Skip to content

release: v0.3.0 — Apache-2.0, core@v0.8.0, and the 404 install path fixed - #20

Merged
bkd-dotcom merged 1 commit into
mainfrom
release-v0.3.0
Sep 1, 2026
Merged

release: v0.3.0 — Apache-2.0, core@v0.8.0, and the 404 install path fixed#20
bkd-dotcom merged 1 commit into
mainfrom
release-v0.3.0

Conversation

@bkd-dotcom

Copy link
Copy Markdown
Member

Cuts Signetry plugins v0.3.0 — the first release since 0.2.2 (2026-07-23), and
the one that makes the repo consumable again.

Everything under ## [Unreleased] has been sitting there for six weeks: the
Umbra → Signetry rebrand, the Apache-2.0 relicense, a 60-second quickstart in every
integration README (two of which did not exist), the community-health files, and the
404 install-path fix. That last one is why this release matters more than the
version number suggests: README.md told Claude Code users to run
/plugin marketplace add bkd-dotcom/signetry-plugins, a repository that has not
existed since the org move — so the documented primary install path for the plugin
could not work, and the fix was unreleased.

0.2.20.3.0 in both places that declare a version:
.claude-plugin/marketplace.json (metadata.version) and
claude-code/signetry/.claude-plugin/plugin.json.

Pins

was now
signetry-core (15 sites, 13 files) core@v0.7.0 core@v0.8.0
advisory reviewer workflow reviewer@v0.2.0 reviewer@v0.3.0
pre-commit rev: (.pre-commit-hooks.yaml, universal/README.md) v0.2.2 v0.3.0

The changelog's own pin bullet said the delta was v0.6.0v0.7.0. Since none of
it ever shipped, the delta an adopter actually gets is v0.6.0v0.8.0, and the
bullet now says that — a changelog entry describes the release it is in, not the
commit that happened to write it.

One line of the record was destroyed by a find-and-replace

The rename section was headed:

Changed — rebranded Signetry → Signetry

The global rebrand swept its own history, overwriting the from side of the arrow and
leaving a heading that states nothing. The old name was Umbra
(b313699 feat: Umbra editor/agent plugins), so it now reads
rebranded Umbra → Signetry. The bullets below it are left alone — they describe what
each thing is called now, which is still accurate.

@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Signetry Reviewer — 🟣 Escalate to a designated reviewer

Escalate to a designated reviewer — this PR touches security-sensitive surface (.github/workflows/reviewer.yml). No blocking issue was found automatically, but a human owner should sign off.

Deterministic gates (the authority)

Gate Status
Required status check — unknown
Secret scan ✅ clean
CI permission / OIDC ✅ no forbidden change
Dependency skew ✅ ok
All green

Findings (1, 0 blocking)

  • 🟡 Change touches a protected path: .github/workflows/reviewer.yml .github/workflows/reviewer.yml (via cross-check)
    • .github/workflows/reviewer.yml matches a protected pattern (.github/workflows/*). Changes here alter shared/foundational surface and warrant a designated reviewer.
    • Fix: Route to a code owner / architecture reviewer.

Sensitive surface

This PR changes security-sensitive paths that warrant a designated reviewer:

  • .github/workflows/reviewer.yml

Merge

A designated reviewer / code owner should sign off before merge (sensitive surface).

This review is advisory. It never merges on its own judgement — the deterministic gates + a human are the authority. Findings can have false negatives; a green bot verdict is not a guarantee.

@bkd-dotcom
bkd-dotcom merged commit cf84be4 into main Sep 1, 2026
2 checks passed
@bkd-dotcom
bkd-dotcom deleted the release-v0.3.0 branch September 1, 2026 15:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant