Skip to content

chore: regenerate catalog from OpenAPI spec - #18

Merged
dangrondahl merged 1 commit into
mainfrom
chore/update-catalog
Aug 11, 2026
Merged

dangrondahl merged 1 commit into
mainfrom
chore/update-catalog

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Automated catalog update from the Kosli OpenAPI spec.

Please review the diff to verify the changes look correct before merging.

@github-actions
github-actions Bot force-pushed the chore/update-catalog branch from bcc853c to 8ca134b Compare August 10, 2026 07:30
@dangrondahl
dangrondahl merged commit 0ab45d1 into main Aug 11, 2026
1 check passed
@dangrondahl
dangrondahl deleted the chore/update-catalog branch August 11, 2026 11:07
dangrondahl added a commit that referenced this pull request Aug 11, 2026
The `main` ruleset requires signed commits.
`peter-evans/create-pull-request` pushes unsigned commits by default, so
every weekly `update-catalog` PR is blocked at merge even after passing
CI and review — #18 is the current example (`verified: false`, `reason:
"unsigned"`).
dangrondahl added a commit that referenced this pull request Aug 11, 2026
Closes #32. Modelled on [terraform-provider-kosli's
`claude-review.yaml`](https://github.com/kosli-dev/terraform-provider-kosli/blob/main/.github/workflows/claude-review.yaml),
adapted to this repo.

## Three jobs, split by PR author

| Job | Fires on | Budget |
| :-- | :-- | :-- |
| `review-dependency-updates` | `dependabot[bot]` | $3 |
| `review-catalog-update` | `github-actions[bot]` on
`chore/update-catalog` | $3 |
| `review-general` | everyone else | $5 |

Classification uses `pull_request.user.login` rather than
`github.actor`, so a job doesn't change identity when a human pushes to
a bot's branch.

### The catalog job

This one has no counterpart upstream, and it is the reason a third job
exists. The reference's dependency prompt is about changelogs and
semver, which says nothing useful about a regenerated catalog.

Instead it summarises added, removed, and changed actions, and insists
that **removals be confirmed against the live spec before merge**. That
case has come up twice: #16 was a stale branch clobbering the catalog,
#18 was a genuine upstream retirement of `list_artifact_approvals`. The
diff alone cannot tell those apart. It also greps `src/`, `test/`, and
`README.md` for now-dangling references, and flags any `$ref` that
survived into the catalog.

### General job

The prompt checks the deliberate design decisions recorded in
`CLAUDE.md`: three generic tools and no tool per endpoint, generated
catalog, the non-throwing `{ error: true, ... }` contract, compact
`JSON.stringify`, the `org` fallback, the `User-Agent` header, ESM `.js`
import extensions, `strict: true`, no HTTP client library, and the
`readOnlyHint` / `destructiveHint` split.

## Security and conventions

- **Fork PRs are skipped** in all three jobs. They run without the OIDC
credentials this needs, and on a public repo an unguarded trigger would
let anyone spend budget.
- **OIDC federation** via org-wide vars, no API key secret. This is also
what makes the bot paths work: Dependabot-triggered runs cannot read
Actions secrets. Confirmed working on a Dependabot PR in
`terraform-provider-kosli` (PR 232), which is itself a public repo.
- **SHA-pinned actions** with version comments, and `harden-runner`
first in every job, matching the other three workflows.
- Only `github.repository` and the PR number are interpolated, and only
into `prompt:` — never into a `run:` step.

## Before merging

- **Model is `claude-opus-5`**, not the reference's `claude-opus-4-8`.
If the federation rule doesn't permit it the first run fails loudly;
switch to `claude-opus-4-8`, which is proven in the provider repo.
- **`actions/checkout` is pinned to v6.0.2** to match the rest of the
repo. #30 bumps it to v7.0.1 — after this merges, rebase #30 and it will
update all four workflows together.
- Worth confirming `mcp-server` is in scope for the `ANTHROPIC_*` org
variables. Reading that config needs `admin:org`, so I couldn't check.
FayeSGW pushed a commit that referenced this pull request Aug 11, 2026
Version bump only — `package.json` and `package-lock.json`. Merge this,
then tag `v0.5.0` on `main` to trigger the release.

## What ships

One user-facing change since `v0.4.0`: the regenerated catalog from #18.

- `list_flows` gains `space_id` and `tag` query filters
- `include_scaling` is marked `deprecated`
- `list_artifact_approvals` is **removed** — the endpoint was retired
upstream

Everything else since `v0.4.0` is CI, docs, and repo hygiene, none of
which reaches the npm tarball. The README does ship, so the new beta
notice and write-action caution go out with this.

## Why minor, not patch

An action disappearing from the catalog is user-visible: anything
calling `list_artifact_approvals` via `execute_read_action` stops
resolving. Pre-1.0, a minor bump is the conventional signal for that,
even though the removal originated upstream rather than here.

## Notes

- `manifest.json` still holds its `0.0.0-replaced-at-build-time`
placeholder, injected by the pack script — untouched, as intended.
- Both `package.json` and `package-lock.json` were updated via `npm
version --no-git-tag-version`, so the lockfile doesn't drift.
- Tests pass locally: 8 files, 65 tests.
- This should be the first release carrying npm provenance, now that the
repo is public and #35 has landed. Verify after publish with `npm view
@kosli/mcp-server dist.attestations` — it returned `null` for 0.4.0.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant