Repository navigation
chore: regenerate catalog from OpenAPI spec - #18
Merged
Merged
Conversation
github-actions
Bot
force-pushed
the
chore/update-catalog
branch
from
August 10, 2026 07:30
bcc853c to
8ca134b
Compare
dangrondahl
approved these changes
Aug 10, 2026
This was referenced Aug 11, 2026
dangrondahl
added a commit
that referenced
this pull request
Aug 11, 2026
The `main` ruleset requires signed commits. `peter-evans/create-pull-request` pushes unsigned commits by default, so every weekly `update-catalog` PR is blocked at merge even after passing CI and review — #18 is the current example (`verified: false`, `reason: "unsigned"`).
This was referenced Aug 11, 2026
dangrondahl
added a commit
that referenced
this pull request
Aug 11, 2026
Closes #32. Modelled on [terraform-provider-kosli's `claude-review.yaml`](https://github.com/kosli-dev/terraform-provider-kosli/blob/main/.github/workflows/claude-review.yaml), adapted to this repo. ## Three jobs, split by PR author | Job | Fires on | Budget | | :-- | :-- | :-- | | `review-dependency-updates` | `dependabot[bot]` | $3 | | `review-catalog-update` | `github-actions[bot]` on `chore/update-catalog` | $3 | | `review-general` | everyone else | $5 | Classification uses `pull_request.user.login` rather than `github.actor`, so a job doesn't change identity when a human pushes to a bot's branch. ### The catalog job This one has no counterpart upstream, and it is the reason a third job exists. The reference's dependency prompt is about changelogs and semver, which says nothing useful about a regenerated catalog. Instead it summarises added, removed, and changed actions, and insists that **removals be confirmed against the live spec before merge**. That case has come up twice: #16 was a stale branch clobbering the catalog, #18 was a genuine upstream retirement of `list_artifact_approvals`. The diff alone cannot tell those apart. It also greps `src/`, `test/`, and `README.md` for now-dangling references, and flags any `$ref` that survived into the catalog. ### General job The prompt checks the deliberate design decisions recorded in `CLAUDE.md`: three generic tools and no tool per endpoint, generated catalog, the non-throwing `{ error: true, ... }` contract, compact `JSON.stringify`, the `org` fallback, the `User-Agent` header, ESM `.js` import extensions, `strict: true`, no HTTP client library, and the `readOnlyHint` / `destructiveHint` split. ## Security and conventions - **Fork PRs are skipped** in all three jobs. They run without the OIDC credentials this needs, and on a public repo an unguarded trigger would let anyone spend budget. - **OIDC federation** via org-wide vars, no API key secret. This is also what makes the bot paths work: Dependabot-triggered runs cannot read Actions secrets. Confirmed working on a Dependabot PR in `terraform-provider-kosli` (PR 232), which is itself a public repo. - **SHA-pinned actions** with version comments, and `harden-runner` first in every job, matching the other three workflows. - Only `github.repository` and the PR number are interpolated, and only into `prompt:` — never into a `run:` step. ## Before merging - **Model is `claude-opus-5`**, not the reference's `claude-opus-4-8`. If the federation rule doesn't permit it the first run fails loudly; switch to `claude-opus-4-8`, which is proven in the provider repo. - **`actions/checkout` is pinned to v6.0.2** to match the rest of the repo. #30 bumps it to v7.0.1 — after this merges, rebase #30 and it will update all four workflows together. - Worth confirming `mcp-server` is in scope for the `ANTHROPIC_*` org variables. Reading that config needs `admin:org`, so I couldn't check.
FayeSGW
pushed a commit
that referenced
this pull request
Aug 11, 2026
Version bump only — `package.json` and `package-lock.json`. Merge this, then tag `v0.5.0` on `main` to trigger the release. ## What ships One user-facing change since `v0.4.0`: the regenerated catalog from #18. - `list_flows` gains `space_id` and `tag` query filters - `include_scaling` is marked `deprecated` - `list_artifact_approvals` is **removed** — the endpoint was retired upstream Everything else since `v0.4.0` is CI, docs, and repo hygiene, none of which reaches the npm tarball. The README does ship, so the new beta notice and write-action caution go out with this. ## Why minor, not patch An action disappearing from the catalog is user-visible: anything calling `list_artifact_approvals` via `execute_read_action` stops resolving. Pre-1.0, a minor bump is the conventional signal for that, even though the removal originated upstream rather than here. ## Notes - `manifest.json` still holds its `0.0.0-replaced-at-build-time` placeholder, injected by the pack script — untouched, as intended. - Both `package.json` and `package-lock.json` were updated via `npm version --no-git-tag-version`, so the lockfile doesn't drift. - Tests pass locally: 8 files, 65 tests. - This should be the first release carrying npm provenance, now that the repo is public and #35 has landed. Verify after publish with `npm view @kosli/mcp-server dist.attestations` — it returned `null` for 0.4.0.
This was referenced Aug 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated catalog update from the Kosli OpenAPI spec.
Please review the diff to verify the changes look correct before merging.