Repository navigation
Conversation
aadimch
marked this pull request as ready for review
October 7, 2026 01:25
ams-thakkar
self-requested a review
October 8, 2026 13:05
Contributor
|
Holding this one, and #126–#129 likewise: @aadimch and @miscreantmoogly have each built the same check independently, and the two are not compatible as they stand — most pointedly, I have asked the two of you to agree on which set to keep. |
This was referenced Oct 8, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR adds a
validate-skill-publishingcheck, and moves two skills to fullMAJOR.MINOR.PATCHversions so that they pass it.Skills on
mainare published as one set, so one skill that breaks a rule stops every skill from being published. The check applies the publishing rules to every skill inskills/on each pull request, so that a pull request that passes the check cannot put a skill onmainthat breaks a rule. The rules are in the new "Publishing Rules" section ofCONTRIBUTING.md.The check (
.github/scripts/validate_skill_publishing.py):git archiveat the head commit and at the merge base.SKILL.md: valid UTF-8, a YAML frontmatter block,name(1 to 64 characters,^[a-z0-9]+(-[a-z0-9]+)*$, equal to the folder name),description(1 to 1024 characters),metadata.versionas a quotedMAJOR.MINOR.PATCHstring, andmetadata.deprecatedas a boolean if present.metadata.version, the version never goes down, and a skill folder is never removed (deprecate it instead).evals/,.skilleval.yaml, andCHANGELOG.mdare not published, so a change to them alone needs no bump.README.mdis published, so a change to it needs a bump.<path>\0<file sha256 hex>\nof the published files, documented in the script and checked against a golden fixture..github/scripts/conformance/cases.json, and every one of the 53 conformance cases in that file. A failed self-check exits with code 2. Run it with--self-check-only.Workflows:
validate-skill-publishing.ymlruns on each pull request. It has read-only permissions, nopathsfilter (so that it always reports a status), passes event values throughenv, and does not keep the checkout credentials.validate-skill-publishing-main.ymlruns the check again after each push tomain, so that two pull requests that each passed on an older base and break a rule together are reported at once.Skill versions:
analytics-opensearch-expertise:2.6→2.6.1database-rds-devops:1.0→1.0.1Each gets a
CHANGELOG.mdentry. The patch number goes up, and not to.0, because the edit toSKILL.mdchanges the published content.Requests for maintainers:
validate-skill-publishingto the required status checks formain. Until then, the check is advisory.CODEOWNERSentry for.github/scripts/and.github/workflows/. A pull request that changes the check runs its own changed copy.Effect on open work: with this check required, a change to a skill's
README.mdwithout a version bump fails. For example, #122 would have needed a patch bump fordevops-agent-cost-insights.Type of change
Testing
python3 .github/scripts/validate_skill_publishing.py --base-ref origin/mainon this branch: the self-check passes, and all 30 skills pass (exit 0). The two changed skills report2.6.0 → 2.6.1and1.0.0 → 1.0.1.--self-check-onlypasses in 0.02 s. Each of these local changes makes the self-check fail with exit code 2: a changed hash record separator, an edited conformance case, and a conformance case with a flipped expected result.CHANGELOG.mdorevals/passes, a removed skill folder fails, a new skill passes, a duplicate key, a symlink, and a 513-character path fail.--base-ref HEAD~30onmainreports the earlier removal ofskills/eks-operation-review, as expected.validate-skill-evalspasses for the two changed skills, with the existing warnings for their legacyevals/layout.scan_aws_identifiers.pyover the diff: 0 findings.License confirmation