Skip to content

feat(attribution)!: rename the provenance plugin to attribution - #4590

Merged
cursor[bot] merged 14 commits into
mainfrom
rename-provenance-plugin-to-attribution
Sep 27, 2026
Merged

cursor[bot] merged 14 commits into
mainfrom
rename-provenance-plugin-to-attribution

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

Closes #4589

Summary

Renames the provenance plugin to attribution, so the name says what the plugin gets you: prose
that restates an external source attributes it. provenance stays for one release as a
deprecation shim, because a plugin id that disappears without a renames entry reports
Plugin "<name>" not found in marketplace to everyone who has it installed
(host-marketplace, "Uninstall removed plugins from users' machines").

Fix

  • plugins/provenance/ moved to plugins/attribution/ with git mv (67 files). The plugin is now
    at 0.6.0, and its CHANGELOG notes each breaking change:
    • Install id attribution@melodic-software.
    • Skills /attribution:audit and /attribution:setup.
    • Rule ids attribution/audit/rule-*.
    • Config file .claude/attribution.json (user, team and .local layers). A leftover
      provenance*.json prints a one-line warning and is never read.
    • Findings file <ts>-attribution.md.
    • The README marker example is attribution:source. Existing provenance:source fences still
      work, because the breadcrumb extractor matches any URL-carrying comment fence rather than a
      literal.
  • A new plugins/provenance/ 0.6.0 shim:
    • A CHANGELOG with every earlier heading kept.
    • A README that explains the migration.
    • Two stub skills with disable-model-invocation: true that point to attribution:*.
    • Minimal evals.
    • Excluded from the cheat sheet.
  • Repo wiring:
    • marketplace.json: an attribution entry plus the deprecated shim entry. renames is
      unchanged.
    • AGENTS.md row.
    • .claude/provenance.json renamed to .claude/attribution.json.
    • scripts/skill-leaf-name-registry.txt, scripts/em-dash-purged-paths.txt,
      scripts/cheatsheet-config.mjs.
    • The unhobble manifest mirror's paths.
    • docs/conventions/detector-findings rows, with a 3.1.2 entry.
    • Regenerated docs/catalog.md.
  • Reference-only edits, each with a patch bump and a CHANGELOG entry: docs-hygiene 0.23.2, review
    0.30.5 (crosswalk rule ids), codebase-health 0.10.1, code-tidying 0.23.3, playbooks 0.13.2.
  • Kept as they were:
    • Past CHANGELOG sections and docs/specs/provenance-*, as history.
    • The word "provenance" where it means origin.
    • The JSON provenance fields in other plugins.

Verification

PENDING

Related

  • This was an unattended interview. The lane lead answered each open question with the default
    from the item or the lane notes, and a fresh-context validator challenged the answers without
    seeing the reasoning. The full register is in the branch's PLAN (local).
    • Q1: rename cleanly or ship a shim? Shim, and the validator confirmed it. Conflict for the
      owner to decide: docs/migration-playbook.md says a rename "is a clean breaking change
      carried by a version bump and a changelog note" and a retirement gets "No tombstone", and
      feat(bugs)!: rename the bug-report plugin to bugs #3232 (bug-report -> bugs) was a hard rename.
    • Q2 (skill ids), Q3 (rule-id prefix), Q4 (config filename, with the warning the validator
      added), Q5 (findings filename), Q6 (keep provenance as a tag), Q7 (unhobble paths):
      confirmed.
    • Q8: the validator overturned keeping the provenance:source marker example.
  • USER-RESERVED, left out of this PR:
    • Adding a renames entry (provenance -> attribution). Upstream calls the map append-only,
      and it reverses the frozen-map doctrine.
    • The dotfiles .chezmoidata/claude.json seed.
    • components/cloud-environment/fleet-plugins.json in melodic-software/standards.
    • Each machine's enabledPlugins.
    • The data directory ~/.claude/plugins/data/provenance-melodic-software/.
  • Follow-up: remove the provenance shim (its directory, marketplace entry, cheat-sheet
    exclusion and leaf-registry owner) in a later release.

🤖 Generated with Claude Code

kyle-sexton and others added 5 commits September 27, 2026 10:24
Move plugins/provenance to plugins/attribution at 0.6.0. The skill ids
become attribution:audit and attribution:setup, emitted rule ids use the
attribution/audit/ prefix, the persisted findings file is
${TS}-attribution.md, and the config cascade reads attribution.json and
attribution.local.json. A layer holding only the legacy provenance file
name is never read and draws one stderr warning naming it.

Repo wiring follows: the marketplace entry (the renames map is
unchanged and the provenance tag stays as a search alias), the AGENTS.md
on-demand row, .claude/attribution.json, the unhobble mirror path
fields, the detector-findings crosswalk rows with a 3.1.2 patch entry,
the em-dash purged-paths list, the audit row of the skill leaf-name
registry (it lists provenance too, for the shim), and the regenerated
catalog and cheat sheet.

BREAKING CHANGE: install id, skill ids, rule-id prefix, config file name
and findings file name all change from provenance to attribution.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…copy row

The crosswalk row's remediation cell still named the old skill id.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
plugins/provenance returns for one release at 0.6.0 so existing installs
update to a notice instead of a not-found error. Its audit and setup stubs
set disable-model-invocation, carry no workflow metadata, and tell the user
to install attribution, drop the provenance entry from enabledPlugins,
rename .claude/provenance.json, and re-run under /attribution:*. The
CHANGELOG keeps the full base history under a new 0.6.0 section. The
marketplace lists the shim as deprecated (renames unchanged) and the cheat
sheet excludes it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Reference-only edits in docs-hygiene, review, codebase-health, code-tidying
and playbooks after the provenance plugin became attribution. Patch bump and
CHANGELOG entry per plugin.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- State that the legacy-config warning fires only when a layer has no
  attribution file (README and CHANGELOG), matching lib.sh and its test.
- Use a colon on all three emit-findings "Not auto-applicable" cells.
- Shim stubs name every legacy config file and layer, state their done
  condition, and the setup stub's evals use its real actions.
- CHANGELOG says the old install id now resolves to the shim.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
cursoragent and others added 5 commits September 27, 2026 20:16
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…ames it

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…ventions

The plugin stops reading .claude/provenance.json and .claude/provenance.local.json,
and plugin-philosophy makes a retirements.yaml record mandatory for a file a
plugin no longer reads. Ships attribution-r001/r002 (migrate), the synced
check-retirements.sh helper, the setup check/apply wiring, and one eval per
record.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
… a scoped rename

Upstream has no deprecation state and a removed name without a renames entry
reports 'Plugin not found in marketplace'
(https://code.claude.com/docs/en/plugins/host-marketplace#rename-or-remove-a-plugin).
The renames map stays frozen; #4589 scopes a shim for provenance -> attribution.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…gin-to-attribution

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@cursor
cursor Bot marked this pull request as ready for review September 27, 2026 20:39
@cursor
cursor Bot enabled auto-merge (squash) September 27, 2026 20:39
cursoragent and others added 4 commits September 27, 2026 20:40
… rename

Keep main's playbooks 0.13.2 (#4601) and review 0.30.5 (code-reviewer
description). Land this PR's attribution catalog and crosswalk edits as
playbooks 0.13.3 and review 0.30.6.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…gin-to-attribution

# Conflicts:
#	plugins/playbooks/CHANGELOG.md

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
# Conflicts:
#	plugins/playbooks/CHANGELOG.md
#	plugins/review/CHANGELOG.md

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
…gin-to-attribution

# Conflicts:
#	plugins/provenance/.claude-plugin/plugin.json
#	plugins/provenance/CHANGELOG.md
#	plugins/provenance/skills/audit/SKILL.md

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@cursor
cursor Bot merged commit 2669391 into main Sep 27, 2026
18 checks passed
@cursor
cursor Bot deleted the rename-provenance-plugin-to-attribution branch September 27, 2026 21:05
cursor Bot pushed a commit that referenced this pull request Sep 27, 2026
<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
Fixes #4267

## Summary

Takes the fix the issue favours: flip the confidence rank order instead
of banning `low`.

- `plugins/review/context/severity.md` ranks `high` > `medium` > `low` >
`unscored` and labels every finding with the value its evidence
supports.
- `code-reviewer` keeps a `Confidence:` value even when the caller
supplies its own finding shape.
- Detector-findings convention rule 2 unchanged (`high` or omitted);
rationale rewritten. `mutation-testing` 0.4.2 drops the false clause.
New fanout eval 39 covers unscored sorting last.

`review` 0.30.6 → 0.31.0.

## Research trail

- `severity.md` owned the inverted order; fanout/fix-pass defer to it.
- Detector producers cite the unchanged rule, not the order.

## Test plan

- [x] validate-plugins, changed-skills, changelog parity,
detector-findings crosswalk
- [x] `standards-binding.test.sh` PASS=8; markdownlint clean

## Notes

Serialized behind #4624. Open PRs #4622 and #4590 also bump `review`
(version-line only).
<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-ab53da24-b89d-4314-a060-0da474e837e9?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-ab53da24-b89d-4314-a060-0da474e837e9&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Rename the provenance plugin to attribution

2 participants