From 4731baef53a429260d8e43d3592a20ba71b75a81 Mon Sep 17 00:00:00 2001 From: YiJie Date: Sat, 19 Sep 2026 23:46:06 +0800 Subject: [PATCH 1/2] build: make agent trace package installable --- AGENTS.md | 10 +++--- README.md | 38 +++++++++------------ README.zh-Hans.md | 29 +++++++--------- cordisx.plugin.json => cordisx-package.json | 4 +-- dprint.json | 2 +- legal/public-name-policy.json | 1 + package-lock.json | 7 ++-- package.json | 15 ++++---- scripts/build-runtime-bundle.mjs | 21 ++++++++++++ test/plugin.test.ts | 11 ++++-- 10 files changed, 81 insertions(+), 57 deletions(-) rename cordisx.plugin.json => cordisx-package.json (96%) create mode 100644 scripts/build-runtime-bundle.mjs diff --git a/AGENTS.md b/AGENTS.md index f37a5d4..90a25df 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -13,9 +13,9 @@ ## Development and release - Requires Node.js 22 or newer. Install with `npm ci`. -- Run `npm run check`, `npm pack --dry-run`, and `git diff --check` before a - checkpoint commit. `npm run check` includes typecheck, build, tests, source - lint, format verification, and the package dry run. +- Run `npm run check`, `npm run format:check`, `npm run lint:source`, and + `git diff --check` before a checkpoint commit. `npm run check` includes + typecheck, build, tests, naming checks, and the package dry run. - The public README is for installation and use. Keep architecture checkpoints, source layout, build details, test commands, contribution steps, and release operations here or in an indexed maintainer guide. @@ -23,6 +23,8 @@ create the private package tarball with `npm pack`, publish it as `cordisx-agent-trace-showcase-.tgz` with `SHA256SUMS`, and verify both assets by downloading and hashing them. Do not publish until the package - descriptor, package version, README version, tag, and archive all agree. + descriptor, package version, README version, tag, and archive all agree. The + archive must contain `cordisx-package.json`, its runtime manifest, and the + browser bundle referenced by `entry`. - Marketplace artifact URLs and SHA-256 digests are updated by the Marketplace owner after the release. Do not copy an older Official or Certified record. diff --git a/README.md b/README.md index e02e421..8b7fc68 100644 --- a/README.md +++ b/README.md @@ -7,32 +7,27 @@ session without giving the plugin control over that session. ## Install -Plugin ID: `agent-trace-showcase`. Current release: `0.1.1`. +Plugin ID: `agent-trace-showcase`. Current release: `0.1.2`. -Release `v0.1.1` is a documentation and source package. Its archive does not -contain the standard `cordisx-package.json` manifest required by the current -CordisX CLI artifact installer, so it cannot be installed with `plugin install`. -Adding an artifact record to the Marketplace alone does not fix that package -format gap. - -The published archive and `SHA256SUMS` remain available from the -[GitHub release](https://github.com/cordisx/plugin-agent-trace/releases/tag/v0.1.1) -for source inspection. Do not unpack it into a CordisX profile as a substitute -for an installable package. - -After a future release provides the standard package manifest and compatible -runtime bundle, the CLI syntax will be: +The CordisX Community Marketplace feed must already be configured and enabled +before `--source` can select it: ```sh FEED_URL=https://raw.githubusercontent.com/cordisx/marketplace/main/marketplace.json npx cordisx@beta source add "$FEED_URL" --yes -npx cordisx@beta plugin install agent-trace-showcase --source "$FEED_URL" --version +npx cordisx@beta plugin install agent-trace-showcase --source "$FEED_URL" --version 0.1.2 ``` -For another profile, add the same `--profile ` argument to both future -commands. `--source` selects an already configured and enabled source; it does -not register one. `--yes` confirms the source change only and does not approve -plugin permissions. A discovery source is not a trust root. +Skip `source add` when that exact feed is already enabled. For another profile, +add the same `--profile ` argument to both commands. `--source` selects +an already configured and enabled source; it does not register one. `--yes` +confirms the source change only and does not approve plugin permissions. A +discovery source is not a trust root. + +The install command becomes available after the Marketplace v3 entry lists the +verified `0.1.2` artifact. Until then, download the archive and `SHA256SUMS` +from the +[GitHub release](https://github.com/cordisx/plugin-agent-trace/releases/tag/v0.1.2). ## Use @@ -60,9 +55,8 @@ entity state, or reconstruct missing history. ## Troubleshooting -- **`plugin install` rejects `0.1.1`:** this release is not an installable CLI - artifact because its archive lacks `cordisx-package.json`. Use the release - only for source inspection and wait for an explicitly installable version. +- **Install cannot find version `0.1.2`:** confirm the Marketplace v3 entry + lists the verified artifact. `--source` does not add or repair a feed. - **Timeline is empty:** open it from a concrete Agent session and review the three session permissions in CordisX plugin settings. - **Timeline stops updating:** reopen the session route. A terminal subscription diff --git a/README.zh-Hans.md b/README.zh-Hans.md index 7317817..04389c2 100644 --- a/README.zh-Hans.md +++ b/README.zh-Hans.md @@ -6,27 +6,24 @@ Agent Trace Showcase 为单个 Agent 会话提供只读 Timeline。它适合查 ## 安装 -插件 ID:`agent-trace-showcase`。当前版本:`0.1.1`。 +插件 ID:`agent-trace-showcase`。当前版本:`0.1.2`。 -`v0.1.1` 是文档与源码包。其压缩包不包含当前 CordisX CLI artifact installer -要求的标准 `cordisx-package.json` manifest,因此不能通过 `plugin install` 安装。 -只在 Marketplace 中添加 artifact 记录无法修复这个包格式缺口。 - -已发布的压缩包和 `SHA256SUMS` 仍可从 -[GitHub Release](https://github.com/cordisx/plugin-agent-trace/releases/tag/v0.1.1) -下载并检查源码。请勿将其解压到 CordisX profile 来替代正式安装包。 - -未来版本同时提供标准 package manifest 和兼容 runtime bundle 后,CLI 语法将是: +CordisX Community Marketplace feed 必须先完成配置并启用,`--source` 才能选择它: ```sh FEED_URL=https://raw.githubusercontent.com/cordisx/marketplace/main/marketplace.json npx cordisx@beta source add "$FEED_URL" --yes -npx cordisx@beta plugin install agent-trace-showcase --source "$FEED_URL" --version +npx cordisx@beta plugin install agent-trace-showcase --source "$FEED_URL" --version 0.1.2 ``` -使用其他 profile 时,未来的两条命令都要添加相同的 `--profile `。 -`--source` 只能选择已配置并启用的来源,不会注册来源;`--yes` 只确认来源变更, -不会批准插件权限。发现来源也不等同于 trust root。 +若该 feed 已启用,可跳过 `source add`。使用其他 profile 时,两条命令都要添加 +相同的 `--profile `。`--source` 只能选择已配置并启用的来源,不会注册来源; +`--yes` 只确认来源变更,不会批准插件权限。发现来源也不等同于 trust root。 + +Marketplace v3 条目列出已验证的 `0.1.2` artifact 后,安装命令才可用。在此之前, +可从 +[GitHub Release](https://github.com/cordisx/plugin-agent-trace/releases/tag/v0.1.2) +下载压缩包与 `SHA256SUMS`。 ## 使用 @@ -49,8 +46,8 @@ Host 服务、精确路由权限、Session、读取或订阅不可用时,Timel ## 排错 -- **`plugin install` 拒绝 `0.1.1`:**该版本压缩包缺少 `cordisx-package.json`,不是 - CLI 可安装 artifact。它仅供源码检查,请等待明确标记为可安装的后续版本。 +- **找不到 `0.1.2`:**确认 Marketplace v3 条目已列出验证后的 artifact; + `--source` 不会添加或修复 feed。 - **Timeline 为空:**从具体 Agent 会话打开 Timeline,并在插件设置中检查三项 Session 权限。 - **Timeline 停止更新:**重新打开会话路由。插件会显示终止原因,不会静默切换 diff --git a/cordisx.plugin.json b/cordisx-package.json similarity index 96% rename from cordisx.plugin.json rename to cordisx-package.json index 75ca6a6..4009830 100644 --- a/cordisx.plugin.json +++ b/cordisx-package.json @@ -2,8 +2,8 @@ "$schema": "https://raw.githubusercontent.com/cordisx/cordisx-protocol/main/schemas/plugin-package.v4.schema.json", "schemaVersion": 4, "id": "agent-trace-showcase", - "version": "0.1.1", - "entry": "./dist/index.js", + "version": "0.1.2", + "entry": "./dist/runtime/module.js", "readme": "./README.md", "canonicalSource": "https://github.com/cordisx/plugin-agent-trace", "distribution": { diff --git a/dprint.json b/dprint.json index f117f43..e32c560 100644 --- a/dprint.json +++ b/dprint.json @@ -10,7 +10,7 @@ "package-lock.json", // Byte-addressed security artifacts: do not rewrite manifests or their recorded digests. "runtime-manifest.json", - "cordisx.plugin.json" + "cordisx-package.json" ], "extends": "https://raw.githubusercontent.com/cordisx/cordisxmono/c63c2e8c2ba7e11502934a52ad2ce3734e804cdc/tooling/quality/dprint/code.json", "typescript": { diff --git a/legal/public-name-policy.json b/legal/public-name-policy.json index 2fb8cde..07250ae 100644 --- a/legal/public-name-policy.json +++ b/legal/public-name-policy.json @@ -13,6 +13,7 @@ "runtimeImports": { "paths": [ "package.json", + "scripts/build-runtime-bundle.mjs", "src/entry.ts", "src/index.ts" ], diff --git a/package-lock.json b/package-lock.json index fcde2e6..99816f7 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@cordisx/agent-trace-showcase", - "version": "0.1.1", + "version": "0.1.2", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@cordisx/agent-trace-showcase", - "version": "0.1.1", + "version": "0.1.2", "license": "AGPL-3.0-or-later", "dependencies": { "@deepseek-ai/cordis": "4.0.1", @@ -18,6 +18,7 @@ "@cordisx/protocol": "github:cordisx/cordisx-protocol#c96c290697f9e802a68c6d3bb094fd27d8d00d1e", "@typescript-eslint/parser": "8.69.0", "dprint": "0.57.1", + "esbuild": "0.28.2", "eslint": "9.39.4", "jsdom": "^26.1.0", "typescript": "^5.9.2", @@ -2759,7 +2760,7 @@ }, "node_modules/esbuild": { "version": "0.28.2", - "resolved": "https://registry.npmjs.org/esbuild/-/esbuild-0.28.2.tgz", + "resolved": "https://bnpm.byted.org/esbuild/-/esbuild-0.28.2.tgz", "integrity": "sha512-HKVLS8dvII+xoKW9kmqxbRKrnWEXfJJr/FZhhJmiqIB0e053QNYFqOBouTMO/k5sID4MvCiUCvv8b9M4h32wIA==", "hasInstallScript": true, "license": "MIT", diff --git a/package.json b/package.json index aa2b334..fe9bfb2 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@cordisx/agent-trace-showcase", - "version": "0.1.1", + "version": "0.1.2", "private": true, "description": "Read-only CordisX Agent Trace Timeline plugin", "license": "AGPL-3.0-or-later", @@ -12,14 +12,14 @@ "dist", "README.md", "README.zh-Hans.md", - "cordisx.plugin.json", + "cordisx-package.json", "runtime-manifest.json", "legal" ], "scripts": { "icon:generate": "node scripts/generate-brand-icon.mjs", "icon:check": "node scripts/generate-brand-icon.mjs --check", - "build": "node scripts/clean-dist.mjs && tsc -p tsconfig.json", + "build": "node scripts/clean-dist.mjs && tsc -p tsconfig.json && node scripts/build-runtime-bundle.mjs", "typecheck": "tsc -p tsconfig.json --noEmit", "test": "vitest run", "naming:check": "node scripts/check-public-naming.mjs", @@ -36,14 +36,15 @@ "cordisx": "0.1.0-beta.1" }, "devDependencies": { + "@cordisx/eslint-config": "github:cordisx/cordisxmono#c63c2e8c2ba7e11502934a52ad2ce3734e804cdc", "@cordisx/protocol": "github:cordisx/cordisx-protocol#c96c290697f9e802a68c6d3bb094fd27d8d00d1e", + "@typescript-eslint/parser": "8.69.0", "dprint": "0.57.1", + "esbuild": "0.28.2", + "eslint": "9.39.4", "jsdom": "^26.1.0", "typescript": "^5.9.2", - "vitest": "^3.2.4", - "@cordisx/eslint-config": "github:cordisx/cordisxmono#c63c2e8c2ba7e11502934a52ad2ce3734e804cdc", - "eslint": "9.39.4", - "@typescript-eslint/parser": "8.69.0" + "vitest": "^3.2.4" }, "engines": { "node": ">=22.19" diff --git a/scripts/build-runtime-bundle.mjs b/scripts/build-runtime-bundle.mjs new file mode 100644 index 0000000..76dc78c --- /dev/null +++ b/scripts/build-runtime-bundle.mjs @@ -0,0 +1,21 @@ +import { build } from 'esbuild' + +await build({ + bundle: true, + entryPoints: ['src/index.ts'], + external: [ + '@deepseek-ai/cordis', + 'cordisx/contracts', + 'cordisx/react', + 'cordisx/react/jsx-runtime', + 'cordisx/react/jsx-dev-runtime', + 'cordisx/ui', + ], + format: 'esm', + metafile: true, + minifyWhitespace: true, + outfile: 'dist/runtime/module.js', + platform: 'browser', + sourcemap: false, + target: ['chrome120'], +}) diff --git a/test/plugin.test.ts b/test/plugin.test.ts index 60eee8d..360a932 100644 --- a/test/plugin.test.ts +++ b/test/plugin.test.ts @@ -78,11 +78,11 @@ describe('plugin boundary', () => { describe('package manifest', () => { it('pins the exact v5 runtime manifest', async () => { - const packageManifest = JSON.parse(await readFile(new URL('../cordisx.plugin.json', import.meta.url), 'utf8')) + const packageManifest = JSON.parse(await readFile(new URL('../cordisx-package.json', import.meta.url), 'utf8')) const runtimeManifestText = await readFile(new URL('../runtime-manifest.json', import.meta.url), 'utf8') const runtimeManifest = JSON.parse(runtimeManifestText) expect(packageManifest.id).toBe('agent-trace-showcase') - expect(packageManifest.entry).toBe('./dist/index.js') + expect(packageManifest.entry).toBe('./dist/runtime/module.js') expect(packageManifest.schemaVersion).toBe(4) expect(packageManifest.runtimeManifest).toMatchObject({ path: './runtime-manifest.json', @@ -92,4 +92,11 @@ describe('package manifest', () => { expect(runtimeManifest).toEqual(manifest) expect(packageManifest.canonicalSource).toBe('https://github.com/cordisx/plugin-agent-trace') }) + + it('ships the standard package manifest and browser bundle', async () => { + const module = await readFile(new URL('../dist/runtime/module.js', import.meta.url), 'utf8') + expect(module).toMatch(/from\s*["']cordisx\/react["']/u) + expect(module).toMatch(/from\s*["']cordisx\/ui["']/u) + expect(module).not.toContain('node_modules/') + }) }) From bb421cf72dbea984b825cecaaf4e02c77deaf0d5 Mon Sep 17 00:00:00 2001 From: YiJie Date: Sat, 19 Sep 2026 23:51:25 +0800 Subject: [PATCH 2/2] fix: use public esbuild registry URL --- package-lock.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package-lock.json b/package-lock.json index 99816f7..96b49c8 100644 --- a/package-lock.json +++ b/package-lock.json @@ -2760,7 +2760,7 @@ }, "node_modules/esbuild": { "version": "0.28.2", - "resolved": "https://bnpm.byted.org/esbuild/-/esbuild-0.28.2.tgz", + "resolved": "https://registry.npmjs.org/esbuild/-/esbuild-0.28.2.tgz", "integrity": "sha512-HKVLS8dvII+xoKW9kmqxbRKrnWEXfJJr/FZhhJmiqIB0e053QNYFqOBouTMO/k5sID4MvCiUCvv8b9M4h32wIA==", "hasInstallScript": true, "license": "MIT",