2 draft.
-
Add commit-pinned Omarchy identity/category and compatibility badges with the official icon.
-
Standardise compact README badge rows: CI, licence, identity, then compatibility.
-
Apply the badge row to this repository and document consistent height and mobile wrapping.
-
Define compatibility as the installed Omarchy version, reported by
omarchy-version. -
Pair badge categories with consistent GitHub topics for project discovery.
-
Catch privilege-tool mentions in documentation before marketplace submission, including negated prose and real commands on the same line.
-
Explain documentation-only capability warnings and distinguish compatibility, security review, maintainer approval and publication at the exact candidate SHA.
-
Pin the marketplace security policy and synchronize portable/OpenAI guidance.
-
Document skill workflows and evidence handoffs, including stale-candidate and marketplace-review behavioral cases; these cases are not recorded model runs.
-
Align version metadata, installation examples and submission materials with v0.4.0.
0.3.1 — 2026-09-12
- Add native Claude Code packaging and adoption documentation.
- Incorporate marketplace reviewer evidence into targeted pre-submission guidance.
- Allow the release workflow to create a new annotated tag after exact-commit checks.
- Update marketplace submission categories and tag labels against a pinned upstream form.
- Add advisory checks and a reviewer-response evidence table for recurring findings.
- Require strict Claude manifest validation in CI alongside the cross-platform matrix.
- Align release metadata, installation examples and submission materials with v0.3.1.
0.3.0
-
Review all twelve skills against OpenAI Astra and Anthropic Fable guidance.
-
Preserve authorized task scope, settled decisions and evidence-backed progress.
-
Make testing proportional, helper paths explicit and Workbench registration optional.
-
Fix host-conformance text output and Codex ancestor/duplicate discovery.
-
Add provider guidance, dated reviews and ten behavioral evaluation cases.
-
Generate agent-neutral Workbench environment probes and a capability-gated validation workflow.
-
Generate the schema-one Plugin Workbench project definition by default.
-
Register
./tests/runas an explicit, initially untrusted Workbench check. -
Pin and verify the upstream Workbench authoring contract.
-
Document the separately versioned builder and local-lifecycle companion boundary.
0.2.3 — 2026-08-31
- Validate every GitHub Actions workflow with pinned actionlint and include workflow validation in the stable required CI gate.
- Repair draft-release recovery by inspecting unpublished drafts through the GitHub CLI instead of a REST tag endpoint that excludes draft releases.
- Retry newly created draft asset downloads with bounded backoff before the byte-for-byte release comparison, while preserving exact tag/main binding and owner-controlled publication.
0.2.2 — 2026-08-31
- Add transactional install, update, diff, recovery, and conservative uninstall with receipts, locks, symlink/hardlink defenses, and managed-file integrity.
- Add read-only discovery diagnostics for Codex, Cursor, Gemini CLI, Claude Code, and OpenCode, plus a deny-by-default OpenCode live-conformance probe.
- Build byte-reproducible archives from one exact Git tree with release/source manifests, SPDX 2.3 SBOM, and complete SHA-256 coverage.
- Add exact-tree secret, binary, symlink, QML capability, and trust-boundary scanning without presenting static findings as a security guarantee.
- Harden scaffolding and validation against duplicate JSON keys, oversized or special files, unsafe ancestors, dynamic QML behavior, and unpinned actions.
- Bind tagged release preflights to annotated local/remote tags, the remote default branch, historical reachability, downloaded assets, and checksums.
- Add PR-only contribution policy, immutable action pins, a Linux/macOS/Windows CI matrix, CodeQL, upstream-contract drift checks, and draft-only release automation with owner-controlled publication.
- Expand installation, removal, reviewer, submission, and release documentation while keeping provider and live-host claims evidence-bounded.
0.2.1 — 2026-08-30
- Add an explicit OpenCode installer target using its native project and global Agent Skills directories.
- Add OpenCode installation and idempotency coverage to the host matrix.
- Document that OpenCode can also discover the shared
.agents/skillstarget.
0.2.0 — 2026-08-30
- Add a provider-neutral Agent Plugins 1.0.0 package at the repository root.
- Make the twelve canonical skills free of provider-specific metadata.
- Add safe project/user installers for shared Agent Skills, Codex, Cursor, Gemini CLI, Claude Code, and custom destinations.
- Preserve the existing OpenAI plugin as a thin adapter with deterministic source synchronisation and drift checks.
- Add offline portable-manifest validation, conflict/idempotency tests, and a deterministic Agent Plugin release archive.
- Document the exact portability, runtime, safety, and live-evaluation boundary.
0.1.0 — 2026-08-29
- Add twelve routed skills covering the complete Omarchy 4 Quattro plugin lifecycle.
- Add a repository generator for all six current shell plugin kinds.
- Add structural, path, symlink, QML, and advisory security validation.
- Add read-only diagnostics, deterministic demos, release preflight, and marketplace submission tooling.
- Add migration guidance for separating legacy machine integration from Quattro shell surfaces.
- Add repeatable tests, submission archives, artwork, policies, and reviewer materials.