feat(attribution)!: rename the provenance plugin to attribution - #4590
Merged
Merged
Conversation
Move plugins/provenance to plugins/attribution at 0.6.0. The skill ids
become attribution:audit and attribution:setup, emitted rule ids use the
attribution/audit/ prefix, the persisted findings file is
${TS}-attribution.md, and the config cascade reads attribution.json and
attribution.local.json. A layer holding only the legacy provenance file
name is never read and draws one stderr warning naming it.
Repo wiring follows: the marketplace entry (the renames map is
unchanged and the provenance tag stays as a search alias), the AGENTS.md
on-demand row, .claude/attribution.json, the unhobble mirror path
fields, the detector-findings crosswalk rows with a 3.1.2 patch entry,
the em-dash purged-paths list, the audit row of the skill leaf-name
registry (it lists provenance too, for the shim), and the regenerated
catalog and cheat sheet.
BREAKING CHANGE: install id, skill ids, rule-id prefix, config file name
and findings file name all change from provenance to attribution.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…copy row The crosswalk row's remediation cell still named the old skill id. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
plugins/provenance returns for one release at 0.6.0 so existing installs update to a notice instead of a not-found error. Its audit and setup stubs set disable-model-invocation, carry no workflow metadata, and tell the user to install attribution, drop the provenance entry from enabledPlugins, rename .claude/provenance.json, and re-run under /attribution:*. The CHANGELOG keeps the full base history under a new 0.6.0 section. The marketplace lists the shim as deprecated (renames unchanged) and the cheat sheet excludes it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Reference-only edits in docs-hygiene, review, codebase-health, code-tidying and playbooks after the provenance plugin became attribution. Patch bump and CHANGELOG entry per plugin. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- State that the legacy-config warning fires only when a layer has no attribution file (README and CHANGELOG), matching lib.sh and its test. - Use a colon on all three emit-findings "Not auto-applicable" cells. - Shim stubs name every legacy config file and layer, state their done condition, and the setup stub's evals use its real actions. - CHANGELOG says the old install id now resolves to the shim. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…ames it Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…ventions The plugin stops reading .claude/provenance.json and .claude/provenance.local.json, and plugin-philosophy makes a retirements.yaml record mandatory for a file a plugin no longer reads. Ships attribution-r001/r002 (migrate), the synced check-retirements.sh helper, the setup check/apply wiring, and one eval per record. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
… a scoped rename Upstream has no deprecation state and a removed name without a renames entry reports 'Plugin not found in marketplace' (https://code.claude.com/docs/en/plugins/host-marketplace#rename-or-remove-a-plugin). The renames map stays frozen; #4589 scopes a shim for provenance -> attribution. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…gin-to-attribution Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
… rename Keep main's playbooks 0.13.2 (#4601) and review 0.30.5 (code-reviewer description). Land this PR's attribution catalog and crosswalk edits as playbooks 0.13.3 and review 0.30.6. Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…gin-to-attribution # Conflicts: # plugins/playbooks/CHANGELOG.md Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
# Conflicts: # plugins/playbooks/CHANGELOG.md # plugins/review/CHANGELOG.md Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…gin-to-attribution # Conflicts: # plugins/provenance/.claude-plugin/plugin.json # plugins/provenance/CHANGELOG.md # plugins/provenance/skills/audit/SKILL.md Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
2 tasks done
This was referenced Sep 27, 2026
cursor Bot
pushed a commit
that referenced
this pull request
Sep 27, 2026
<!-- CURSOR_AGENT_PR_BODY_BEGIN --> Fixes #4267 ## Summary Takes the fix the issue favours: flip the confidence rank order instead of banning `low`. - `plugins/review/context/severity.md` ranks `high` > `medium` > `low` > `unscored` and labels every finding with the value its evidence supports. - `code-reviewer` keeps a `Confidence:` value even when the caller supplies its own finding shape. - Detector-findings convention rule 2 unchanged (`high` or omitted); rationale rewritten. `mutation-testing` 0.4.2 drops the false clause. New fanout eval 39 covers unscored sorting last. `review` 0.30.6 → 0.31.0. ## Research trail - `severity.md` owned the inverted order; fanout/fix-pass defer to it. - Detector producers cite the unchanged rule, not the order. ## Test plan - [x] validate-plugins, changed-skills, changelog parity, detector-findings crosswalk - [x] `standards-binding.test.sh` PASS=8; markdownlint clean ## Notes Serialized behind #4624. Open PRs #4622 and #4590 also bump `review` (version-line only). <!-- CURSOR_AGENT_PR_BODY_END --> <div><a href="https://cursor.com/agents/bc-ab53da24-b89d-4314-a060-0da474e837e9?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-web-light.png"><img alt="Open in Web" width="114" height="28" src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a> <a href="https://cursor.com/background-agent?bcId=bc-ab53da24-b89d-4314-a060-0da474e837e9&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img alt="Open in Cursor" width="131" height="28" src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a> </div> Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #4589
Summary
Renames the
provenanceplugin toattribution, so the name says what the plugin gets you: prosethat restates an external source attributes it.
provenancestays for one release as adeprecation shim, because a plugin id that disappears without a
renamesentry reportsPlugin "<name>" not found in marketplaceto everyone who has it installed(host-marketplace, "Uninstall removed plugins from users' machines").
Fix
plugins/provenance/moved toplugins/attribution/withgit mv(67 files). The plugin is nowat 0.6.0, and its CHANGELOG notes each breaking change:
attribution@melodic-software./attribution:auditand/attribution:setup.attribution/audit/rule-*..claude/attribution.json(user, team and.locallayers). A leftoverprovenance*.jsonprints a one-line warning and is never read.<ts>-attribution.md.attribution:source. Existingprovenance:sourcefences stillwork, because the breadcrumb extractor matches any URL-carrying comment fence rather than a
literal.
plugins/provenance/0.6.0 shim:disable-model-invocation: truethat point toattribution:*.marketplace.json: an attribution entry plus the deprecated shim entry.renamesisunchanged.
AGENTS.mdrow..claude/provenance.jsonrenamed to.claude/attribution.json.scripts/skill-leaf-name-registry.txt,scripts/em-dash-purged-paths.txt,scripts/cheatsheet-config.mjs.docs/conventions/detector-findingsrows, with a 3.1.2 entry.docs/catalog.md.0.30.5 (crosswalk rule ids), codebase-health 0.10.1, code-tidying 0.23.3, playbooks 0.13.2.
docs/specs/provenance-*, as history.provenancefields in other plugins.Verification
PENDING
Related
from the item or the lane notes, and a fresh-context validator challenged the answers without
seeing the reasoning. The full register is in the branch's PLAN (local).
owner to decide:
docs/migration-playbook.mdsays a rename "is a clean breaking changecarried by a version bump and a changelog note" and a retirement gets "No tombstone", and
feat(bugs)!: rename the bug-report plugin to bugs #3232 (bug-report -> bugs) was a hard rename.
added), Q5 (findings filename), Q6 (keep
provenanceas a tag), Q7 (unhobble paths):confirmed.
provenance:sourcemarker example.renamesentry (provenance->attribution). Upstream calls the map append-only,and it reverses the frozen-map doctrine.
.chezmoidata/claude.jsonseed.components/cloud-environment/fleet-plugins.jsonin melodic-software/standards.enabledPlugins.~/.claude/plugins/data/provenance-melodic-software/.provenanceshim (its directory, marketplace entry, cheat-sheetexclusion and leaf-registry owner) in a later release.
🤖 Generated with Claude Code