Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 6 additions & 4 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,16 +13,18 @@
## Development and release

- Requires Node.js 22 or newer. Install with `npm ci`.
- Run `npm run check`, `npm pack --dry-run`, and `git diff --check` before a
checkpoint commit. `npm run check` includes typecheck, build, tests, source
lint, format verification, and the package dry run.
- Run `npm run check`, `npm run format:check`, `npm run lint:source`, and
`git diff --check` before a checkpoint commit. `npm run check` includes
typecheck, build, tests, naming checks, and the package dry run.
- The public README is for installation and use. Keep architecture checkpoints,
source layout, build details, test commands, contribution steps, and release
operations here or in an indexed maintainer guide.
- Releases use a GitHub prerelease, not npm. Build the exact merged main commit,
create the private package tarball with `npm pack`, publish it as
`cordisx-agent-trace-showcase-<version>.tgz` with `SHA256SUMS`, and verify both
assets by downloading and hashing them. Do not publish until the package
descriptor, package version, README version, tag, and archive all agree.
descriptor, package version, README version, tag, and archive all agree. The
archive must contain `cordisx-package.json`, its runtime manifest, and the
browser bundle referenced by `entry`.
- Marketplace artifact URLs and SHA-256 digests are updated by the Marketplace
owner after the release. Do not copy an older Official or Certified record.
38 changes: 16 additions & 22 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,32 +7,27 @@ session without giving the plugin control over that session.

## Install

Plugin ID: `agent-trace-showcase`. Current release: `0.1.1`.
Plugin ID: `agent-trace-showcase`. Current release: `0.1.2`.

Release `v0.1.1` is a documentation and source package. Its archive does not
contain the standard `cordisx-package.json` manifest required by the current
CordisX CLI artifact installer, so it cannot be installed with `plugin install`.
Adding an artifact record to the Marketplace alone does not fix that package
format gap.

The published archive and `SHA256SUMS` remain available from the
[GitHub release](https://github.com/cordisx/plugin-agent-trace/releases/tag/v0.1.1)
for source inspection. Do not unpack it into a CordisX profile as a substitute
for an installable package.

After a future release provides the standard package manifest and compatible
runtime bundle, the CLI syntax will be:
The CordisX Community Marketplace feed must already be configured and enabled
before `--source` can select it:

```sh
FEED_URL=https://raw.githubusercontent.com/cordisx/marketplace/main/marketplace.json
npx cordisx@beta source add "$FEED_URL" --yes
npx cordisx@beta plugin install agent-trace-showcase --source "$FEED_URL" --version <installable-version>
npx cordisx@beta plugin install agent-trace-showcase --source "$FEED_URL" --version 0.1.2
```

For another profile, add the same `--profile <profile>` argument to both future
commands. `--source` selects an already configured and enabled source; it does
not register one. `--yes` confirms the source change only and does not approve
plugin permissions. A discovery source is not a trust root.
Skip `source add` when that exact feed is already enabled. For another profile,
add the same `--profile <profile>` argument to both commands. `--source` selects
an already configured and enabled source; it does not register one. `--yes`
confirms the source change only and does not approve plugin permissions. A
discovery source is not a trust root.

The install command becomes available after the Marketplace v3 entry lists the
verified `0.1.2` artifact. Until then, download the archive and `SHA256SUMS`
from the
[GitHub release](https://github.com/cordisx/plugin-agent-trace/releases/tag/v0.1.2).

## Use

Expand Down Expand Up @@ -60,9 +55,8 @@ entity state, or reconstruct missing history.

## Troubleshooting

- **`plugin install` rejects `0.1.1`:** this release is not an installable CLI
artifact because its archive lacks `cordisx-package.json`. Use the release
only for source inspection and wait for an explicitly installable version.
- **Install cannot find version `0.1.2`:** confirm the Marketplace v3 entry
lists the verified artifact. `--source` does not add or repair a feed.
- **Timeline is empty:** open it from a concrete Agent session and review the
three session permissions in CordisX plugin settings.
- **Timeline stops updating:** reopen the session route. A terminal subscription
Expand Down
29 changes: 13 additions & 16 deletions README.zh-Hans.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,27 +6,24 @@ Agent Trace Showcase 为单个 Agent 会话提供只读 Timeline。它适合查

## 安装

插件 ID:`agent-trace-showcase`。当前版本:`0.1.1`。
插件 ID:`agent-trace-showcase`。当前版本:`0.1.2`。

`v0.1.1` 是文档与源码包。其压缩包不包含当前 CordisX CLI artifact installer
要求的标准 `cordisx-package.json` manifest,因此不能通过 `plugin install` 安装。
只在 Marketplace 中添加 artifact 记录无法修复这个包格式缺口。

已发布的压缩包和 `SHA256SUMS` 仍可从
[GitHub Release](https://github.com/cordisx/plugin-agent-trace/releases/tag/v0.1.1)
下载并检查源码。请勿将其解压到 CordisX profile 来替代正式安装包。

未来版本同时提供标准 package manifest 和兼容 runtime bundle 后,CLI 语法将是:
CordisX Community Marketplace feed 必须先完成配置并启用,`--source` 才能选择它:

```sh
FEED_URL=https://raw.githubusercontent.com/cordisx/marketplace/main/marketplace.json
npx cordisx@beta source add "$FEED_URL" --yes
npx cordisx@beta plugin install agent-trace-showcase --source "$FEED_URL" --version <installable-version>
npx cordisx@beta plugin install agent-trace-showcase --source "$FEED_URL" --version 0.1.2
```

使用其他 profile 时,未来的两条命令都要添加相同的 `--profile <profile>`。
`--source` 只能选择已配置并启用的来源,不会注册来源;`--yes` 只确认来源变更,
不会批准插件权限。发现来源也不等同于 trust root。
若该 feed 已启用,可跳过 `source add`。使用其他 profile 时,两条命令都要添加
相同的 `--profile <profile>`。`--source` 只能选择已配置并启用的来源,不会注册来源;
`--yes` 只确认来源变更,不会批准插件权限。发现来源也不等同于 trust root。

Marketplace v3 条目列出已验证的 `0.1.2` artifact 后,安装命令才可用。在此之前,
可从
[GitHub Release](https://github.com/cordisx/plugin-agent-trace/releases/tag/v0.1.2)
下载压缩包与 `SHA256SUMS`。

## 使用

Expand All @@ -49,8 +46,8 @@ Host 服务、精确路由权限、Session、读取或订阅不可用时,Timel

## 排错

- **`plugin install` 拒绝 `0.1.1`:**该版本压缩包缺少 `cordisx-package.json`,不是
CLI 可安装 artifact。它仅供源码检查,请等待明确标记为可安装的后续版本。
- **找不到 `0.1.2`:**确认 Marketplace v3 条目已列出验证后的 artifact;
`--source` 不会添加或修复 feed。
- **Timeline 为空:**从具体 Agent 会话打开 Timeline,并在插件设置中检查三项
Session 权限。
- **Timeline 停止更新:**重新打开会话路由。插件会显示终止原因,不会静默切换
Expand Down
4 changes: 2 additions & 2 deletions cordisx.plugin.json → cordisx-package.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@
"$schema": "https://raw.githubusercontent.com/cordisx/cordisx-protocol/main/schemas/plugin-package.v4.schema.json",
"schemaVersion": 4,
"id": "agent-trace-showcase",
"version": "0.1.1",
"entry": "./dist/index.js",
"version": "0.1.2",
"entry": "./dist/runtime/module.js",
"readme": "./README.md",
"canonicalSource": "https://github.com/cordisx/plugin-agent-trace",
"distribution": {
Expand Down
2 changes: 1 addition & 1 deletion dprint.json
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
"package-lock.json",
// Byte-addressed security artifacts: do not rewrite manifests or their recorded digests.
"runtime-manifest.json",
"cordisx.plugin.json"
"cordisx-package.json"
],
"extends": "https://raw.githubusercontent.com/cordisx/cordisxmono/c63c2e8c2ba7e11502934a52ad2ce3734e804cdc/tooling/quality/dprint/code.json",
"typescript": {
Expand Down
1 change: 1 addition & 0 deletions legal/public-name-policy.json
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@
"runtimeImports": {
"paths": [
"package.json",
"scripts/build-runtime-bundle.mjs",
"src/entry.ts",
"src/index.ts"
],
Expand Down
5 changes: 3 additions & 2 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

15 changes: 8 additions & 7 deletions package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@cordisx/agent-trace-showcase",
"version": "0.1.1",
"version": "0.1.2",
"private": true,
"description": "Read-only CordisX Agent Trace Timeline plugin",
"license": "AGPL-3.0-or-later",
Expand All @@ -12,14 +12,14 @@
"dist",
"README.md",
"README.zh-Hans.md",
"cordisx.plugin.json",
"cordisx-package.json",
"runtime-manifest.json",
"legal"
],
"scripts": {
"icon:generate": "node scripts/generate-brand-icon.mjs",
"icon:check": "node scripts/generate-brand-icon.mjs --check",
"build": "node scripts/clean-dist.mjs && tsc -p tsconfig.json",
"build": "node scripts/clean-dist.mjs && tsc -p tsconfig.json && node scripts/build-runtime-bundle.mjs",
"typecheck": "tsc -p tsconfig.json --noEmit",
"test": "vitest run",
"naming:check": "node scripts/check-public-naming.mjs",
Expand All @@ -36,14 +36,15 @@
"cordisx": "0.1.0-beta.1"
},
"devDependencies": {
"@cordisx/eslint-config": "github:cordisx/cordisxmono#c63c2e8c2ba7e11502934a52ad2ce3734e804cdc",
"@cordisx/protocol": "github:cordisx/cordisx-protocol#c96c290697f9e802a68c6d3bb094fd27d8d00d1e",
"@typescript-eslint/parser": "8.69.0",
"dprint": "0.57.1",
"esbuild": "0.28.2",
"eslint": "9.39.4",
"jsdom": "^26.1.0",
"typescript": "^5.9.2",
"vitest": "^3.2.4",
"@cordisx/eslint-config": "github:cordisx/cordisxmono#c63c2e8c2ba7e11502934a52ad2ce3734e804cdc",
"eslint": "9.39.4",
"@typescript-eslint/parser": "8.69.0"
"vitest": "^3.2.4"
},
"engines": {
"node": ">=22.19"
Expand Down
21 changes: 21 additions & 0 deletions scripts/build-runtime-bundle.mjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
import { build } from 'esbuild'

await build({
bundle: true,
entryPoints: ['src/index.ts'],
external: [
'@deepseek-ai/cordis',
'cordisx/contracts',
'cordisx/react',
'cordisx/react/jsx-runtime',
'cordisx/react/jsx-dev-runtime',
'cordisx/ui',
],
format: 'esm',
metafile: true,
minifyWhitespace: true,
outfile: 'dist/runtime/module.js',
platform: 'browser',
sourcemap: false,
target: ['chrome120'],
})
11 changes: 9 additions & 2 deletions test/plugin.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -78,11 +78,11 @@ describe('plugin boundary', () => {

describe('package manifest', () => {
it('pins the exact v5 runtime manifest', async () => {
const packageManifest = JSON.parse(await readFile(new URL('../cordisx.plugin.json', import.meta.url), 'utf8'))
const packageManifest = JSON.parse(await readFile(new URL('../cordisx-package.json', import.meta.url), 'utf8'))
const runtimeManifestText = await readFile(new URL('../runtime-manifest.json', import.meta.url), 'utf8')
const runtimeManifest = JSON.parse(runtimeManifestText)
expect(packageManifest.id).toBe('agent-trace-showcase')
expect(packageManifest.entry).toBe('./dist/index.js')
expect(packageManifest.entry).toBe('./dist/runtime/module.js')
expect(packageManifest.schemaVersion).toBe(4)
expect(packageManifest.runtimeManifest).toMatchObject({
path: './runtime-manifest.json',
Expand All @@ -92,4 +92,11 @@ describe('package manifest', () => {
expect(runtimeManifest).toEqual(manifest)
expect(packageManifest.canonicalSource).toBe('https://github.com/cordisx/plugin-agent-trace')
})

it('ships the standard package manifest and browser bundle', async () => {
const module = await readFile(new URL('../dist/runtime/module.js', import.meta.url), 'utf8')
expect(module).toMatch(/from\s*["']cordisx\/react["']/u)
expect(module).toMatch(/from\s*["']cordisx\/ui["']/u)
expect(module).not.toContain('node_modules/')
})
})
Loading