Skip to content

Ops: pin Official catalog pluginRef (tags/commits) after #177 #292

Description

@ReBoticsAI

Summary

Follow-up ops work from #177 (Marketplace buyer protection).

Official/Community plugin installs now fail closed unless the catalog entry has an immutable pluginRef (release tag or commit sha). Optional pluginDigest must match HEAD. Floating main / master / empty is rejected.

Goal

Curate GodMode Cloud Official catalog rows (and any public Official feed entries used by SaaS) so every plugin installType entry has a real pin, not main.

Acceptance

  • Audit active Official catalog plugin entries for missing or floating plugin_ref / pluginRef
  • Set each to a release tag or commit sha (and pluginDigest where useful)
  • Confirm a free Official plugin install succeeds on Cloud after pins
  • Document operator checklist in MARKETPLACE.md or admin UI copy if needed

Related

Out of scope

Changing the pin fail-closed policy; Local/Unofficial folder installs.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    Status
    Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions