Scaffold chock-devin-plugins from the codex repo's file set - #2
Conversation
Populate this empty repository with the hand-written scaffold a generated-output repo needs before its first Publish run: CI workflows, docs, and legal files. Copied byte-identical from chock-codex-plugins where the source has no repo-specific content, and adapted for Devin's plugin format where it does. The generated trees themselves (devin/, .devin-plugin/plugin.json, chock-market.lock) are left for the Publish workflow's first real run to write. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Signed-off-by: Jothi Mani Rajendran <250249270+jothimani-rajendran@users.noreply.github.com>
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
That job resolves the framework ref from
This isn't something this PR can fix: Generated by Claude Code |
…itnessed-claims wording The block was copied from the codex README, which still names v0.7.0; the Devin format first ships in chock 0.9.3, so an adopter following the older pin gets 'invalid choice: devin'. The contributing row also implied these packages carry witnessed-blocking claims; none exist yet. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Signed-off-by: Jothi Mani Rajendran <250249270+jothimani-rajendran@users.noreply.github.com>
|
Update on That is the empty-repository case: there is no generated tree on this branch for Generated by Claude Code |
What this is
This repository is meant to become compiled output — a Devin-plugin packaging of the chock-catalog policies, published by a
workflow_dispatchPublish run, the same waychock-codex-pluginsworks today. This PR only adds the hand-written scaffold that has to exist before that first Publish run: CI workflows, legal files, and docs. It does not adddevin/,.devin-plugin/plugin.json, orchock-market.lock— those are generated output and are left for the Publish workflow's first real run (dry_run: false) to write, dispatched by the repo owner/orchestrator, not by this PR.Copied byte-identical from chock-codex-plugins
No repo-specific content in these, so they're verbatim copies (verified with
diff):.gitattributesLICENSE.github/workflows/close-prs.yml.github/workflows/security.yml.github/zizmor.ymlassets/icon.svg(the shared org mark)Adapted for Devin
.github/workflows/generated-only.ymland.github/workflows/publish.yml— same structure (dispatch inputs, three-checkout catalog/framework resolution,chock checkgating), with the build invocation swapped tochock plugin build --format devin/chock marketplace build --tree devin --name chock-devin --url https://github.com/open-coder-ai/chock-devin-plugins(Devin has no marketplace index file of its own, so--name/--urlare required, unlike the codex build). The "clear the generated trees" step now also removesdist/devinanddist/.devin-plugin.README.md— same shape as the codex README, with:docs.devin.ai, read 2026-09-21): "currently best effort and fail open — if a hook fails to load or run, the session continues without it — so don't rely on them for crucial guardrails yet." No livedevin plugins installrun has been recorded for this repository, and the page says so plainly instead of claiming a witnessed block (the codex README's claim is a witnessed Codex Desktop install; this one has no equivalent yet)..claude/settings.jsonhooks, so achock-claude-pluginsinstall may already provide the same guard — documented for the Claude-format fallback, not verified against this repo's layout.devin plugins install open-coder-ai/chock-devin-plugins(and the#devin/<id>single-plugin form) instead of aconfig.tomlmarketplace block.generated-only.yml.chock-{claude,cursor,copilot,codex,devin}-plugins.SECURITY.md— same structure,codex/→devin/,.devin-plugin/plugin.jsonnamed as compiled output alongsidechock-market.lock, and the "what these plugins do not promise" section restates the fail-open/local-sessions-only caveats from Devin's docs (exit code2blocks,0continues, cloud sessions don't register hooks at all).docs/assets/hero.svg— same animated terminal illustration; the caption line now reads "Devin — chock guard, best-effort by vendor design, not yet witnessed" instead of "witnessed on a real install", and the badge text names the hook's actual mechanism (plugin hook, exit code 2) instead of the Codex-specificPreToolUse/permissionDecisionwording.PLUGINS.md— this file is normally compiled output (chock marketplace buildwrites it, per its own header comment). Rather than hand-copy the codex repo's table — which I confirmed against a real build is already stale, the catalog now has 25 policies, not codex's snapshot of 23 — this is a short placeholder explaining that it awaits the first Publish run, with a pointer to the catalog and to the local build command in the meantime.Local build validation (not committed)
Installed
chock==0.9.3, clonedopen-coder-ai/chock-catalogto a scratch directory, and ran the two build commands this repo's workflows use, with--out-dirpointed outside the repo:Both succeeded against the catalog's
base/: 25 policies packaged (9 best-effort with ahooks.jsonguard, 16 advisory/skill-only), producing 105 files total —devin/<id>/.devin-plugin/plugin.json+AGENTS.md+rules/(+hooks.json/scripts/for the 9 guard policies) per plugin, plus the root.devin-plugin/plugin.jsonmeta-plugin,chock-market.lock, andPLUGINS.md. Hook commands andhooks.json's bare event-map shape ({"PreToolUse": [...]}, no wrapping"hooks"key) match what's documented in the task brief. None of that output is committed here.Lint / checks
actionlinton.github/workflows/*.yml: clean.zizmor --min-severity low --config .github/zizmor.ymlon.github/workflows/: no findings (onlineimpostor-commitaudit skipped — this sandbox's outbound GitHub API access isn't authenticated for it — offline audits pass clean).git diff --check: clean (the one flagged trailing-blank-line inLICENSEis present byte-for-byte in the source file too).README.mdand thepublish.yml"clear the generated trees" line, which the task brief specifies verbatim includingdist/codex.🤖 Generated with Claude Code