-
Notifications
You must be signed in to change notification settings - Fork 377
[BUG] apm pack omits per-plugin version for INTERNAL/private github.com repos (raw.githubusercontent.com 404, no REST fallback) #1847
Copy link
Copy link
Closed
Labels
area/distributionInstallers (curl/PowerShell/Brew/Scoop), self-update, devcontainer, codespaces.Installers (curl/PowerShell/Brew/Scoop), self-update, devcontainer, codespaces.area/marketplacemarketplace.json schema, federation, authoring suite, source parity.marketplace.json schema, federation, authoring suite, source parity.status/acceptedHuman scope approval; verify the issue's approval record and review contact before work.Human scope approval; verify the issue's approval record and review contact before work.status/triagedAutomated advice completed; deduplication only. Not human approval; silence is not approval.Automated advice completed; deduplication only. Not human approval; silence is not approval.theme/portabilityOne manifest, every target. Multi-target deploy, marketplace, packaging, install.One manifest, every target. Multi-target deploy, marketplace, packaging, install.type/bugSomething does not work as documented.Something does not work as documented.
Description
Activity
Metadata
Metadata
Assignees
Labels
area/distributionInstallers (curl/PowerShell/Brew/Scoop), self-update, devcontainer, codespaces.Installers (curl/PowerShell/Brew/Scoop), self-update, devcontainer, codespaces.area/marketplacemarketplace.json schema, federation, authoring suite, source parity.marketplace.json schema, federation, authoring suite, source parity.status/acceptedHuman scope approval; verify the issue's approval record and review contact before work.Human scope approval; verify the issue's approval record and review contact before work.status/triagedAutomated advice completed; deduplication only. Not human approval; silence is not approval.Automated advice completed; deduplication only. Not human approval; silence is not approval.theme/portabilityOne manifest, every target. Multi-target deploy, marketplace, packaging, install.One manifest, every target. Multi-target deploy, marketplace, packaging, install.type/bugSomething does not work as documented.Something does not work as documented.
Type
Projects
- StatusShow more project fieldsDone
Describe the bug
apm packdoes not emit the per-pluginversionfield in the generated Claudemarketplace.jsonwhen the marketplace packages are remotegit-subdirreferences to a GitHub.com repository with INTERNAL (or private) visibility.Root cause: the per-plugin
versionis sourced from a best-effort "metadata enrichment" fetch of each resolved package's remoteapm.yml(marketplace/builder.py::_fetch_remote_metadata). For hosts classified asgithub.life-white.uk, APM fetches it fromhttps://raw.githubusercontent.com/.... For INTERNAL/enterprise repos,raw.githubusercontent.comreturns HTTP 404 even with a valid token, while the GitHubREST/contentsAPI serves the file correctly. APM only falls back to the REST API for GHES/GHE-Cloud hosts, never forgithub.life-white.uk. Because the fetch fails,versionis silently omitted.This is not a permissions problem: APM resolves and sends a valid token (
source=gh-auth-token), and the same 404 happens both locally and in CI.Secondary factor: the root
apm.ymlmarketplace entries pin a semver range (version: "^1.0.0"), which_is_display_version()deliberately rejects, soversiondepends exclusively on the remote fetch that is failing.To Reproduce
Steps to reproduce the behavior:
apm.ymldeclaresmarketplace.packages[]as remotegit-subdirentries (source: <owner>/<repo>+subdir:+version: "^1.0.0"), withversioning.strategy: tag_pattern.2. Ensure the referenced packages are tagged ({name}-v{version}) so resolution succeeds, and that you are authenticated (gh auth login/ a valid token).apm pack -m claude --marketplace-path claude=build/marketplace.json.plugins[]hasname,description, andsource, but noversionfield.APM_LOG_LEVEL=DEBUGand observe, for every entry:<sha>):Expected behavior
apm packshould populate the per-pluginversionfor remote entries on INTERNAL/private github.com repositories — e.g. by falling back to the GitHub REST/contentsAPI (which works with the token) whenraw.githubusercontent.comreturns 404, instead of silently droppingtheversionfield. Metadata enrichment should not depend on a CDN that does not serve INTERNAL-visibility repos.Environment (please complete the following information):
Logs
(identical 404 for all 12 marketplace entries)
Reproduced endpoint behavior:
raw.githubusercontent.com/.../apm.yml(withAuthorization: token): HTTP 404gh api repos/.../contents/.../apm.yml?ref=<sha>: returns the file (200)Additional context
marketplace/builder.py::_fetch_remote_metadata(host branch:github.com→ raw CDN; else → REST API) andmarketplace/output_mappers.py(_is_display_versionrejects semver ranges, soversionrelies solely on the remote-metadata fetch).marketplace.jsonto inject each entry'sversionread from the local leafapm.yml(the single source of truth), avoiding the remote fetch entirely.